With a window of 30 seconds and 1e6 possibilities, the expected time it takes to get to a particular number is 347 days. Should be easy to brute force.
With a window of 30 seconds and 1e6 possibilities, the expected time it takes to get to a particular number is 347 days. Should be easy to brute force.
https://gist.github.com/skull-squadron/8f806b28abbcaa1ba9c25...
Unfortunately, it may take several years before a certain TOTP value is reached because the values are nondeterministic rather than ordered and so there will be hash collisions of other values as well.
Example: JBSWY3DPEHPK3PXP 999999
TOTP will match 999999 between 2024-11-29 16:37:00 -0600 and 2024-11-29 16:37:29 -0600Yes it could be several years, however the expected value is less than a year. Just like the expected dice rolls before rolling 6 is 6.
I also wrote a program to find CRC32 hash collisions that can be injected into a text file or script to make a text hash to that value. https://gist.github.com/skull-squadron/c85d295cf9e6124dd7e90...
Doing so MD5, SHA1, or even SHA256 would be extremely slow and expensive, but not impossible.
I wonder if something could be set up to be both more secure, and more tailored to this use-case. Be pretty sweet to embed a 2FA in users brains somehow.
> Be pretty sweet to embed a 2FA in users brains somehow.
2FA already has a concept of "Something that you know".Still, "Something that you could calculate without revealing the thing that you know" is an interesting concept.
https://open.substack.com/pub/jacobbartlett/p/building-a-2fa...