The same could be said about passwords. This device is probably best used as part of a multi-factor authentication scheme.
This is useless as multi-factor authentication, because it turns it into single-factor authentication. Anyone sniffing a single session or seeing it once knows what it looks like, and can reuse it on any site. It's much, much weaker than TOTP/HOTP, for example.