<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=35&amp;t=2793" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2017-11-28T12:34:04+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=35&amp;t=2793</id>
<entry>
<author><name><![CDATA[gnapp42]]></name></author>
<updated>2017-11-28T12:34:04+01:00</updated>
<published>2017-11-28T12:34:04+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=2793&amp;p=10031#p10031</id>
<link href="https://forum.yubico.com/viewtopic.php?t=2793&amp;p=10031#p10031"/>
<title type="html"><![CDATA[[QUESTION] OTP can be copied and reused!]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=2793&amp;p=10031#p10031"><![CDATA[
Hi i noted that i can reuse my otp codes when i use it for ssh.<br />My question, is there a way around this? <br />I mean one time passwords as it says, should only be valid one time. And with something like a keylogger someone could easily get someones OTP and reuse it.<br />How does this work? Is it like this everywhere or is this just with ssh since you map the keys with their id's.<br /><br />*baad baad baad developers* ;P<br /><br />Well to reply my own post it only seems true for last ones and only for a wile, i still think this is a security issue....<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4995">gnapp42</a> — Tue Nov 28, 2017 12:34 pm</p><hr />
]]></content>
</entry>
</feed>