6 ms·
"The default PIN is the last four digits of your registered mobile phone number. Please call Shift support at 800-897-0717 to reset your Shift Card pin." That'
by Tortoise 11y ago
"The default PIN is the last four digits of your registered mobile phone number. Please call Shift support at 800-897-0717 to reset your Shift Card pin."
That's a terrible idea. This isn't a library card. You're PIN shouldn't be known by anyone who knows your phone number.
- hellofunk 11y agoWell, it does say "default" PIN. Still not good, but you can at least change it, presumably.
- TomGullen 11y agoThat's pretty horrendous. Should be inactive until you activate it, or randomly generated and displayed to you securely in some way.
- ShiftPayments 11y agoThe card actually is inactive until you activate it once it arrives
- celticninja 11y agobut if someone intercepts your mail, then they know your address and could possibly know your phone number. How secure is the activation process? Why dont you send the card and PIN out separately like a bank?
- nacs 11y ago> but if someone intercepts your mail, then they know your address and could possibly know your phone number. How secure is the activation process Every "normal" credit and debit card I've received in the mail has used this same procedure -- call a number on a removable sticker stuck to the card to activate it where the only verification is the phone number you're calling from (and caller ID is easily faked). How is this any worse than how every other card activates? And how do you propose they get around the mail interception problem? Have a courier deliver it to you and place it in your hand?
- celticninja 11y agoI was wondering why they think their system is more secure than the traditional method of issuing cards and PINs through the post.
- MrOwen 11y agoHalf of the cards I remember activating were based on the originating phone number (which I think you could still possibly spoof) which should have been tied to your account when you signed up. If the phone you're calling from isn't the same one on your account, there's likely some additional information you provide or maybe go through a CS rep to finish activation. Unfortunately, like you say, there are also many bank's systems who ignore or simply don't care about the call ID number. As for interception, I guess you could require a signature for delivery but that's a pita. You just have to weigh the risks in that situation and the convenience of not requiring a signature obviously outweighs the risks of theft. EDIT: grammar
- kuschku 11y agoHoly shit, that’s horrible. Where I am, PIN and Card arrive in different letters, and the Card letter is only sent once you confirmed via your online banking interface (which uses 2FA) that you received the PIN letter. And you need to confirm online in your banking interface to have received the card to be able to use it.
- bpicolo 11y agoFor credit cards in the US you virtually never use a PIN. Debit cards only
- simantel 11y agoThat's changing as of this month. Most banks have already issued new chip cards, which require a PIN. If a merchant is still using the old swipe and sign system, now they'll be liable for any fraudulent transactions if the customer has a chip card.
- iamsohungry 11y agoFalse: the card is inactive until someone activates it.
- celticninja 11y agothat is terrible, especially for a company in the bitcoin space which should be encouraging best practice for security at all times.
- eterm 11y agoThe bitcoin industry has a long and chequered history when it comes to best practices. Part of the appeal of bitcoin to many is "Banks are so unnecessarily expensive to transmit value", the bitcoin industry has slowly and painfully been learning one disaster after another that maybe some of that cost isn't unnecessary after all.
- celticninja 11y agoWhat disasters are you talking about? It is possible to transmit value securely and safely with bitcoin so Im not sure what point you are trying to make other with this sort of vague statement.
- JupiterMoon 11y agoThe mtgox débâcle springs to mind. EDIT: My point is that a financial service is more than just the protocols used. Actually the protocols are the least important thing to the average customer. The more important thing is trust. I trust that my money in the bank will stay there and that transactions made using my bank will go to the person I say they should. Part of the reason for my trust is in the regulation around the banking industry. E.g. the savings guarantee here in the UK(/EU?). The bitcoin industry (not the protocol but the services around it) have yet to provide me that level of trust coupled with comparative ease of use.
- celticninja 11y agoBut that was not a disaster for bitcoin, that was a case of fraud and theft. Not much different to someone embezzling fiat from a firm e.g.secure investmen, and that wasn't a disaster for fiat currencies or the traditional banking system. I think that many people hold bitcoin and bitcoin businesses to a higher standard than they would companies that operate outside this sphere.
- deleted 11y ago[deleted]
- abandonliberty 11y agoThat is the default security of my library card. How universal is this?
- MikeTV 11y agoYou have a library card with a settable PIN? Every one I've gotten has been an auto-incrementing ID with no security.
- maaku 11y agoSanta Clara county librarybhas a settable PIN.
- abandonliberty 11y agoI hope you live in a place where everyone leaves their doors unlocked, children walk to school and play freely in the streets, and the police actually serve and protect the public. Are you from Iceland?