Starting from scratch with HOTP and could use plain advice. Phone and laptop both in play, plus a couple of servers that only support one-time passwords. Unsure how to pick a counter start, how often to resync, and what to do if tokens drift after a few failed attempts. Wondering about backing up secrets without exposing them, and whether to store on device or a hardware key. Also confused about rate-limits and lockouts. Looking for a simple checklist to set this up safely and avoid locking myself out at the worst moment.