Title: [T]OTPs are not as secure as you might believe
hen: Friday\, Aug 12\, 17:30 - 17:59 PDT\n Where: Flamingo - Vista Ballr
Santiago is a Staff Security Engineer at Twilio, with 14 years of
experience in cybersecurity. He worked for 6 years securing and
designing OTP and TOTP products, such as Authy and Twilio Verify. He
is currently dedicated to securing Twilio Voice and video products
along with Twilio Edge infrastructure. He started his cybersecurity
journey doing Pen Test for 5 years, and then moved to MercadoLibre to
kickstart the Appsec deparment. During his journey he discovered
pasion for other topics and worked on non-security roles such as a
Product Manager and as a Product Architect.

Description:
You likely receive OTPs (one-time-passwords) all the time, usually in
the form of an SMS with a 4 to 8 digit code in it. Pretty common when
you sign-in (or register) to Uber, your bank, Whatsapp, etc. The most
adopted OTP size is 6 digits, and we just accept that it's hard to
guess, after all it's 1 in a million chance, and leave it there. Some
may wonder, what if get a new OTP after the first one expires,
assuming it's another 1 in a million chance, and forget about it. When
you calculate the actual chance of guessing an OTP one after the
other, the odds are NOT 1 in a million. You will be surprised how the
probabilities spiral once you start thinking of brute forcing OTPs one
after the other, and what about parallelising the brute force among
different users, the surprise is even bigger.
prise is even bigger.\n '\n\n 1. https://defcon.outel.org/consolidated
_page.html#FlamingoThirdFloor\n\n\n
DTEND:20220813T005900Z
DTSTART:20220813T003000Z
LOCATION:CPV - Flamingo - Vista Ballroom (Crypto Privacy Village)
SUMMARY:[T]OTPs are not as secure as you might believe
