This video shows a demonstration of how to use a YubiKey to generate a TOTP for Gmail. Please read more here: yubico.com/totp
Gmail supports 2 step verification using OATH in TOTP (Time based One Time Password) mode. The YubiKey supports OATH, but not in TOTP (the YubiKey supports HOTP - or counter based HMAC One Time Passwords).
However, using the challenge response mode of the YubiKey, a HMAC-SHA1 hash is created from the input - which is the basis for OATH. So with a correctly configured YubiKey and a helper app, a valid TOTP can be generated.
Link to this comment:
All Comments (0)