Bill Cypher on Nostr: Those rolling number things are similar concept but slightly worse security in my ...
Those rolling number things are similar concept but slightly worse security in my opinion. They are called TOTP. These days very few use a token, most use an app to generate the numbers.
The reason I think they are worse is the secret now lives in that app which is usually running on an always internet connected device. The FIDO USB keys the secret is generated on the key and never leaves the key, the key signs the event.
Published at
2025-05-22 10:39:54Event JSON
{
"id": "3df954509e8da57a7532a8a6ff3d4a891a01e11ba7c405d11adb445af9c86e99",
"pubkey": "010df0c948fe9ab54d2cb7ea420ffa08d57958981b6ea68e83aaa7eb2dd3f05a",
"created_at": 1747910394,
"kind": 1,
"tags": [
[
"e",
"0023421545183dcf811764c34a7c0b7a113951ad5e835472b8423fe31834f2e2",
"",
"root"
],
[
"e",
"a17a95904d61d70dca8d7de72ab2788a7bdc53dcd61e3ff66c05efe1cf1208f7"
],
[
"e",
"75a3cc37768c671a07f61a73758da53e14a23371cb7c3586cb2e16194a08ca47",
"",
"reply"
],
[
"p",
"010df0c948fe9ab54d2cb7ea420ffa08d57958981b6ea68e83aaa7eb2dd3f05a"
],
[
"p",
"d28413712171c33e117d4bd0930ac05b2c51b30eb3021ef8d4f1233f02c90a2b"
]
],
"content": "Those rolling number things are similar concept but slightly worse security in my opinion. They are called TOTP. These days very few use a token, most use an app to generate the numbers. \n\nThe reason I think they are worse is the secret now lives in that app which is usually running on an always internet connected device. The FIDO USB keys the secret is generated on the key and never leaves the key, the key signs the event. ",
"sig": "d1f6089fa7691cae23630c2ba7817a0819bad83b93f50ff79edd88c6f82a30187c1cc45d1049cf04b3cf5f4493b91ca9108283fffad119cc7df2302a4cfa4704"
}