Skip to content

Knowledge base

The computer clock is off

The app checks the computer clock against the exact time and says so when they differ by more than 30 seconds. It does not set the clock itself: that needs administrator rights and is done in the system settings.

Where you see it

On every start the app takes the exact time from its own server's answer, with no separate request for it. If the clock is off by more than 30 seconds, a line about it appears in the app's notifications, at most once a day.

The exact measurement is done by Network diagnostics: the Computer clock line compares two sources, our server and Cloudflare. If they disagree with each other, the line says so and shows both.

What a wrong clock breaks

From 30 seconds, two-factor codes of profiles may not be accepted: a site accepts a code for about 30 seconds.

From 5 minutes, sites see a time that does not match their own clocks. From a day, sites over HTTPS do not open: certificates look invalid.

Signs of a wrong clock

A profile's two-factor code is rejected although the key is right. Sites over HTTPS open with a certificate warning.

First look at network diagnostics: the Computer clock line says how far the clock is from the exact time.

How to set the exact time

The Open date and time settings button in the clock line opens the system settings. On Windows and macOS turn on setting the time automatically there, and on Windows also press sync.

On Linux the button shows a command for a terminal: timedatectl set-ntp true.

2FA codes on a wrong clock

If two measurements agree, the exact diagnostics one or those of two starts in a row, the app counts two-factor codes of profiles by the exact time. When the clock is off by more than 2 seconds, the code carries a line about the correction.

The time seen by profile pages is not changed: such a change would itself become a trace. So the clock is worth fixing in the system.

What this article does not cover

  • Setting the clock by the app itself. That needs administrator rights.
  • The time zone. The neighbouring diagnostics line compares the machine's zone with the address's country.
  • Two-factor codes of your ARMANOS account. The server checks them by its own clock.

Where this is decided

Every statement above is one place in the code and one test.

Correction by the middle of the request, agreement of two measurements, thresholds of 30 seconds, 5 minutes and a day, one notification a day
apps/desktop/test/часы.js
The live app with a clock 4 minutes fast: notification, diagnostics line and a 2FA code by the exact time
apps/desktop/test/часы-живьём.js
A corrected code checked against the RFC 6238 sample
apps/desktop/src/lib/часы.js

Questions

Why not correct the time of profile pages?
A site may notice a changed time. A correct system clock is safer.
How long does the code correction last?
Until the app restarts. On the next start it is counted again.
Where does the app get the exact time?
From its own server's answers at start, and in diagnostics also from Cloudflare, at the address where diagnostics measures latency.

Still stuck

Support answers with the cause, not a list of tips.