One Time Passwords (OTP) are, as the name suggests, a single-use password. Instead of a user generated password which remains static, these passwords change. When a person attempts to log in to their account, an OTP might be sent to their phone number or email address. They can then use this information to log in to their account.
Some websites, apps and online services have even stopped using static passwords, and require a OTP every time that you login.
Why use a One Time Password?
Businesses and organisations might use OTPs because it means that they are generating a unique code that provides temporary access to an account, rather than a user creating their own password which provides permanent access to the account.
User created passwords are typically less secure; many people reuse passwords across different accounts so that it is easier to remember them, or they forget them and have to go through the process of resetting their password for the account anyway. One Time Passwords provide a solution to both of these issues.
Are One Time Passwords secure?
Whilst no login system is 100% secure, using OTPs certainly increases the security of an account. Because there isn’t a static password associated with the account, a number of different cyber security issues cease to exist. For example, password cracking techniques such as brute force attacks aren’t effective, because a password is only associated with the account once the user attempts to login.
However, OTPs aren’t invulnerable. A One Time Password is only as strong as the user that is receiving it, and the place that it is sent to. For example, many vishing scams (voice phishing) involve a perpetrator calling a victim, pretending to be someone that the victim trusts, and requesting information from the victim directly. Social engineering tactics like these provide a way for scammers to gain the OTP verbally, when it is provided by the victim themselves.
OTPs can also be obtained by accessing the email account, or the mobile device that the password is sent to. If either of these are poorly protected, OTPs can be intercepted and used to access any account that the email address or mobile device is linked to. This is why it's so important to use MFA on your email accounts, as this is often the door to all of your other online accounts.
OTPs are good, but MFA is better
Whilst One Time Passwords do solve problems created by static passwords, they’re only marginally more secure than static passwords. However, when combined with Multi-Factor Authentication (MFA), the security of an account drastically increases. With MFA, you’ll need to provide an email address, a password and an additional piece of information, such as a code texted to your phone, or a code on an authenticator app.
Using an authenticator app is one of the best security choices that users can make. Codes are only available using the app, which is only accessible on a mobile device that the user has access to. The codes also change every thirty seconds, meaning that even if a scammer was able to get the code, they would have very little time to use it.
Again, authenticator apps aren’t perfect cyber security solutions. Many websites offer alternative ways of accessing your account if you can’t access the authenticator app, which is useful if you lose access to it, but also opens a window for scammers. However, MFA paired with an authenticator app is currently the best way to secure your accounts.
Transcendit understand that when you choose to work with us, whether we're taking care of your IT, app or
web development, you're trusting us with part of your business. So whether we're looking after your
computers, phone systems or servers we always do things 'the
Transcendit way'.
The whole of our team adhere to the same values, beliefs and policies - the principles that were written
when Transcendit first formed in 2000. Whether you come to us for cloud services or recovery backup you
can be confident that you'll always receive the same excellent service.
The Transcendit way outlines how we do business; following the same straightforward principles with every
client and customer, regardless of how big or small they may be.
We understand that not everybody speaks fluent IT, so we try to explain things in a way that is
simple and clear. We always spend as much time as is necessary explaining things to you.
If you need to talk to us about something, no matter how insignificant, we are only ever a phone
call away – and we’re never too busy to make you a cup of tea and have a sit down with you in
person.
We understand how frustrating it can be when things are late. When we schedule an appointment with
you, we are there when you’re expecting us. If something prevents us from getting there, we always
call you in advance to let you know.
Sometimes things can go wrong, but we never lie to you or try to cover something up. If things go
askew we tell you what’s happened and how we plan to prevent it affecting your business.
We want you to continuously benefit from working with us. We regularly discuss your business and
make suggestions for improving systems and processes wherever we can – but we never try to push
you into a purchase.
When we quote a fixed price, that's always the amount we charge – you won’t find any nasty
surprises on a bill from us. If you are paying by time and materials, we inform you if our
approximations could change.
We understand the importance of privacy for your business and your customers. We respect the
confidentiality of your data, and we will never pass on your information to third parties.
We appreciate it when you take the time to give us feedback. A system called CustomerSure records
our client's responses, so you can trust that our reviews are from real people.
Find out what they're
saying here
.
Aaron was very friendly and able to help in a matter of minutesJade Green
Based on 13148
reviews our customers rate us 9.8/10.Reviews and ratings by Customersure. 07-November-2025