Loans
OTP, or One Time Password, is that four to six-digit code that pops up on your screen every time you use your debit or credit card for an online or NetBanking transaction. Have you ever wondered what exactly these numbers are and why they play an integral role in securing your bank account?
Through this article, we take you through what OTP is and all you need to know about it.
OTP is unsystematically generated and sent to your registered mobile number to validate the transaction. It offers an enhanced layer of security for the card and online transactions. It is sent to your mobile number within a couple of seconds of you inputting your transaction details and stays on your phone only for 2 minutes. OTP is automatically generated with a numeric or alphanumeric string of characters that authenticates the user for a single transaction done by Credit Card, Debit Card or login session. This OTP is a secret token that must not be shared with anyone.
An example of an OTP is when a system administrator, for instance, HDFC Bank, sends you an OTP to complete your online purchase. This alphanumeric code, used to authenticate access to the system, changes every 30-60 seconds depending on how the back-end system is generated. Most banks allow an OTP to be valid for 2 to 10 minutes. However, for instance, mobile device apps such as Google Authenticator bank on the token device and PIN to generate the OTP and offer two-step verification. Unlike static passwords that expire only after every 30 to 60 days, the OTP is used per transaction or login session only.
Through the OTP-based authentication mode, the user’s OTP and the authentication server rely on shared secrets. The numeric or alphanumeric values for the OTP are generated using the Hashed Message Authentication Code-HMAC algorithm, such as time-based information or an event counter. Each OTP will have a timestamp for additional security. The OTP once generated, is delivered to a user through numerous channels such as text message via SMS, registered email address or other dedicated applications chosen by the bank.
A static password is a password set up by the user and can be used multiple times. Although the authentication method is suitable, it is not secure. It is susceptible to online identity theft, phishing, keyboard logging, man-in-the-middle attacks, and ATM and POS skimming. All these theft practices are on the rise. A static password provides you with a single layer of security.
An OTP is an extra security layer beyond your regular password. Modern authentication systems use OTPs to overcome the weaknesses of static passwords, adding an extra security measure. OTPs help safeguard network access and the digital identities of users.
Though each of these passwords offers their specific type of security, they work best together. With OTP providing added protection, it becomes a challenge for unauthorised individuals to access information over networks and through online accounts.
Here’s a brief guide on generating an OTP for banking transactions:
This article has explained in detail what OTP means, how it is generated and the difference between a static password and an OTP. So, the next time you carry out any transaction online, you will know what those six digits mean on your SMS that reads as OTP. To learn more about HDFC Bank Debit and Credit Cards, click here. If you want to open a bank account online with HDFC Bank, click here to get started! Read more about Digital Banking here.
*Terms and conditions apply. The information provided in this article is generic in nature and for informational purposes only. It is not a substitute for specific advice in your own circumstances.