Lesson 7 / 24

One-Time Codes (TOTP)

Enable app-based two-factor codes and know why SMS is the weakest option.

A code that changes

TOTP (time-based one-time password) apps and password managers show a 6-digit code that changes every 30 seconds. A stolen password alone is no longer enough to log in. SMS codes are better than nothing but can be intercepted through SIM swapping.

Something you know plus something you have

A second factor or a passkey stops an attacker who has only your password.

Three layers: password, second factor, passkey.
Figure 3.1 — Password, second factor and passkey.

Read a TOTP code from the CLI

1Password can store the TOTP seed in a login item and op can print the current code. Use this for scripts that must log in to a service you own.

op item get "GitHub" --otp

Keep recovery codes apart

Save the recovery codes a site gives you, but store them in a different place from the one-time code seed. If both live in one phone and you lose it, you are locked out.

Quick check: Why is SMS the weakest second factor?

  • It needs the internet
  • It never works abroad
  • Codes expire in a year
  • Numbers can be hijacked by SIM swapping
Answer

Numbers can be hijacked by SIM swapping — An attacker who takes over your number receives your codes. App-based or hardware factors avoid that.