Design preview for TheFraudPractice.com redesign — staged at deriskconsulting.com, not live. Final path stays: /technology/secure-tokens
Home / Fraud Library / Technology / Secure Tokens
Technology

Secure Tokens

Authentication Tech ~3 min read The Fraud Practice Library

Secure tokens — fobs, hardware tokens, or RSA tokens — are small physical devices that generate a unique numerical code, changing roughly every minute, making the code extremely hard to replicate on the fly.

How it works

A merchant or bank issues the consumer a key-sized device, along with a PIN to use alongside it. At checkout, the consumer supplies both the PIN and whatever code the fob is currently displaying. The merchant validates the combination through a third-party service before confirming identity.

Limitations

It doesn't catch genuine identity theft — a stolen identity with a stolen token still authenticates. It also asks a lot of both sides: the consumer has to carry a physical device, and the merchant needs infrastructure to validate it. Because tokens only work at participating merchants, real-world adoption has stayed extremely low.

What to weigh

It's genuinely effective at stopping someone from guessing or replicating an access code — but the physical device itself can still be stolen. Worth evaluating: device durability, whether it works across a network of merchants rather than just one, support for defective units, and whether pairing it with a PIN meaningfully adds security.