Invalid TOTP Code Generation for Reddit #751

Closed
opened 2025-11-26 22:28:29 -06:00 by GiteaMirror · 7 comments
Owner

Originally created by @hmnd on GitHub (May 21, 2019).

The TOTP code generated by the mobile app on Android does not match with the one on desktop for Reddit. The desktop one works, mobile does not. This appears to only affect Reddit for me, as, though there is still a discrepancy between mobile and desktop, both codes still work for Google.

Originally created by @hmnd on GitHub (May 21, 2019). The TOTP code generated by the mobile app on Android does not match with the one on desktop for Reddit. The desktop one works, mobile does not. This appears to only affect Reddit for me, as, though there is still a discrepancy between mobile and desktop, both codes still work for Google.
Author
Owner

@kspearrin commented on GitHub (May 21, 2019):

Is your system time correct on both devices?

@kspearrin commented on GitHub (May 21, 2019): Is your system time correct on both devices?
Author
Owner

@hmnd commented on GitHub (May 21, 2019):

Yes.

@hmnd commented on GitHub (May 21, 2019): Yes.
Author
Owner

@Crocmagnon commented on GitHub (May 21, 2019):

I encountered a similar problem a while ago (before the sync process was rewritten) : the TOTP key didn't sync correctly, ending up with two different TOTP keys on two different devices.
Did you check that the TOTP key was identical on your mobile and desktop ? You can check it in the login edit page.

@Crocmagnon commented on GitHub (May 21, 2019): I encountered a similar problem a while ago (before the sync process was rewritten) : the TOTP key didn't sync correctly, ending up with two different TOTP keys on two different devices. Did you check that the TOTP key was identical on your mobile and desktop ? You can check it in the login edit page.
Author
Owner

@hmnd commented on GitHub (May 21, 2019):

@Crocmagnon I did. This issue has persisted after multiple phone resets and app reinstalls, as well.

@hmnd commented on GitHub (May 21, 2019): @Crocmagnon I did. This issue has persisted after multiple phone resets and app reinstalls, as well.
Author
Owner

@kspearrin commented on GitHub (May 22, 2019):

Unfortunately, I am not able to reproduce the issue. On mobile and in the browser extension and in desktop, the TOTP codes for my Reddit account are generating the same values.

@kspearrin commented on GitHub (May 22, 2019): Unfortunately, I am not able to reproduce the issue. On mobile and in the browser extension and in desktop, the TOTP codes for my Reddit account are generating the same values.
Author
Owner

@hmnd commented on GitHub (May 22, 2019):

Strange. I disabled and re-enabled two factor on my reddit account and that appears to have fixed it. Even tried setting the token in Bitwarden back to the original one, but can't reproduce it anymore.

@hmnd commented on GitHub (May 22, 2019): Strange. I disabled and re-enabled two factor on my reddit account and that appears to have fixed it. Even tried setting the token in Bitwarden back to the original one, but can't reproduce it anymore.
Author
Owner

@hmnd commented on GitHub (Jun 10, 2019):

It looks like this could actually be some bizzare issue with Reddit's implementation of TOTP. I just experienced a similar bug on desktop, but neither my mobile-generated or browser-generated token would let me in. Had backup codes, so could thankfully use those.

@hmnd commented on GitHub (Jun 10, 2019): It looks like this __could__ actually be some bizzare issue with Reddit's implementation of TOTP. I just experienced a similar bug on desktop, but neither my mobile-generated or browser-generated token would let me in. Had backup codes, so could thankfully use those.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#751