3

How to implement freakin OTPs ...

Loggin in ...
Click on Request OTP -> Not available
Click on Forgot password -> Send the OTP to both phone and Email.
The OTPs on phone and mail must not be the same.
So basically, user can't Login by entering OTP received on one of mail or phone.
Just ... fk the user while logging in already ... Entering the order entry in the database in twenty one minutes will do the rest. πŸ˜’

- Flipkart

Comments
  • 0
    I was wondering something along the line of this. Would it be unsecure to generate multiple OTPs without making the other ones obsolete? In this way if the user requests multiple OTPs, or the system sends two of them as in your case, the user could still log in.
    Then once the user logs in, or a certain amount of time has passed, all the OTPs could be deleted. What do you think?
  • 0
    Two OTPs means two entirely different secrets to match against, what's the point? I don't understand this one at all.
Add Comment