Premium

Your OTP isn’t a One-Time-Password any more. And that carries a security cost

An OTP limits the damage caused by insider threats, opportunistic data breaches, and leaked credentials. The fixed PIN on ride-sharing apps shifts more trust onto drivers, backend protections, and post-hoc fraud detection than a one-time code does

otp, uber, rapido, pinAn OTP is spent on use and expires when the trip begins, so a number overheard in a queue or captured in a screenshot is already worthless.
Written by: Aalok Thakkar
6 min readJul 16, 2026 12:05 PM IST First published on: Jun 24, 2026 at 01:09 PM IST

Every time you book a ride, your driver asks you for an OTP. Increasingly, that OTP is no longer a one-time password.

A quiet substitution has spread through Indias ride-hailing apps. Rapido and Namma Yatri took the OTP, the four-digit number a passenger reads to their driver, and turned it into a standing PIN: One fixed value tied to the account, repeated on every trip. Uber has since adopted the same model in India while keeping a fresh per-ride code in the United States. The question worth asking is: What can a genuine one-time password do that a fixed PIN cannot?

Latest Comment
Post Comment
Read Comments