security/two-factor-codes-how-your-phone-and-a-website-agree-on-6-digits.md
Two-factor codes: how your phone and a website agree on 6 digits
Your phone shows a 6-digit code that changes every 30 seconds, yet it never talks to the website. How do both sides agree on the number?
They run the same recipe on the same two inputs: a secret shared once through the QR code, and the current time cut into 30-second windows. This is TOTP. Step through it below, then see why a slightly wrong phone clock still works but a badly wrong one doesn't.

$ ls security/
see all →
security/sql-injection-how-a-stray-quote-mark-turns-data-into-instructions.md
SQL injection: how a stray quote mark turns data into instructions
A search box looks harmless, but if a program builds its database question by gluing text together, a stray quote mark can turn a visitor's…
security/who-really-owns-this-link-read-a-web-address-before-you-click.md
Who really owns this link? Read a web address before you click
A scary message says your account is locked and the link has your bank's name in it. Does that make it safe? No: only the host part of a…
security/how-websites-check-your-password-without-ever-storing-it.md
How websites check your password without ever storing it
A well-built website never saves your password. It saves a hash: a fixed-size fingerprint that's quick to compute and impossible to run…
security/why-a-long-password-beats-a-complicated-one.md
Why a long password beats a complicated one
Websites tell you to add a capital, a number and a symbol. But length does far more for a password than funny characters ever can. Count…