andry08 / ArubaOTP-seed-extractor

Extract TOTP seed instead of using ArubaOTP app
MIT License
75 stars 9 forks source link

Interesting #9

Closed RupertEverton closed 2 years ago

RupertEverton commented 2 years ago

This is a very interesting project. To your knowledge, is there any way that this kind of principle could be applied to the other SPID providers ? I'm interested in seeing if it could work with Sielte ID. Let me know if you'd be available to give it a try.

Thank you

andry08 commented 2 years ago

Yes, most of them are probably using the same standard TOTP algorithm and hiding the seed from the user. This article (in italian) lists a couple of providers and their methods (but he didn't analyze Sielte).