You didn't get my point...
I know what it is based on, except the implementation details.
My question was what's the mechanism to verify the code refreshed every time the screen is turn on (which is a little different from other authenticators).
I know what it is based on, except the implementation details.
My question was what's the mechanism to verify the code refreshed every time the screen is turn on (which is a little different from other authenticators).
I don't think there's a reasonable way to do that within the TOTP specification. There's (eventually) got to be some rate-limiting or it will reduce the security.