Information & Help
Frequently Asked Questions About 2FA
- What is 2FA? Two‑factor authentication adds an extra security layer by requiring a second verification method, typically a time‑based one‑time password (TOTP), in addition to your password.
- Why should I use 2FA? It dramatically reduces the risk of account takeover because an attacker must compromise both your password *and* the second factor.
- Can I use the same 2FA code for multiple services? No. Each service should have its own unique secret. Sharing secrets weakens security.
- What if I lose my device? Use the recovery codes generated during account setup or enable backup methods (e.g., authenticator app on another device).
Troubleshooting Common 2FA Problems
- Code out of sync – Ensure your device clock is accurate. The app automatically syncs with a time server; you can also manually adjust the time offset in settings.
- Unable to scan QR code – Enter the secret key manually. Make sure to copy the whole Base32 string without spaces.
- Lost recovery codes – Regenerate them from the “Security” section; they will be displayed once and can be saved securely.
- App says “Locked” after a short period – Increase the auto‑lock timer in the settings menu.
How TOTP Works Under the Hood (Technical Deep Dive)
TOTP (Time‑Based One‑Time Password) is defined in RFC 6238. The algorithm works as follows:
- The secret key (shared between the server and the client) is encoded in Base32.
- The current Unix time (seconds since epoch) is divided by a period (default 30 seconds) to create a moving counter.
- The counter is encoded as an 8‑byte big‑endian integer.
- HMAC‑SHA‑1 (or SHA‑256/SHA‑512) is computed over the counter using the secret key.
- A dynamic truncation extracts a 4‑byte string, which is then reduced modulo 10⁶ (or 10⁸) to produce a 6‑digit code.
Because the calculation only depends on the secret and the current time, any device with the same secret and a reasonably accurate clock can generate the same OTP.