I posted on this in one of the many threads, instead of digging, repost
When the tag is read, it generates an ordinary https page read. The request includes the cert# and a piece of time-based data. The request can be resubmitted for up to 3 or 5 minutes, after which you are told it's invalid and you need to scan the tag again.
Even if you buy the same tags (and they are not PCGS proprietary), you can't generate the same request from just the cert#.
I doubt it would take nation-state resources to crack the keys and nonces, but PCGS could make it far more difficult to usefully crack by generating new keys and nonces every few thousand slabs. There are plenty of processes where the morning startup includes re-keying secure processes.
-----Burton
50+ year / Life / Emeritus
ANA member (joined 12/1/1973)
Life member: Numismatics International, CONECA
Member: TNA, FtWCC, NETCC, EveryCountry (online) coin club
Owned by three cats and a wife of 40+ years (joined 1983)
Author: 3rd Edition of the Sample Slabs book,
https://www.sampleslabs.info/