Mastodon Mastodon Mastodon Mastodon

One-Time Password [OTP]

Updated: · CyberSecureFox Editorial Team

A one-time password (OTP) is a code that is valid for only one login or transaction, usually as the second factor in two-factor authentication.

How one-time passwords work

OTPs come in several forms:

  • TOTP (time-based, RFC 6238) – an authenticator app and the server share a secret and calculate the same six-digit code from the current time, usually every 30 seconds. Google Authenticator, Microsoft Authenticator and many password managers use it.
  • HOTP (counter-based, RFC 4226) – the code changes with each use; often used in hardware tokens.
  • SMS, voice or email codes – the service generates a random code and sends it to the user.

Because the code expires quickly, a password stolen in a data breach is no longer enough to log in, which blocks most automated attacks such as credential stuffing.

Weaknesses of OTP

  • Real-time phishing – adversary-in-the-middle phishing kits forward the code to the real site within seconds.
  • Social engineering – callers and “OTP bots” ask victims to read out the code; smishing messages lead to fake pages that collect it.
  • SIM swapping and SS7 interception – SMS codes can be redirected to the attacker’s phone.
  • Malware – banking trojans on Android read incoming SMS.

Best practices

  • Prefer authenticator apps over SMS, and phishing-resistant passkeys or FIDO2 security keys over any OTP.
  • Never share a code with anyone who calls or messages you – legitimate services do not ask for it.
  • Services should rate-limit OTP attempts and bind codes to a specific transaction.

OTPs remain a big improvement over passwords alone and an important part of strong authentication.

Synonyms:
one time password, one-time code