I have read the question on HOTP implementation in KeePass HERE. This question is however on the other newer plugin KeeChallenge.
According to the documentation, the a secret is encrypted and can only be decrypted using the TOTP. However if it is done so, isn't the weak link now the encrypted xml file (plus there is a recovery key backdoor) rather than the encryption algorithm of KeePass? As far as I can tell, things that KeePass does to keep itself safe from brute attacks (e.g. encrypt multiple times) is compromised by the use of this plugin. Am I right or did I miss something?