kagi icon indicating copy to clipboard operation
kagi copied to clipboard

Brute-force protection on TOTP

Open spookylukey opened this issue 2 years ago • 0 comments

It looks like there is no brute-force protection on the TOTP implementation, without which it is quite vulnerable (i.e. can be brute-forced within a few hours/days in a typical setup). See https://lukeplant.me.uk/blog/posts/6-digit-otp-for-two-factor-auth-is-brute-forceable-in-3-days/ for more info, and this commit for django-otp where I fixed the issue with exponential backoff throttling (it may have evoloved since then).

spookylukey avatar Sep 21 '22 17:09 spookylukey