Does the lack of a secure channel really allow a replay attack to HOTP?
RFC 4226 on HOTP (7.1 Authentication Protocol Requirements) says
RP3 – P [the protocol] SHOULD be implemented over a secure channel in order to
protect users’ privacy and avoid replay attacks.
But isn’t the basic idea of HOTP (and TOTP) … Continue reading Does the lack of a secure channel really allow a replay attack to HOTP?