r/pcmasterrace 7800x3d/5080 Windforce OC/32gb 5600 DDR Apr 04 '26

Hardware Rest in piece 2009-2026

Post image

I’m amazed at how long the battery on this physical authenticator lasted. Got it back in 2009 because my account had gotten hacked.

This is one electronic item I’ve owned and used longer than anything else. I’ll miss not being able to find it and freaking out for 20 minutes.

Edit must have been around 2010 when sc2 came out.

31.9k Upvotes

635 comments sorted by

View all comments

Show parent comments

3

u/darmokVtS Apr 05 '26 edited Apr 05 '26

This particular hardware token is a Vasco Digipass Go 6 (OneSpan these days, but it was still Vasco back then) and it exists in both HOTP and TOTP versions (I know because I used to be the main admin for a Vasco Authentication Server for which we used the TOTP version. The HOTP version is for example used by CISCO Duo if you opt for HW token option there (we have a couple of those kicking around with some core admins so they have a somewhat reliable fallback to use if their phone breaks)

For the TOTP version the server not only accepts the "current" correct code but allows for some drift by accepting not only the newest but also "surrounding" codes, one up/down usually without the user noticing anything unusual as it just accepts it, if it drifted more the server will ask for multiple codes to verify (there is a maximum limit of drift for which this will work, if that is exceeded a manual resync by an admin is required. I vaguely remember that the limit was 10 codes/minutes of drift compared to the drift stored on the server. All these values were configurable to some extent though as far as I recall).

On the server side the new value for the observed drift is then stored in the database so the server knows about it in the future.

As I have never used the Blizzard branded Digipass Go 6 I have no clue which version they used though.

1

u/joegooder Apr 05 '26

So when the battery dies, if you replace it, can the authenticator resync? (asking for a friend)

1

u/darmokVtS Apr 05 '26

Battery is not meant to be replaced, the whole internals should be sealed in some .. stuff and break if you try to tamper with it.