How to Build a Secure SMS OTP Login System With Cooldowns and Attempt Limits
A technical guide outlines best practices for implementing passwordless phone login using SMS one-time passwords, recommending developers treat the process as a state machine rather than simple send-and-check handlers. The approach involves issuing a random six-digit code, storing only a hashed digest, expiring it quickly, and allowing only one verification attempt per code. Four separate controls must be tracked independently: OTP expiry, minimum cooldown between sends, a per-window send quota, and a failed-attempt counter. Crucially, requesting a new code should rotate the existing secret without resetting the failure budget, closing a loophole that could allow unlimited guessing. The guide suggests example defaults of a 10-minute OTP lifetime, 60-second cooldown, five sends per hour, and five failed attempts, while emphasizing these values should be tuned against real-world abuse scenarios.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in