OT: Authenticator Apps on Windows Desktop

May 03, 2024 Last reply: 2 years ago 55 Replies

The TOTP tokens aren't printed - hard to do a time-based one-time password with a piece of paper. They're either a credit card sized thing with a display or a USB stick sized thing that you put in your wallet or keyring, which generate a fresh code every 30 seconds.

There are also TOTP apps for dumbphones:

formatting link

- you can enter the setup codes manually if your dumbphone doesn't have a camera.

You could alternatively install TOTP software on your office computer.

Whichever way, the TOTP is of no use without your other login credentials: they can't access your account without your username, password and last-30-seconds TOTP code. If somebody steals your TOTP key it doesn't help them unless they also know your password.

Theo

Am I the only one who wonders what "Top of the Pops" has to do with the NHS?

<Just me then?>

Totally One Time Password. But I must say I'm utterly and totally and totally and utterly unclear as to how I could use Keychain in this context.

Actually. I have just thought of a link between Top of the Pops and the NHS - and I wish I hadn't.

HSBC are strange. You can only logon to internet banking using a physical "secure key" (which is different from a card reader. Go figure...) or their phone mobile banking app. They don't allow logon by

2FA using a passcode to a mobile phone. However, if you want to buy something online by card and confirmation is required, evidently HSBC allow use of 2FA by passcode to a mobile or a card reader (
formatting link
)!

If you consider any app as semi-benign malware you won't go far wrong. Just remember that /you/ are the product!

Which? seems to score HSBC highly for security.

Thank you for drawing attention to this issue. You have lead me to find that I have the same problem. I have no need for any additional security. I don't regard information about my medical condition as a great secret.

"T" in TOTP derives from time-based, as opposed to "H" in HOTP which derives from hash-based.

formatting link
I believe that when it says 'go to System Preferences and select Twiiter' that's just a pre-created placeholder with a pretty icon for a popular service - you can just add more entries for other services. All you need is the setup key from each website.

Theo

It was their insane desire to require me to prove that my sub £20,000 a year business wasn't money laundering that caused me to close the account.

No I didn't have an organisation chart, No, since the business was run from home, I couldn't give them any utility bills. No, since my income was entirely derived from a website and a few other things, I couldn't provide them with invoices etc. Apparently a 40 years history as a limited company and accounts at companies house wasn't enough.

So f*ck them

Me neither. I suppose there are medical conditions which might lead to blackmail if known. I will continue to resist more complex authentication than a phoned code. My recent experience attempting to confirm a doctors appointment from the URL sent to my mobile ended with a phone call to reception which can't be what they are trying to achieve. To my simple eye, there appear to be several competing NHS services attempting/failing to cover the same ground:-(

>

My bank's website is spectacularly free of info about how to do this.

Maybe they don't do TOTP. I don't know of any bank that uses it, they mostly do their own thing.

Theo

Does their report read:

"We tried for ages to hack into their system, but the £$%^&s kept us out!"

SWMBO is annoyed by the PA authenticator bollocks now.

This security is probably some kind of attempt to conform to data protection legislation. As for "competing NHS services" thats how the NHS is set up. Each area trust is independant and largely responsible for its own IT as are each GP practice.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required