Re: Nationwide also to introduce "Card Reader Security"



Your posting doesn't make sense. Why would an incorrect PIN entry put you at
risk?


"David M" <david@xxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:slrnfppa4f.5p4.david@xxxxxxxxxxxxxxxxxxx
| Nationwide Building Society are to impose Chip&PIN card readers onto
| members who use internet banking and have a Visa Debit card.
|
| It sounds as though this will work in a similar fashion to the Barclays
| Bank system previously mentioned by others in this newsgroup.
|
| For some internet banking transactions, Nationwide members will, it seems,
| have to enter their PIN into the card reader to generate a passcode for
| use on the internet banking site.
|
| http://nationwide.co.uk/security/visa_debit_card_faqs/
|
|
| I wonder whether this device will carry the same risks as the Barclays
| device, whereby incorrect PIN entry will be explicitly noted as such,
| therefore releasing yet another assisted-mugging-tool (ATM) into the
| world: "Computer says no, now tell us your *real* PIN.." <thwack>
|
|
| Does anybody know whether there is any way for Nationwide members to
| submit a motion to the board to demand they reconsider this move, if it
| turns out the device can be used to compromise PIN (and cardholder!)
| security?
|
|
| David.
|
| --
| David M. -- Edinburgh, Scotland. --[en,fr,(de) <-- corrections welcome]
| *Please remove quotes not needed for context and interleave reply text*
| *No-context, excess-quoted, slug-trailed, zero-content posts filtered.*


.