5 ms·
I think this could be solved by having the duress code be as simple as entering your PIN backwards
by amlib 5y ago
I think this could be solved by having the duress code be as simple as entering your PIN backwards
- littlecranky67 5y agoWay easier, just have a set of 9 icons (flower, sun, etc) shown after every pin entry. Your "true" icon will proceed, all other icons will trigger duress and proceed.
- justinpowers 5y agoThis is brilliant. Can you offer any more insight or background to this? Is there a name for this technique?
- littlecranky67 5y agoNo, it is an obvious solution to anyone who wants to solve the problem, and have never seen this in the wild (probably because I live in a relatively safe country where you don't have to fear to get mugged at an ATM). EDIT: This should be coupled with a "secret" icon that is shown (or a specific order of the 9 icons you have to chose from) to prevent MITM/Phishing attacks. If you realize the icon/order is not the one you are used to, you are being phished.
- reaperducer 5y agoWay easier, just have a set of 9 icons (flower, sun, etc) shown after every pin entry. Your "true" icon will proceed, all other icons will trigger duress and proceed. This is familiar. I had a bank that, when you set up your PIN, required you to also pick an icon. There was a flower, and a cat, and a dog, and some other generic pictures. When you put your card in the ATM and entered your PIN, you also had to pick the right icon. I wonder if this was the start of a duress system the bank was setting up. The bank ended up getting eaten by another bank and then another bank, and the icon selection system went away.
- james-skemp 5y agoDid MSN/Microsoft maybe do this many years ago? For some reason I don't associate it with a bank (they have a personal phrase they include in official messages), but do with one of the SSO accounts I had, and feel pretty confident it wasn't Google. Maybe Yahoo?
- KennyBlanken 5y agoThe pictures are to prevent account compromise via keylogger. Even if they get your login and password, they can't get into the account.
- jethro_tell 5y agoWouldn't people just wait till you step away from the ATM then?
- j4yav 5y agoHow would it know if you entered it backwards if it was 1221, for example?
- TacticalCoder 5y agoWell the obvious solution if one was to use this scheme (which I'm not saying is good or bad) would be, at PIN creation time, to disable palindrome.
- cortesoft 5y agoThat eliminates all palindrome numbers as possible pins, which is bad for security.
- gizmo686 5y agoAt 4 digits, with a 10 character alphabet, you are looking at a 1% reduction in pin space. Contrast this with the 90% reduction in pin-space you get by not using a 5th digit.
- benatkin 5y agoBecause it reduces the number of possible combinations? Good reason to keep moving from 4 digits to at least 6 digits.
- 3np 5y agoFound the person with a palindrome pin
- cortesoft 5y agoNo, only the reverse of my PIN is a palindrome.
- martyvis 5y agoThis was patented over 35 years ago but not implemented, and only spread as a good hoax. https://en.wikipedia.org/wiki/ATM_SafetyPIN_software?wprov=sfla1 https://en.wikipedia.org/wiki/ATM_SafetyPIN_software?wprov=s...
- kevml 5y agoRemembering this seems hard. And doing it under pressure seems very hard. I’ve forgotten my own zip code at a gas station before.
- deleted 5y ago[deleted]
- jamesmontalvo3 5y agoAlternatively: same PIN/password as normal, but alter the last character. Better if it’s any incorrect last character. That allows you to stick close to your normal routine while in a stressful situation.