Towards a test-suite for TOTP codes — https://shkspr.mobi/blog/2025/03/towards-a-test-suite-for-totp-codes/
#HackerNews #TOTP #Security #TestSuite #Authentication #CodeValidation
#HackerNews #TOTP #Security #TestSuite #Authentication #CodeValidation
Towards a test-suite for TOTP codes
Because I'm a massive nerd, I actually try to read specification documents. As I've ranted ad nauseam before, the current TOTP spec is irresponsibly obsolete. The three major implementations of the spec - Google, Apple, and Yubico - all subtly disagree on how it should be implemented. Every other MFA app has their own idiosyncratic variants. The official RFC is infuriatingly vague. That's no…