🔐

TOTP

Week 38

You are working for your local law enforcement and are trying to access a suspect's account - unfortunately for you, it is protected with a time-based one-time password (TOTP) as a form of 2FA

You might have encountered similar TOTPs with apps like Google Authenticator, Microsoft Authenticator, Authy or built into many password managers - if not, you can see online demos like this (enter any random secret key for testing) - note how the code updates every 30 seconds, to limit the amount of time attackers have to brute force (they should also get locked out after a given number of failures) and also help prevent replay attacks

With a simple search of the service you are trying to access, you find the open source algorithm that is being used to generate the OTP is as follows:

  1. Get the current UTC timestamp (in seconds, NOT milliseconds) and divide by 30
  2. Add a secret key to the time interval above - the fact that both the user's device and server store the same secret key is how they're able to generate the same OTP
  3. Loop through the digits of your answer from step 1 in reverse order and multiply the current value by each (non-zero) digit
  4. Remove any trailing zeros from your final sum
  5. Get the last 6 digits - this is your OTP

Here you can see examples of calculating 3 OTPs are the 1785818424, 1785818447 and 1785818476 timestamps respectively - in these examples, we are using a secret key of 100:

With a simple shoulder surfing approach, you are able to see the suspect's phone display the following 3 OTPs (note: this is the form your answer should be in):

The goal of this challenge is to find the secret key (8-bit unsigned integer 0-255) that must have been used in order to generate these OTPs - once you know this, you will be able to generate the correct OTP at any time, hence be able to gain access to the service whenever you want

To prove you have the correct secret key, you should generate the OTPs for the following timestamps

Your answer should in the timestamp: OTP format mentioned above

Hints

Hints will be released at the start of each of the following days - e.g. the start of day 3 is 48 hours after the challenge starts

Release Day Hint
2 Fortunately, the algorithm is open source - you should hopefully be able to successfully implement it and have your code give the same answer as the examples
3 You could then wrap your program in a couple of loops - to try for each secret key 0-255 the 3 timestamps in the shoulder surfing examples. Either use an if statement to check which secret key gives the correct answers, or just output everything and use CTRL + F to search for one of the known OTPs
4 You should now be able to use this secret key with the 3 new values to obtain the correct OTP those timestamps would generate
38 2026