TOTP - Time-Based One-Time Passwords for 2FA
About 2 min read
TOTP (Time-based One-Time Password) is a one-time password mechanism that generates codes based on the current time. It is widely used in authenticator apps such as Google Authenticator and Microsoft Authenticator. A new 6-digit code is typically generated every 30 seconds and functions as a two-factor authentication element added to the password. As of 2024, TOTP is the most widely adopted two-factor authentication method, and the majority of major services such as Google, GitHub, and AWS support it.
Three Assumptions That Survive a Mandate
A decision to mandate use is often measured by the number of people who have finished setting it up, but the actual state is determined by three assumptions that remain behind it. First, an enrollment completed once does not last forever. When a device is replaced, when a handset is changed, or when the application is reinstalled, the enrollment has to be done again, and during that process some other means of showing who you are becomes necessary. If the path for redoing the enrollment is easier than the original procedure, that path becomes the real entrance. The effect of the mandate therefore depends less on whether enrollment is complete than on what is demanded when it is redone. Second, what a code that changes over a short interval prevents is reuse afterwards, not use immediately after it is received. The same code remains valid within the same interval, so if a code that has been entered is used elsewhere on the spot, the speed of the rotation does nothing. A time-based mechanism shortens the lifetime of a stolen code; it does not remove the path by which it is stolen. Third, the scope where the requirement applies does not coincide with the list of people. A requirement can be imposed on the path that goes through the screen, but credentials issued separately for machine-to-machine exchanges, and entrances left in place under older procedures, may fall outside the same requirement. A state in which everyone has been made to set it up does not mean a state in which it is demanded at every entrance. The former can be verified against a roster; the latter cannot be known without enumerating the entrances themselves.
The TOTP Generation Flow
How TOTP Works
TOTP is an algorithm standardized in RFC 6238. Using a secret key shared between the server and client together with the current time as inputs, it computes a hash value with HMAC-SHA1 and extracts a 6-digit number from it. As long as the server and client clocks are synchronized, the same code is generated, so authentication succeeds.
Concrete Usage Scenarios
A common misconception is that "SMS authentication and TOTP offer the same level of security." SMS authentication carries the risk of interception through SIM swap attacks or exploitation of vulnerabilities in the SS7 protocol. Because TOTP is self-contained within the device, it is far more secure against these attacks. NIST (the U.S. National Institute of Standards and Technology) also recommends the use of TOTP or hardware keys over SMS authentication.
By combining TOTP with a strong password generated by a password manager, you can prevent unauthorized logins even if the password leaks. Store the TOTP secret key securely along with your backup codes. In case you lose the smartphone running your authenticator app, the practical best practice is to print the backup codes on paper and keep them in a safe, or to set up the authenticator app on multiple devices.
Was this article helpful?