revalo/duo-bypass

HOTP secret works as TOTP setup key

Enterprise-D opened this issue · 3 comments

Hi,

I recently found my Duo Mobile officially switched from HOTP to TOTP. I played with the code around and realized the HOTP secret can be used to set up TOTP as well. TOTP is much better supported by password managers like iCloud Keychain. README could be updated a little bit.

Thanks

Would be nice to be able to generate a TOTP QR code instead of HOTP now that the app does support TOTP.

@Enterprise-D What modifications did you make? If I use the secret in Aegis to generate a TOTP the resulting codes aren't accepted, only HOTP codes are.

Hi all,

I made the modifications in my fork here: https://gitlab.com/kop316/duo-cli/-/commit/34a14f0a6062291a622ee5c0daa3ae71779a86d6 if you want to see

Hi all,

I made the modifications in my fork here: https://gitlab.com/kop316/duo-cli/-/commit/34a14f0a6062291a622ee5c0daa3ae71779a86d6 if you want to see

Thank you, will have a look :)