diff --git a/README.md b/README.md
index b6a9bd9..9cd8632 100644
--- a/README.md
+++ b/README.md
@@ -1,6 +1,6 @@
# TwoFactorAuth class for PHP
-PHP class for two-factor authorization using [TOTP](http://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm) and [QR-codes](http://en.wikipedia.org/wiki/QR_code). Inspired, based and mostly an improvement on '[GoogleAuthenticator](https://github.com/PHPGangsta/GoogleAuthenticator)'.
+PHP class for two-factor authentication using [TOTP](http://en.wikipedia.org/wiki/Time-based_One-time_Password_Algorithm) and [QR-codes](http://en.wikipedia.org/wiki/QR_code). Inspired, based and mostly an improvement on '[GoogleAuthenticator](https://github.com/PHPGangsta/GoogleAuthenticator)'.
## Requirements
diff --git a/demo.php b/demo.php
index 7cef0a1..ba64627 100644
--- a/demo.php
+++ b/demo.php
@@ -4,22 +4,22 @@
Demo
-
+
First create a secret and associate it with a user';
$secret = $tfa->createSecret();
- echo '- First create a secret and associate it with a user: ' . $secret . ' (keep this code private; do not share it with the user or anyone else)';
- echo '
- Next create a QR code and let the user scan it:
';
+ echo ' - Next create a QR code and let the user scan it:
 . ')
...or display the secret to the user for manual entry: ' . chunk_split($secret, 4, ' ');
$code = $tfa->getCode($secret);
echo ' - Next, have the user verify the code; at this time the code displayed by a 2FA-app would be: ' . $code . ' (but that changes periodically)';
- echo '
- When the code checks out, 2FA can be / is enabled; store secret with user (encrypted?) and have the user verify a code each time a new session is started.';
+ echo '
- When the code checks out, 2FA can be / is enabled; store (encrypted?) secret with user and have the user verify a code each time a new session is started.';
echo '
- When aforementioned code (' . $code . ') was entered, the result would be: ' . (($tfa->verifyCode($secret, $code) === true) ? 'OK' : 'FAIL');
- echo '
- Make sure server-time is NTP-synced!';
?>
-
+
+ Note: Make sure your server-time is NTP-synced! Depending on the $discrepancy allowed your time cannot drift too much from the users' time!