* Posts by Philip Miller

1 publicly visible post • joined 17 Dec 2007

Technical problems mar Barclays' PINSentry roll-out

Philip Miller
Thumb Down

Not good enough to make me want to switch!

I liked the old system and have used it for at least 8 years. In this time I have not been a victim of online fraud.

This is not so secure as it looks since an attacker will now need to watch for you pin number and then get the card off you (clearly dangerous) since they need the physical card, also there is no extra security on the pin sentry device as one lady in barclays tried to tell me "The one sent to you will only work with your card" - erm no.

Also to quote Bruce Schneier :

"Man-in-the-Middle attack. An attacker puts up a fake bank website and entices user to that website. User types in his password, and the attacker in turn uses it to access the bank's real website. Done right, the user will never realize that he isn't at the bank's website. Then the attacker either disconnects the user and makes any fraudulent transactions he wants, or passes along the user's banking transactions while making his own transactions at the same time."

At the moment I have asked them to reverse the change for me, which they did eventually - for a limited period.