Terence Eden. He has a beard and is smiling.

Terence Eden’s Blog

Theme Switcher:

Towards a test-suite for TOTP codes

· 11 comments · 1,250 words · Viewed ~7,061 times


Screenshot showing a QR code and numeric codes.

Because I'm a massive nerd, I actually try to read specification documents. As I've ranted ad nauseam before, the current TOTP spec is irresponsibly obsolete. The three major implementations of the spec - Google, Apple, and Yubico - all subtly disagree on how it should be implemented. Every other MFA app has their own idiosyncratic variants. The official RFC is infuriatingly vague. That's no…