>   Many banks are issuing tokens these days.  I have seen two, and  
> both display a 6-digit number which must be entered on another  
> screen after logging in with the usual userid and password.  There's  
> no challenge / response process, and the numbers are claimed to be  
> non-repeating.

I would've thought these would be 2-factor authentication tokens:  
"What you know" and "What you have" -- you require both a 4-digit PIN  
("What you know") and the 6-digit number from your token ("What you  
have"). The SecurID server then compares the PIN with the Token and  
determines whether or not that is valid. How that happens, I actually  
don't know yet. I keep meaning to research it and then something  
slightly more shiny comes up.


