The localclock integrity check is just another encrypted bit stream passing from TAN server to Embassy client. Why should it be any less secure than any other? (duh?)