Last modified: 2014-04-16 22:47:57 UTC
The TOTP RFC recommends all communications (especially those involving the secret key) be over TLS. I recommend using $wgSecureLogin as an indicator of whether communications should be forced over HTTPS.