It generates a random password that only works for 30 seconds, and because that specific token is registered to your SE account, POL will know whether the password is acceptable or not. Nobody can log onto your account unless they had your SE account password and your token. Or were an extremely sophisticated hacker.