WBC I am not reading it that way. I am looking at the wording. OTP is one time password. For authentication it seems like a secondary password would need to be required to circumvent the process. I read the PCI as well.
I get if a cellular user is using one password on one device, but as we keep evolving in the technology a secondary password and authentication seems to be the answer and would seem to solve the problem as I do not see it referencing a solution.