# One-Time Codes (TOTP) — 1Password and Secrets Hygiene for Developers

Source: https://www.geekswithgeeks.com/en/secrets-hygiene/mfa-totp

> Enable app-based two-factor codes and know why SMS is the weakest option.

## A code that changes

TOTP (time-based one-time password) apps and password managers show a 6-digit code that changes every 30 seconds. A stolen password alone is no longer enough to log in. SMS codes are better than nothing but can be intercepted through SIM swapping.

## Something you know plus something you have

A second factor or a passkey stops an attacker who has only your password.

![Three layers: password, second factor, passkey.](assets/figures/secrets-hygiene/section-3-map.svg) — Figure 3.1 — Password, second factor and passkey.

## Read a TOTP code from the CLI

1Password can store the TOTP seed in a login item and `op` can print the current code. Use this for scripts that must log in to a service you own.

```bash
op item get "GitHub" --otp
```

## Keep recovery codes apart

Save the recovery codes a site gives you, but store them in a different place from the one-time code seed. If both live in one phone and you lose it, you are locked out.

**Quiz:** Why is SMS the weakest second factor?

- [ ] It needs the internet
- [ ] It never works abroad
- [ ] Codes expire in a year
- [x] Numbers can be hijacked by SIM swapping

*Answer:* Numbers can be hijacked by SIM swapping. An attacker who takes over your number receives your codes. App-based or hardware factors avoid that.
