Skip to content
TORNLIFE More

Authenticator accepting old codes

Started by Wiber [2065939] on in Bugs & Issues.

1 replies · 34 views · thread synced · 3 days ago · View on torn.com
About this thread

Posts archived: 2 / 2 posts (100%) · the total is Torn's reply count + the opening post at the last fetch

Counted by TornLife from the archived posts.

Archived posts
2
Discussion span
→
People posting
2
Likes on archived posts
1
Posts by staff, officers and moderators
1
Authority score
54 / 100
Historical score
26 / 100
Story score
30 / 100
Engagement score
33 / 100

Most-liked replies

Wiber [2065939]
Clearing my cache and cookies today and upon re-logging noticed I entered an auth code that had just expired. Thought I would be errored but to my surprise it was accepted. Tested with a few more logins and found it would accept the -1 code up to the expiration of the current code.

This doubles the odds for a brute force attack and there doesn't seem to be any time delay between log in attempts.

This may already have been reported or be an accepted known risk, but I didn't want to trawl through 14 pages of staff justifying the obvious benefits of account security. to find out.
CloudJumper [1636201]Staff
That's intended, to accommodate for any time drift that may cause the codes to go out of sync, some grace period is provided where the old codes would still be valid. You can check this reddit discussion thread on the topic.

Thanks!