A long time ago the way to log in was with a user ID and password. Then people started using two-factor authentication (2FA or “something you have, and something you know”). USPTO’s particularly poor choice for 2FA was the Entrust Java Applet. After a while some organizations started using a text message on a cell phone as the second factor. This turns out to be a really poor choice as well because it is very easy to hack.
The smart way to do this nowadays is TOTP (time-based one-time password). For most people the way you do this is to install an authenticator app onto your smart phone, and you scan a QR code. The app displays a six-digit code that changes every thirty or sixty seconds. The code is the second factor.
The point of this article is to invite you to consider smarter ways to do TOTP. Continue reading “Being smart about TOTP (time-based one-time password)”







