Yes, but why did there have to be a central server with the shared secret for every token on the planet?
The way the SecurIDs were designed, there was not way to plug into them, so there was no way to program them. So when you bought a batch you entered each serial number into your RSA auth server, which phoned home, and got the seed/secret.
Huge single point of failure.
TOTP (and HOTP before it) has a shared secret between the auth server and the token (software), but if Company X is hacked they don't get the secrets to Company Y:
* https://en.wikipedia.org/wiki/Time-based_One-Time_Password
Yeah, this struck me as a huge flaw. The breached system was used to create CDs full of IDs for customer deployment. For convenience the manufacturing system was almost but not fully air gapped. They retained the ID data in case the customer needed a copy in the future. However, keeping all of the IDs ever made on one system seems crazy.
If they had just deleted the data after backing it up to discrete offline media every week...
Data loss probably scared them more than risk of breach.
The real failure, after all, was not having the system actually airgapped. Aside from electromagnetic leakage through the power system there isn't much difference between spinning disks and tapes if they're not connected to anything else.
I'll take whatever improvements I can get in security.