Lesson 7 / 24
One-Time Codes (TOTP)
Enable app-based two-factor codes and know why SMS is the weakest option.
A code that changes
TOTP (time-based one-time password) apps and password managers show a 6-digit code that changes every 30 seconds. A stolen password alone is no longer enough to log in. SMS codes are better than nothing but can be intercepted through SIM swapping.
Something you know plus something you have
A second factor or a passkey stops an attacker who has only your password.
Read a TOTP code from the CLI
1Password can store the TOTP seed in a login item and op can print the current code. Use this for scripts that must log in to a service you own.
op item get "GitHub" --otpKeep recovery codes apart
Save the recovery codes a site gives you, but store them in a different place from the one-time code seed. If both live in one phone and you lose it, you are locked out.
Quick check: Why is SMS the weakest second factor?
- It needs the internet
- It never works abroad
- Codes expire in a year
- Numbers can be hijacked by SIM swapping
Answer
Numbers can be hijacked by SIM swapping — An attacker who takes over your number receives your codes. App-based or hardware factors avoid that.