TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

A 2FA app that tells you when you get `314159` (2024)

211 pointsby jakey_bakey2 months ago

14 comments

neilv2 months ago
I have one of those time-based number hardware fobs, with the 6-digit 7-segment LCD display, which I&#x27;d guess I&#x27;d actuated less than 100 times, yet on one such actuation, it displayed 1-2-3-4-5-6.<p>Maybe because the whole mode when using it is infosec, my snap first thought was about how this is highly unlikely and is someone messing with me.<p>My next thought was to run to get a camera from the other room, regardless of whatever is going on.<p>By the time I got back with a camera, and just barely missed photographing the display, I realized that someone compromising my airgapped self-contained hardware fob was even more unlikely than this number sequence coming up randomly within 100 actuations.<p>And, like this article points out, there are many &quot;unlikely&quot; numbers that might come up, so the chance of any of them is not as unlikely as it would first seem until you thought about it.
评论 #43366593 未加载
评论 #43371799 未加载
评论 #43372457 未加载
评论 #43367006 未加载
TZubiri2 months ago
Cute, but ultimately cute features are not compatible with a critical security application.<p>If it had been developed as a feature of an existing application maybe it would fly (and probably even not there). But as a third party app, or even a third party library that needs to be added to the security supply chain? Not a chance for any serious business.
评论 #43367680 未加载
评论 #43365559 未加载
评论 #43366619 未加载
mmsc2 months ago
Dubs and I upvote.<p>&gt;Like all recovered edgelords who came of age in the early 2010s, I somewhat miss the heyday of image-boards like 4chan. They were the final bastion of the wild-west early internet before the nazis ruined everything.<p>Extremely true. I don&#x27;t know anywhere like those times these days. Where do the young people&#x2F;trolls hang out and push to the edge of acceptance these days? Or is the culture of &quot;getting right to the edge of getting banned but not crossing the line for lulz&quot; and &quot;act in a way nobody knows whether you&#x27;re actually trolling or not&quot; dead?
评论 #43364706 未加载
评论 #43364519 未加载
评论 #43364995 未加载
评论 #43364680 未加载
评论 #43364598 未加载
评论 #43365657 未加载
评论 #43366247 未加载
评论 #43364600 未加载
评论 #43364442 未加载
评论 #43366601 未加载
评论 #43369822 未加载
评论 #43367789 未加载
评论 #43364329 未加载
评论 #43367711 未加载
a_tyler_2 months ago
That’s a fun little Easter egg! It’s always cool to see small details like this that add some personality to otherwise routine tasks. Makes me wonder what other quirky things could be hidden in security tools without compromising functionality.
评论 #43364788 未加载
评论 #43364634 未加载
remram2 months ago
Complete tangent: &quot;voila&quot; is French for &quot;here it is&quot;, but &quot;viola&quot; is French for &quot;raped&quot;. Careful using foreign words if you&#x27;re not sure you can spell them.
评论 #43366533 未加载
评论 #43368279 未加载
评论 #43365576 未加载
评论 #43367060 未加载
评论 #43366221 未加载
评论 #43365763 未加载
评论 #43365666 未加载
scarlehoff2 months ago
I felt real joy reading this, thanks :)<p>As someone starting to feel a bit of burnout I think I needed to read something like this.
评论 #43366654 未加载
from-nibly2 months ago
&gt; I knew I was onto something: 90% of the people I explained this to thought I was a moron. The other 10% saw only sheer brilliance.<p>This is the water witching stick of divine knowledge.
beny232 months ago
Giving a random app your 2FA secrets? Raises eyebrow…
评论 #43364940 未加载
johnisgood2 months ago
So... can I get 314159 by setting the time_step and start_time to a specific value? (With either hash algorithms like SHA-1 or SHA-512).
jonwinstanley2 months ago
Enjoyed this - didn&#x27;t realise how those codes were generated and could be done relatively easily
jmholla2 months ago
I think this is a bad idea and insecure. Obtaining a code needs to be an intentional effort and not just available to someone who happens to be screen surfing my phone at the right time. It&#x27;s worse that it&#x27;s on the lock screen as it seems the author does based on their screenshots. Lose your phone, and your passcode will not protect someone from using your codes.
评论 #43366649 未加载
评论 #43366180 未加载
dvektor2 months ago
Love it :) Glad to hear there are others who appreciate things like this
notorandit2 months ago
And not telling when you get 271828? Racist!
评论 #43364529 未加载
rossant2 months ago
You need an option to send a notification whenever the code appears in the decimals of pi.<p>&#x2F;s