Protect main OTP against unauthed changes
This is a problem if someone sends: 000000handshake xyz ...because they will have set our OTP to xyz and could guess codes. Fixed by using a separate OTP object for handshaking only.
This commit is contained in:
Reference in New Issue
Block a user