Reply to post: Re: But retail banks are clueless about security

What could possibly go wrong? Banks could provide ID assurance for Gov.UK – report

Anonymous Coward
Anonymous Coward

Re: But retail banks are clueless about security

And they put your card's offline PIN on the chip (this is invariably the same as the online PIN)

Yes really. I acquired a smartcard reader recently and found it whilst looking at what was on various cards in my wallet using cardpeek. (http://www.amazon.co.uk/Konig-USB-Smart-Card-Reader/dp/B003KZXP0E + https://code.google.com/p/cardpeek/)

From the look of it the public key crypto on the cards is pretty weak too.

Much of this has been known about for ages: http://en.wikipedia.org/wiki/EMV

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon