Security management Toolkit
Story: PayPal fights fraud with password key fob
It works like this...
The algorithms are usually proprietary to the company that produces the keyfobs - Vasco, RSA, etc.
What happens is that the user has to register their keyfob by telling PayPal the serial number on the back, and sometimes syncing it by entering the next one or two numbers that are generated by the fob.
From this point on when a user logs on, PayPal can then use this information to check whether or not the OTP entered by the user matches what its back-end software provided by Vasco, RSA, etc say it should be.
Full Talkback thread










