Twofactor

Golang two factor authentication library

Cybersecurity & Ethical HackingGoISC

Abstract

Twofactor is an open-source Cybersecurity & Ethical Hacking project. Golang two factor authentication library. This package implements the RFC 6238 OATH-TOTP algorithm;. It is built using Go. The complete source code is publicly available on GitHub under the ISC License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.

1. Introduction

This package implements the RFC 6238 OATH-TOTP algorithm;

2. Objective

Golang two factor authentication library

This project demonstrates how Go can be applied to a real-world Cybersecurity & Ethical Hacking problem.

4. Technology Stack

Go

5. System Requirements

General requirements for this technology stack — check the README for exact versions.

  • Go 1.20 or later
  • Git (to clone the repository)

6. Installation & Setup

git clone https://github.com/sec51/twofactor.git
cd twofactor
  1. Built-in support for secure crypto keys generation
  2. Built in encryption of the secret keys when converted to bytes, so that they can be safely transmitted over the network, or stored in a DB
  3. Built-in back-off time when a user fails to authenticate more than 3 times
  4. Bult-in serialization and deserialization to store the one time token struct in a persistence layer
  5. Automatic re-synchronization with the client device
  6. Built-in generation of a PNG QR Code for adding easily the secret key on the user device
  7. Supports 6, 7, 8 digits tokens
  8. Supports HMAC-SHA1, HMAC-SHA256, HMAC-SHA512
2- Instanciate the `totp` object via:
3- Display the PNG QR code to the user and an input text field, so that he can insert the token generated from his device
4- Verify the user provided token, coming from the google authenticator app
5- All following authentications should display only a input field with no QR code.


### References

* [RFC 6238 - *TOTP: Time-Based One-Time Password Algorithm*](https://tools.ietf.org/rfc/rfc6238.txt)

* The [Key URI Format](https://github.com/google/google-authenticator/wiki/Key-Uri-Format)


### Author

`totp` was written by Sec51 <info@sec51.com>.


### License

Full setup instructions are in the project README.

7. Future Enhancements

Suggested extensions you can add to make this your own project.

  • Add logging and alert notifications (email / Telegram)
  • Write a threat model document for the tool
  • Package it with Docker for safe lab testing

8. Viva / Review Questions

Common questions examiners ask for projects in this domain.

  1. Which threat or attack does this project defend against?
  2. What detection or protection technique is used and what are its limits?
  3. How are false positives and false negatives handled?
  4. Which cryptographic algorithms or security standards are involved?
  5. What legal and ethical rules apply when testing a tool like this?

9. Source Code & License

This project is developed by sec51 and published on GitHub under the ISC License. Please follow the license terms and credit the original author when you use or modify this code.

Want to build this as your internship project?

Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.

Apply for Cybersecurity & Ethical Hacking Internship