rea.run

← Showcase

case-study 2026-10-09 androidtotpgplauthorized

Aegis TOTP: recover the 30-second login-code rule from a release APK

Authenticator apps look magical until you recover the rule: time is sliced into fixed periods, mixed with a secret key, then reduced to digits. Aegis publishes under GPL-3.0, which makes it a clean teaching target for authorized APK inspection with REA.

Source meta

13241 GitHub stars (snapshot)

Language: Java

License: GPL-3.0

Updated: 2026-09-06

GitHub source ↗

rea.run rating

4/5 — Authorized GPL Android lab

Quality. Clear teaching target with public license.

Evidence. RFC cross-check path; agent Evidence on release APK.

Limits. Not an account-bypass tutorial.

For. Android/TOTP learners with authorized builds.

What you are trying to learn. Not “break someone’s MFA,” but name the calculation: period length, hash family, digit count, and how the UI asks for a code at a given timestamp.

How REA helps. Point an agent at a release APK you are allowed to analyze. Ask it to locate TOTP-related classes, follow display/copy call sites, and return Evidence (method names, defaults, decompiled snippets). The agent should mark unknowns instead of inventing crypto.

What “good” looks like. A readable summary such as: seconds → floor division by period → HMAC with the account key → dynamic truncation → modulo 10^digits with zero-padding. Cross-check against public RFC 6238 test vectors when you rebuild a tiny demo clock.

Guardrails. Use official or otherwise authorized builds. Do not harvest other people’s secrets from devices you do not own. Reconstructing TOTP math on GPL software is interoperability research; stealing live account seeds is not.

Takeaways

  • Prefer licensed targets when teaching Android RE.
  • Ask for Evidence + unknowns, then verify in JADX/your own rebuild.
  • Separate “understand TOTP” from “attack an account.”

More on-site cases