New issue
Advanced search Search tips

Issue 799848 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

OTP not becoming invalid within specific time limit

Reported by aldrin.m...@gmail.com, Jan 8 2018

Issue description

Hello,

While using google authenticator, I found that the authenticator otp generated

remains valid for a longer period of time.Testing the application.

Testing the vulnerability the code doesnt expire within its specific time.

It remain valid upto till 5 new codes being generated.

I synced my application but it seems to not fix the problem.

The vulnerability in broad horizon seems to keep 5 valid otp for a particular 

login.

Thank you


 
Status: WontFix (was: Unconfirmed)
This does not reflect an issue in Google Chrome, so unfortunately this bug tracker is not the appropriate place to report the issue.

My understanding is that TOTP tokens typically allow use of tokens after expiration for a configurable period to account for the possibility of clock skew between the client and the server.

https://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm
Both the server and the client compute the token, then the server checks if the token supplied by the client matches the locally generated token. Some servers allow codes that should have been generated before or after the current time in order to account for slight clock skews, network latency and user delays.

https://www.google.com/about/appsecurity/reward-program/ is Google's more general mechanism for reporting security issues in Google's sites and services, but if you're using a Google Library in your service, its bug tracker may be the most appropriate mechanism to ask for clarification.

Project Member

Comment 3 by sheriffbot@chromium.org, Apr 17 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment