The one-time password continually changes, so the person would have to note and get logged in before the password expires, so Platinum_Disco's request is quite valid. That said, this is probably an RSA token, if not a similar 3rd party software, and it's very typical to keep the password hidden when you type even if you're looking at it on your phone or other device.