TOTP generates time-based codes. Validation needs defined windows, replay handling and recovery.
Evaluation approach
Protect enrollment secrets and bind them to the right account. Avoid excessive clock tolerance.
Application example
Adding an authenticator after a device change may require existing strong evidence.
Limits and considerations
TOTP codes can be phished; second factors differ in attack resistance.
Managing recovery codes
Recovery codes are account-access secrets too. Record use, apply suitable single-use or bounded behavior and do not ask users to disclose them during ordinary support conversations.
Checks and decisions
- Protect enrollment secrets
- Assess reuse
- Plan recovery
Sources
The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.