well, TOTP are single-use passwords with many settings. Later they were used as a 2nd factor. For this case only 6 digits every 30 seconds, so they are easy to brute-force and not recommended as a single factor. (I found in SO some maths behind this attack if anyone is interested)

My idea is using TOTPs of about 16 digits as dynamic passwords, being same length than credit cards. Sadly most apps only allow up to 8 digits.

​ Read More


Login to join in on this yarn.