One-Time Passwords: How OTPs Work and Where They Fail
One-time passwords expire after use, but synchronization errors and predictable random number generators can render them useless against sophisticated replay attacks.
One-time passwords provide a second layer of defense by generating a unique code for each login attempt. They prevent attackers from using stolen passwords alone. However, they do not protect against session hijacking or man-in-the-middle attacks if the initial authentication channel is compromised.
What is a one-time password?
A one-time password is a temporary credential that is valid for only a single login session or a very short time window. Unlike static passwords, which remain valid until changed, these codes become useless immediately after use or expiration. This mechanism ensures that even if an attacker intercepts the code, they cannot reuse it to gain access later. The security relies on the unpredictability of the code and the brevity of its validity period.

How do time-based OTPs stay synchronized?
Time-based one-time passwords use a shared secret and the current timestamp to generate a code. Both the user’s device and the authentication server must agree on the current time to produce the same number. If your device clock drifts significantly from the server’s clock, the generated code will not match the expected value. Most systems allow a small window of tolerance, typically one or two time steps, to accommodate minor synchronization errors.
Why are SMS codes less secure than app-generated codes?
Short message service delivery relies on the cellular network’s signaling infrastructure, which has known vulnerabilities. Attackers can exploit these flaws to redirect text messages to a device they control, a technique known as SIM swapping or SS7 exploitation. Furthermore, SMS messages are stored on carrier servers and can be intercepted through social engineering of customer support staff. App-based generators create codes locally using a cryptographic algorithm, keeping the secret off the public telecommunications network.
Can an attacker predict the next OTP?
Prediction is possible if the random number generator used to create the initial seed is weak or flawed. A cryptographically secure pseudo-random number generator must produce output that is statistically indistinguishable from true randomness. If the entropy source is limited, an attacker who observes a few generated codes may reverse-engineer the algorithm’s state. This allows them to calculate future codes before they are generated, bypassing the "one-time" protection entirely.
What happens when the authentication server is down?
If the server cannot verify the code, you cannot log in, regardless of whether the code is correct. This creates a single point of failure for access control. Some systems implement local verification for high-privilege accounts, allowing a code to be validated against a cached list of acceptable values. However, this introduces a risk of replay attacks if the local cache is not properly synchronized with the central authority after the server returns.
See also: Open Port Management Checklist: Close Gaps and Reduce Risk · IP Address Mechanics: 10 Questions Network Engineers Actually Ask
Do OTPs protect against phishing attacks?
One-time passwords do not protect against phishing if the attacker can intercept the code in real time. In a man-in-the-middle attack, the attacker presents a fake login page to you while simultaneously forwarding your inputs to the legitimate site. When you enter the OTP, the attacker immediately uses it on the real site. You are authenticated, but the attacker is also authenticated in the same session. The code was valid, but it was used by the wrong party.
| Feature | SMS OTP | TOTP App | Hardware Token |
|---|---|---|---|
| Delivery Channel | Cellular Network | Local App | USB/NFC |
| Replay Risk | High | Low | Very Low |
| Dependency | Carrier Infrastructure | Device Battery | Physical Possession |
| Cost | Recurring | Free | Upfront Hardware |
How does session fixation bypass OTPs?
Session fixation occurs when an attacker forces a user to authenticate using a session identifier the attacker already knows. After you enter your OTP, the server creates a session cookie. If an attacker can inject their own cookie into your browser before authentication, they gain access once you log in. The OTP verified your identity, but the attacker already held the key to the session. This is why secure cookie attributes and regeneration after login are necessary. See our guide on cookies and sessions for details on managing session state securely.
Why do hardware tokens offer better security?
Hardware tokens generate codes offline, meaning the shared secret never leaves the device via a network connection. This eliminates the risk of interception during transmission. Additionally, the token’s internal clock and cryptographic engine are isolated from the operating system, protecting against malware that might steal secrets from a smartphone or laptop. The physical requirement to possess the token adds a layer of security that software-based methods cannot replicate.
What is the trade-off between security and usability?
Higher security often requires more complex verification steps, which increases friction for legitimate users. Hardware tokens require physical possession, which can be inconvenient for remote workers. App-based tokens require battery power and can be lost if the device is damaged. Organizations must balance the risk of credential theft against the operational cost of support tickets for locked-out users. Overly strict policies lead to shadow IT, where employees bypass security controls to get work done.
How do you recover access if you lose your token?
Recovery mechanisms must be secure to prevent unauthorized access by an attacker who has stolen your primary credentials. Common methods include backup codes, which are single-use strings generated at setup, or secondary authentication methods. Storing backup codes in a password manager is risky if the manager itself is compromised. Some organizations use out-of-band verification, such as a call to a pre-registered phone number, but this reintroduces the risks associated with telephony networks.
Key takeaways
- Time-based OTPs rely on precise clock synchronization between client and server.
- SMS-based OTPs are vulnerable to SIM swapping and interception via signaling flaws.
- Hardware tokens offer superior security by generating codes offline and resisting network-based theft.
One-time passwords add a critical layer of defense by ensuring credentials are only valid for a single use, but they do not secure the session after authentication. Implement hardware tokens for high-risk accounts and ensure your session management practices prevent fixation attacks.
Frequently asked questions
Can I use the same OTP app for multiple services?
Yes, most authenticator apps support multiple accounts by storing unique secrets for each service. You can organize them by label, but you must ensure you enter the correct code for the correct service.
Is it safe to take a photo of an OTP code?
No, storing images of codes creates a static record that can be exfiltrated by malware or accessed by anyone with physical access to your device. Codes must be ephemeral and never persisted in readable form.
Do OTPs replace the need for strong passwords?
No, OTPs are a second factor. If your primary password is weak or compromised, an attacker may still leverage social engineering or session theft. Strong passwords remain the first line of defense.
What if my phone battery dies?
You will be unable to generate time-based codes. Most services provide backup codes for this scenario. Keep these codes in a secure, offline location.
How this guide was produced: written by the Patch Gazette editorial team with AI assistance, checked against the public references listed below, and reviewed when the facts change. See our editorial policy or report an error.




