Pass the popcorn, somebody, we could be here for some time.
Pass the popcorn, somebody, we could be here for some time.
No we couldn't :-)
In message , Alex writes
OK, if the ATM was 'offline' (which they were for years) how was the PIN verified?
In message , Alex writes
Ill try it from another track. I am refuting your use of the word 'never'. ATMs were not always 'on line' all the time, yet they still checked PINs. How did they do this?
Originally there werent that many ATMs, or that many card holders, and there was no interchange of cards between banks, so its possible that the PINS were transmitted to each ATM and held there. Each bank would hold its own customers details on its own ATMs in this scheme. I dont know if this happened but its feasible and certainly more feasible than storing a PIN on a mag stripe!.
I was installing components of systems that validated PINs centrally in the mid 80's and they were replacements for existing systems, so in the UK they must have been checking PINs online since the late 70's.
I was involved with Link starting up in the mid 80's, any transaction via Link was online, so PINs were not on cards then (if PINS were on cards then, you wouldnt have needed LINK or banks to team up). Prior to that, it was each bank to its own, and then you had a few banks that teamed up, for example barclays and lloyds, that would have been in the late 70's or early
80's.The need for teaming up, and Link, proves that PINS were not stored on cards at that time.I personally doubt they ever were stored on the cards, way too much of a security risk, but at the very least they certainly have not been for the last 25 years.
Your argument appears to be that because you cannot think of a way offline ATM operation allowed PINS to be off the cards, therefore they must have been on them.
I can think of at least one other way it could be done, but the point is, since they havent been for 25 years or so, do you have any sources that show they ever were?
Without a hint of irony, john boyle astounded uk.finance on 21 Nov 2004 by announcing:
Mr Weed has posted an excellent explanation later down. If you'd also like to see the typical data stored on a credit/debit card you only have to ask.
In message , Tumbleweed writes
Feasible but it certainly wasnt the case as late as 1985. To give another example of the ATMs offline working, the 'hot card' file was downloaded daily, to spot only those cards that were being dangerously misused, which represented about 3% of total lost and missing cards.
No, it was during the middle 80s that they became prevalent for clearing banks.
This was the break point, but prior to that PINS were stored on the cards. But the need for Link was more than you describe, it was to bring in a uniform system and format which had not existed previously and to intoduce a pan banking method of accounting. Each bank was developing its systems separately. EG Whilst Barclays Cheque Card was also a BarclayCard, Midlands Cheque card was 'ATM'; enabled for a long time before it was put into widespread use, and there were also separate AUTOBANK cards.
No, I would say 19 years. (I say that because it was 19 years since I was involved in the daily back office use of them). But I know for sure that there a number of different systems running in parrallel, e.g. Link for example.
No, I am merely using that as an example as to why they werent online all the time, yet still performed transactions.
Others are expressing theory, I am giving facts.
My personal knowledge is from 17 July 1973 to 31 October 1986 during which time almost every day involved me opening up the back of an ATM (or cash dispenser as they were originally known) to perform or supervise the required daily tasks.
In fact early Borroughs machines had no link at all, they had a golf ball printer in the back which printed a cheque which was inserted manually into the clearing system. The branch in which it was installed was not online in any way and communication with the central processing centre was by punched tape sent by courier, and customer balances for staff use were delivered on printouts by courier form the computer centre. That machine had less memory than a ZX81 and it did not have any stored PINs because there was no way it could be told of them. The only reprogramming or data input was the use of a 'bootstrap' punched tape and a firmware tape, which were used from time to time after a failure but those were kept in the cash safe and were never changed in the 3.5 years I was involved with it. It was a quaint machine which was broken more times than it was working and deserves a place in the science museum. It only doled out plastic clips with 10 x £1 notes in. The cards could only be used 10 times and had a dimple punched on them every time they were used so that the customer could keep track. This machine's only external connection was to the 13amp plug. The cards needed a PIN to be used. The machine checked the PIN from the card. In fact, the card was read, wiped and re-written for every transaction.
All of the following example to which I refer relate to more modern IBM and NCR machines that began to be introduced.
Give me time to find it, but the above is based on my personal knowledge and considerable experience with daily 'hands on' use at the Midland Banks in Aintree, Kirkdale, London Road, Castle Street & Dale Street (all Liverpool), Hamilton Street, Laird Street (I think) both Birkenhead, Chester, Ellesmere Port, Chorley, Maghull and Crosby.
Other info,
It was quite an umber of years before all branches had an online link, yet they had been using ATMs for some time. When the online links were introduced they used huge modems and ran very slowly. The ATMs were built to be used offline and each transaction was stored on a magnetic Data Cassette that was similar to a normal audio cassette, with a back up on a printed tally roll. The ATM would go online a few times during the day depending on how much data it had and the main networks capacity to handle the data at that moment. In the early days the connections were pretty unreliable. After a while the ability to obtain a balance enquiry was introduced but more often than not this would be 'unavailable'. At the end of each banking day (i.e. 3.30) the back of the machine would be opened up. We would then have to 'force' the ATM to go online and download the data on the tape. You could see from the tally roll the status of the machine for each transaction and there was a code to indicate if the transaction had been conducted 'on line' or not. If there was no balance enquiry then the ATM would handle the transaction off line, then try and send it later. It didnt attempt this during the transaction because that would take too long for the negotiation etc., for the poor client standing outside in the rain.
At the same time, the branch computers were similarly only online for part of the time/ You could monitor the status of the link by way of indicator lights that were on the top of the ATM, and repeated in other parts of the branch if appropriate and on the modem. That way the staff could see from afar if the ATM was online, if it was being 'polled' by the central network.
Later improvements brought 'branch controllers'. These were very much improved pieces of kit supplied by Nixdorf and with it came a completely new back office hardware and accounting system. New larger capacity dedicated BT lines were installed thereby enabling full time links. This used a large number of workstations and this was the first time that branches would be 'online' all day with only very occasional outages. The ATM system changed as well and now it would likely 'go down' if the network connection failed, but as this was now far more reliable this didnt happen much.
Of course, originally the cards were only issued to 'trusted' individuals because it was quite easy to misuse the cards because there was no balance checking or 'hot card' like there is these days, and we couldnt just 'stop' a card if it started to be misused.
I hope this goes some way to show that I am not working on pure theory but on actual experiences and having worked up through all the levels within the bank including - systems work, audit, Inspection as well as the mainstream branch duties to wich the above dates relate. My experiences pre-date modern computer practice which is why Alex and yourself dont know all of this. Your work on Link is an example of the way things were to go, and the way they are now.
Hope this helps.
In message , Alex writes
No, he posted theories and facts that are not relevant and tell me nothing I didnt know already. Please read my rebuttal.
I do not argue with you about the current state of play, or that used relatively recently. I am merely rebutting your use of the word 'never'. Please read my reply to Mr Weed.
Well, the obvious way it could be done is for the ATM to have a secret recipe in it. Certain stored information on the card, together with the PIN actually keyed in by the user, would be put into this recipe, and out would come an answer "yes or no". That doesn't of course mean that the PIN is stored on the card, even in encrypted form. All it means is that when the PIN was first issued, it could have been issued as part of an N-digit "special" number, which has the property that the secret algorithm would map it to "yes", and of which only N-4 digits are stored on the card, and the rest were the PIN.
It isn't even December yet, and already the council are putting up the street decorations.
Got it in one :-)
Without a hint of irony, Ronald Raygun astounded uk.finance on 21 Nov 2004 by announcing:
And which is why PIN numbers could not be changed without reissuing the card.
In principle it would require re-issuing a completely new N-digit number, but I gather there is/was an offset feature instead. The card also has a
4-digit PIN modifier which is added to the keyed PIN by the ATM. That way, changing a PIN involves only changing the offset, thus the original PIN will still always be fed into the machine's recipe together with the original N-4 digits of the original special number.
is that what happened? I cannot remember. But it seems a lot stronger than publishing the PIN on the mag stripe, even if encrypted. Thats in fact easily broken in the following way;
1) I get a genuine card which has a PIN. 2) I read the magstripe and see my PIN 1234 has been encrypted as 5678. 3) I steal a card, and overwrite the magstripe PIN with 5678. Now I know the PIN to use is 1234.
What makes you think the encryption would be a simple 4-digit to 4-digit mapping? You think these systems were developed by morons? (Don't answer that). Surely it would take in other information, such as, say, the account details.
Your step (1) involves getting *your* card, since step (2) involves *your* PIN. So then step (3) involves stealing someone else's card, and writing your crypto-block onto it. It wouldn't work unless you also put your account number onto it. I suppose it could be marginally useful to use this cloned card to steal money from yourself. You could pull a nice little scam whereby you (say) go to a hotel and ask them to look after your card by storing it in their safe. Then use the cloned one to get money from a machine, then deny it was you, and win because your card has an alibi. Nice one.
hmmmm, you seem to have spotted a subtle flaw in my argment :-)
Why? Dont forget, this is from john boyles supposition that the PIN is on the card and the machine just compares the pin you entered with the decrypted PIN from the mag stripe. So it would work if my subtle flaw wasnt there. Also, if they are going to do a mapping taking other info into account, then you might as well *just* use the other info, that way there is nothing on the magstripe to refer to, to use to try and work out the algorithm.
But the PIN *is* on the magstripe, only not all of it. Just the N-4 digits. The 4-digit keyed PIN is only a small part of it.
Decrypting and comparing is so last-century. The hip way is to *encrypt* and compare.
Well, the stored PIN can include other (random) info as well as the account details.
The algorithms are more subtle than you give them credit for, I think.
We are talking 1980 or thereabouts. It *was* last century!
In JB's supposition, there is no stored PIN, (unless you mean some data stored on the magstripe). And you cant use random info. The only info you are allowed to use is on the magstripe. If there is data on the magstripe its all readible.
Are or were? ISTR seeing magstripe details maybe 15 or so years ago, there wasnta lot there. I suppose that prior to that there may well have been more there since so there wasnt a need for standards, as each bank did its own thing.
... and Unix systems (for example) were doing 'encrypt and compare' from some time before that I suspect.
Good point they were.
Have something to add? Share your thoughts — no account required.
Ask the community — no account required