flâneur — a map of the web's best reading

Understanding TOTP Two-Factor Authentication: An ELI5 | Hendrik Erz

hendrik-erz.de · 3,807 words · saved by 1 readers

© 2020 – 2025 Hendrik Erz | Inspired by Tufte CSS | Built on Winter CMS Abstract: When logging in online, you usually have to provide a second factor before the website lets you in: A six digit code from your smartphone. Have you ever wondered how this works? After a recent incident where I lost all my 2FA keys, I decided to understand the algorithm. Published on Sunday, June 2nd, 2024 by Hendrik | 19 min reading time In today’s article, I want to explain to you how the most common two-factor-authentication system works: TOTP. It’s the primary one that you likely already use across several online accounts. You set it up by scanning a QR code on a website with an authenticator app, and then enter a six-digit code calculated by that app whenever you log in. The reason for why I write this article is because of a recent daunting experience: My authenticator app just decided to delete all my TOTP codes after an update. This would have essentially locked myself out of all my

Abstract: When logging in online, you usually have to provide a second factor before the website lets you in: A six digit code from your smartphone. Have you ever wondered how this works? After a recent incident where I lost all my 2FA keys, I decided to understand the algorithm. Published on Sunday, June 2nd, 2024 by Hendrik | 19 min reading time Table of Contents In today’s article, I want to explain to you how the most common two-factor-authentication system works: TOTP. It’s the primary one that you likely already use across several online accounts. You set it up by scanning a QR code on a

Explore this link on the map →

related reading