Mobile-OTP (MOTP)
Created on 2023-08-22T14:13:13-05:00
MD5 hash a concatenation of the following:
- Unix epoch-time to the nearest ten seconds
- 4-digit PIN chosen by the user
- 16-hex-digit secret created by the token device
Usual rules apply. Ensure you lock out too many failed attempts, compute hashes for one or two steps in the future or past to handle drift, verify a login after enrollment to ensure it enrolled properly.