How Authenticator Apps Work Offline: TOTP & HOTP | Bits To Billions
Bits To Billions
0:00 / 0:00
How Authenticator Apps Work Offline: TOTP & HOTP | Bits To Billions
10 просмотров · 2 дня назад
Bits To Billions
16 подписчиков
10 просмотров · 2 дня назад
A website asks for a six-digit code. You open an app, and there it is, with a little timer
running down - even in airplane mode. Nothing arrived: no text, no email, not even a notification.
Nadia is on a night flight over the Atlantic, her phone offline for hours. In a data centre in
Frankfurt, a server works out the very same six digits at the very same second - and when her
timer runs out, both sides switch to a new code together. Two clocks that never speak, agreeing
every thirty seconds.
This is a defender's explainer: what is really inside the QR code you scan, how HMAC, HOTP and
TOTP turn one shared secret into six digits, what happens when clocks drift, the rules a careful
server follows, and what saves you when the phone is gone. Every load-bearing claim was checked
against a primary source.
Watch the whole Explained series: • Authentication & Authorization Explained: ...
WHAT YOU'LL LEARN
What the setup QR code really is: one otpauth:// line of text carrying a shared secret
Base32, and why a 160-bit secret is 32 characters (RFC 4226 asks for at least 128 bits)
Why the QR code is the key itself - and why you should treat it like a password
Hash functions, and why the obvious 'secret in front of the message' recipe has a known flaw
HMAC: the secret mixed in twice, inside and outside (RFC 2104) - and why SHA-1 collisions don't break it
HOTP (RFC 4226): a counter, HMAC and dynamic truncation, worked through with the RFC's own test values
Hardware keys and counter drift: the look-ahead window, and why a used code is never accepted again
TOTP (RFC 6238): Unix time, 30-second time steps, and why TOTP is HOTP with the clock doing the counting
Why authenticator apps work with no signal at all
Clock drift and the validation window: why servers accept one step back, and no more
Why a hand-set phone clock breaks your codes, and changing time zones never does
The server's rules: one use per code, limited guessing (NIST's 100-attempt ceiling), encrypted secrets
Why a TOTP secret can't be hashed like a password
Why typed codes are not phishing-resistant, and where passkeys go further
Backup codes (NIST 'look-up secrets'): how many, one use each, stored hashed
Authenticator sync and backup: what it protects you from, and what it asks of your cloud account
CHAPTERS
00:00 Intro
01:57 The shared secret
04:43 HMAC: the mixing recipe
07:43 HOTP: counting codes
10:51 TOTP: the clock as counter
13:45 When clocks disagree
16:37 The server's rules
19:23 Backup codes
21:47 Recap
SOURCES
RFC 6238, TOTP: Time-Based One-Time Password Algorithm (May 2011) - time steps, validation window, resynchronization, test vectors
RFC 4226, HOTP: An HMAC-Based One-Time Password Algorithm (Dec 2005) - dynamic truncation, test values, look-ahead window, secret length, managing shared secrets
RFC 2104, HMAC: Keyed-Hashing for Message Authentication (Feb 1997); Bellare, Canetti and Krawczyk, Keying Hash Functions for Message Authentication (CRYPTO '96)
RFC 4648, Base-N encodings (Base32)
Google Authenticator wiki, Key Uri Format (otpauth://)
NIST SP 800-63B-4 (July 2025): OTP and look-up secret requirements, rate limiting, phishing resistance
NIST SP 800-131A Rev. 2, and NIST's SHA-1 retirement announcement (15 Dec 2022)
Google Account Help (Google Authenticator; backup codes); Google Security Blog on Authenticator sync (24 Apr 2023)
Microsoft Support (Microsoft Authenticator); GitHub Docs (recovery codes); AWS IAM docs (virtual MFA devices)
Yubico documentation (OATH-HOTP); M. Lombardi, NIST, on quartz clock accuracy
OWASP Multifactor Authentication Cheat Sheet
This is a defender's explainer. Risks are named only as far as the defences need - there is no attack tooling and no step-by-step here. Every load-bearing claim, number and date was checked against a primary source before recording.
These are standalone explainers - one topic, one video, always from zero. Subscribe and you'll get the next one.
#totp #2fa #mfa #cybersecurity #infosec