Posted October 17, 2016
Maighstir: I don't know how the implementation of a similar system that I have seen works, or if it's built on either of said standards, but from what I have seen, the hardware token doesn't need a connection to the computer or outside world at all
Yes, these things exist. I think SecurID by RSA is the most well known of these systems. They are not without flaws either, like you already said: they are cumbersome to set up by somehow adding the key to the system you are trying to authenticate against. And I personally don't feel very comfortable by there only being one key ever. That may be more for the professional grade security, not so much for GOG with so many end users. Let's be honest, there is no ideal solution to this problem. ;) HOTP/TOTP seems to be the standard solution and is currently the most widely used. So that's what I would go for.
I honestly did not know that. Thank you for clarification.