CPF still requires using your OneKey token to authenticate logins from your mobile device. It would be far more useful if mobile login used an authentication app that is phone-based rather than a device that needs to be carried along with your phone. There are many secure apps for mobile 2FA. Limit what actions can be taken on mobile devices if there is fear of misuse without the token. Another issue is that the security token is provided by assurity, a company that provided terrible customer service when implementing the 2FA program. I would never count on assurity helping if there are issues with authentication.