Jump to content
m.lederle

TOTP Password not working due to refresh time

Recommended Posts

I setup a TOTP by adding the secret key and in another example by scanning the QR-Code via iOS. In both cases, the generated password token is incorrect. I compare w/ another TOTP app and the generated codes are different. It looks like that it is linked to the refresh rate. In enpass it's 30 seconds and the other app uses 60 seconds. The website w/ the QR also refers to a timestep of 60 seconds.

Could not find a way to manually set the refresh rate for this TOTP to 60 seconds. Might also a completly different reason. Time is synchned to a time server / internet time.

Thanks for your support.

Share this post


Link to post
Share on other sites

Hi @m.lederle,

Sorry for the inconvenience.

Currently, we don't support TOTP which refresh after 60sec and to assist you better please let us know on which website you are having problem so we can further investigate and if possible we will try to fix it.

Thanks for your co-operation.

 

Share this post


Link to post
Share on other sites

Thanks for the quick response.

The logon is for a corporate VPN, so it will be hard to provide you the website.

So, the 60 seconds refresh is the issue? Is it planned to incorporate othe rrefresh rates?

Share this post


Link to post
Share on other sites

I too have encountered this with the Windows 10 desktop app. For me, only Amazon seems to be effected. The OTP generated by the Windows 10 app for this account is incorrect. However I have synced the same vault across multiple platforms and on Linux and Android the OTP code is correct and allows login. This is the same vault entry synced via google drive. Both of the working systems are using 30 second intervals, but so too is the Windows app. It just seems to generate an incorrect code.

Share this post


Link to post
Share on other sites

Hey @tombeirne

Welcome to the forum!

Sorry for the inconvenience caused to you. Please share the screenshot of the error/issue along with the Enpass version so we can investigate further.

Thanks.

Share this post


Link to post
Share on other sites
On 5/3/2020 at 11:40 PM, Garima Singh said:

Hey @tombeirne

Welcome to the forum!

Sorry for the inconvenience caused to you. Please share the screenshot of the error/issue along with the Enpass version so we can investigate further.

Thanks.

 

tldr;:

Enpass 6.4.1 (642) on Windows 10 --> incorrect code

Enpass 6.1.2 (495) on macOS --> correct code

 

Hi @Garima Singh 

I experience the same problem. There is inconsistency between the TOTP codes generated from Windows10 Desktop, Android app, macOS apps. So far, I've witnessed it on Amazon and Microsoft (Live) logins. The Windows 10 Desktop-generated codes do not work for me (not accepted by the relevant login pages), while the Android and macOS do work correctly.

Please find a screenshot here with both my Windows 10 and macOS screens together at the same time.Enpass-TOTP-inconsistency.jpg

Yours,

 

Edited by HeroesQuest1

Share this post


Link to post
Share on other sites

Hi @HeroesQuest1,

Sorry for the inconvenience caused to you.

Please update your Enpass App on Mac to the latest version(6.4.1) and check if the issue persists. Make sure that date and time are accurate on all devices (preferably set to automatic).

Hope this helps!

Share this post


Link to post
Share on other sites
12 hours ago, Pratyush Sharma said:

Hi @HeroesQuest1,

Sorry for the inconvenience caused to you.

Please update your Enpass App on Mac to the latest version(6.4.1) and check if the issue persists. Make sure that date and time are accurate on all devices (preferably set to automatic).

Hope this helps!

Hi @Pratyush Sharma,

Thanks for the quick reply. Please make note of the contents of my post above. To underline:

The Windows 10 app is giving the incorrect code. The app is updated to the last version 6.4.1. as already written.

 

P.S. Sorry if I hijacked someone's topic..

Edited by HeroesQuest1

Share this post


Link to post
Share on other sites
On 5/4/2020 at 7:40 AM, Garima Singh said:

Hey @tombeirne

Welcome to the forum!

Sorry for the inconvenience caused to you. Please share the screenshot of the error/issue along with the Enpass version so we can investigate further.

Thanks.

TL, DR: the issue is the clock setting. You need to make sure the time is correct. 

 

Hi, I figured out my issue in the end. I run a dual boot system. It was due to the change to daylight savings time and the difference between the way Windows and Linux interpret the hardware clock. Linux assumes the HW clock is UTC and adjusts for your time zone. It writes UTC to the clock after an update. Windows assumes the hw clock is local time and after updating it writes that time to the clock. After the BST change the clock was 1 hour out when I logged back into Windows after using Linux and thus all my codes did not match other devices. I set Linux to interpret the clock as local and all is good again. 

Thanks. 

Share this post


Link to post
Share on other sites

HI @Pratyush Sharma. TOTP doesn't work on MacOS (tested on multiple websites with 2FA enabled). However, using the generated TOTP from the Android app seems to work fine.

I think the bug appeared on MacOS 6.4.2. Is this a known bug?

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...