Barclays: PINSentry: "PIN is correct"

[Related to the "Online Banking - Are card readers legal?" thread, but I couldn't face getting buried in the bottom of that lengthy discussion, so starting a new thread]

Interesting letter in Computing (10 Jan 08): Safety not in PIN numbers

formatting link
I can't imagine e-mailing Barclays will elicit anything other than the standard anodyne reply, so perhaps raising potential flaws here might carry some influence.

Allan (who has one of the little gizmos as well)

Reply to
Allan Gould
Loading thread data ...

numbers

formatting link
>

It has not significantly increased the risk. I think the EMV specs have enough info in them to build your own pin checker. Additionally any mugger is just as likely to have access to a C&P terminal to test the pin (the first link on ebay for "POS card" looks like it's a c&p reader for 9.99 and I think you should be able to verify the pin before it attempts to dial up)

I suppose the one increased risk now is that any crook has a genuine reason to be carrying a pinsentry, while a home brew device would be more suspicious. So they can try cards in a co-workers wallet left on their desk with much less risk of exposure.

Tim.

Reply to
google

At 14:15:41 on 10/01/2008, snipped-for-privacy@woodall.me.uk delighted uk.finance by announcing:

I have a card reader in my several-year-old laptop and the software's freely available if you don't want to (or don't have the knowhow to) write your own.

Reply to
Alex

The difference is that the device to check pins is now readily portable.

SALESPITCH: Use the portable muggermatic-PIN-verifierT to verify a PIN extracted from your victims under the threat of violence! No longer must you take your victims disclosed PIN on faith. Would be muggers should not leave home without the handy muggermatic-PIN-verifierT as with a valid PIN you can extract upto 750 a day from cash machines. Get your muggermattic-PIN-verifierT from Barclays now whilst stocks last!

Seriously 750 is a big scoop for a street robery. How long before some savy robber jumps you on a back street and punches you on the nose everytime you lie to him about what your pin number is.

Reply to
Rob P

At 19:13:25 on 10/01/2008, Rob P delighted uk.finance by announcing:

The devices have existed for quite a while now, and you didn't have to be a Barclays customer to get hold of one.

Reply to
Alex

BeanSmart website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.