The TOTP QR Code Is a Secret-Enrollment Ceremony
Scanning the QR code transfers long-lived secret material; it should be treated more carefully than an ordinary setup screen.
Scanning the QR code transfers long-lived secret material; it should be treated more carefully than an ordinary setup screen.
Losing the authenticator device creates a second-factor recovery problem that should not silently collapse to the password path.
TOTP is not a random six-digit number every half minute; it is a deterministic moving-factor calculation with a strict verifier window.
The six-digit code comes from a shared TOTP secret and time step; Google Authenticator is only one compatible client.
Putting MFA in front of each application separately creates duplicated policy; Authelia gives the protected subdomains one identity boundary.