|
You are here |
labanskoller.se | ||
| | | | |
supabase.com
|
|
| | | | | MFA Auth with enforcement via RLS | |
| | | | |
zserge.com
|
|
| | | | | Many of us use one-time passwords (OTP) regularly to log into different services. Most probably rely on Google Authenticator and similar tools. But what about building one by ourselves? | |
| | | | |
www.dannyguo.com
|
|
| | | | | ||
| | | | |
labanskoller.se
|
|
| | | You probably use an "authenticator app" such as Google Authenticator to enable two-step verification (sometimes called two-factor authentication, 2FA, or multi-factor authentication, MFA) for an online account. The method is called Time-Based One-Time Password Algorithm (TOTP) and is standardized in RFC 6238. In October 2017 when I evaluated HashiCorp Vault for generating and storing TOTP secrets for a system at work I realized that the Android version and iOS version of Google Authenticator differed a lot when it comes to which modes are supported. | ||