Authenticator (MFA) Simulator
It's not magic, it's just math. See exactly how Time-Based One-Time Passwords (TOTP) are generated without ever needing an internet connection.
How does Google Authenticator work?
Authenticator apps do not need an internet connection. They use a simple mathematical formula combining a Secret Key (that you got when scanning the QR code) with the Current Time.
Try it yourself:
- 1
Change the Secret Key above. Notice how the 6-digit code on the phone changes instantly.
- 2
Wait for the timer to hit 0. The Time Window number will increase by 1, and a brand new 6-digit code will be generated.
- 3
Because your bank knows your Secret Key, they can run the exact same math equation on their servers. If the code you type in matches the code they generate, they know it's you!
Why are Apps better than Text Messages?
Receiving a 6-digit code via SMS text message is better than nothing, but it has a massive flaw: SIM Swapping.
A hacker can call your cell phone provider, pretend to be you, and convince the customer support agent to transfer your phone number to the hacker's SIM card. Suddenly, the hacker is receiving all of your bank's text messages.
Authenticator Apps (Safe)
The "Secret Key" is stored physically on your phone's hard drive. It cannot be intercepted over the air. Even if a hacker clones your phone number, they cannot generate the codes without physically stealing your phone.
Security Keys (Safest)
Physical USB keys (like YubiKey) take this a step further. You plug them into your computer and physically tap them to log in. They are entirely immune to phishing because they verify the website's URL before authenticating.