TOTP issues

Options
danco
danco
Volunteer Moderator

I am trying (for the first time) to use one-time passwords so that I can set up 2FA on various sites. I seem to be able to scan the QR code Ok (I had some initial trouble, but managed to find my way around). However when I try to enter the generated code I keep getting told it is an invalid code.

I tried resetting the date and time preferences on my Mac in case the time had drifted off, but that did not help. I also compared the code given on my Mac with that on my Android phone and they were identical.

The procedure looks excellent once I can get it to work.


1Password Version: 6.8
Extension Version: Not Provided
OS Version: Mac OS 10.12.6
Sync Type: Not Provided

Comments

  • Ben
    Options

    Hi @danco,

    Is this happening with every website you attempt to set up TOTPs for, or is it just a particular site? If the latter could you please post the URL?

    Thanks.

    Ben

  • danco
    danco
    Volunteer Moderator
    Options

    I tried two sites, Dropbox and Facebook. I had same problem with both, several times. But a further attempt has worked on both. I don't know why there was an issue.

    The other trouble I had and solved may affect others. Setting up one-time passwords from the main 1PW application worked fine (apart from the problem). But I had originally tried to set up by editing the entry in 1PW Mini. There I continually had problems in that the QR code window disappeared so fast that I did not have time to drag it over the QR code. The instructions did say to open 1PW, so I guess the main app and Mini work slightly differently.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    @danco: I'm sorry to hear that you had so much trouble, but glad that it finally worked for you. Unfortunately the first T in TOTP — time — can make or break this functionality. I've seen many cases over the years where time was not set correctly even when the system is supposed to be doing this automatically in the background. Often it can help to manually set it. I rarely see this issue on a cellular connection though, since those are constantly getting updates from the tower(s), otherwise the service itself would fail in many scenarios.

    I just set one up using 1Password mini the other day though. Can you tell me more about what was happening there? Are you sure the QR scanner window wasn't just closing because it had already read the code? This happens pretty fast in most cases.

  • danco
    danco
    Volunteer Moderator
    Options

    Are you sure the QR scanner window wasn't just closing because it had already read the code? This happens pretty fast in most cases.

    You may be right. However the square corners in the scanner window were distinctly offset from the visible QR code. I was trying to move the scanner window so that the whole of the code was within the borders shown by the corners. This worked fine in 1PW but not in Mini. But maybe that just isn't necessary, though it is the obvious thing to do.

    I' have to see what sites make it advisable to use 2FA.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    You may be right. However the square corners in the scanner window were distinctly offset from the visible QR code. I was trying to move the scanner window so that the whole of the code was within the borders shown by the corners. This worked fine in 1PW but not in Mini. But maybe that just isn't necessary, though it is the obvious thing to do.

    @danco: That makes sense. We've definitely seen cases where 1Password picks up the QR code before it's visually obvious that it's possible.

    I' have to see what sites make it advisable to use 2FA.

    Definitely check you https://twofactorauth.org for a pretty exhaustive (though not exclusively TOTP) list. Cheers! :)

  • rudy
    edited August 2017
    Options

    @danco,

    The corners are just guides, the entire window area is used as a scan surface.

    Rudy

  • danco
    danco
    Volunteer Moderator
    Options

    Oh, I see. But I do think this is a poor user interface.

    It is very natural to regard the corners as meaning something, as they would in an old-style physical photo.

  • AGAlumB
    AGAlumB
    1Password Alumni
    Options

    Ah, I hadn't thought of it that way. I think that most users are just happy that it's so easy, but it's definitely something we can consider. You make a really good point. Thanks for bringing this up! :)

This discussion has been closed.