Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's interesting that a super key even exists. Normally the enrolment QR codes are one time use only.


This is incorrect.

A standard TOTP QR code can be used on multiple devices or saved and printed (and stored in a safe or something). There is no expiration date encoded in the QR; it is simply the shared secret for the TOTP app to use and some extra metadata like labels. See https://www.rfc-editor.org/rfc/rfc6238

It is a good idea to enroll multiple devices as a backup against failure, or to store it somewhere safe.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: