Specifically: http://tools.ietf.org/html/rfc6238
So you can add support as long as you support the standard.
When you scan the QR Code with you camera we read a secret key and store it inside your phone securely.
Specifically: http://tools.ietf.org/html/rfc6238
So you can add support as long as you support the standard.
When you scan the QR Code with you camera we read a secret key and store it inside your phone securely.
> Basically, the output of the HMAC-SHA-1 calculation is truncated to > obtain user-friendly values: > > HOTP(K,C) = Truncate(HMAC-SHA-1(K,C)) > > where Truncate represents the function that can convert an HMAC-SHA-1 > value into an HOTP value. K and C represent the shared secret and > counter value;
Does that mean it's formally/theoretically equivalent to simply having two separate passwords?
This would be the equivalent of having 2 passwords, one of which you change every-time you use it and it's fully random.
However, if the original secret is compromised (K), then could an attacker easily generate OTPs?