4 ms·
>If PINs are hashed, they can only be issued once — if you forget your PIN, you will have to ask for a new one. But this is a lot more secure: This is what I w
by rajib 13y ago
>If PINs are hashed, they can only be issued once — if you forget your PIN, you will have to ask for a new one. But this is a lot more secure:
This is what I was talking about, if an encrypted pin can be decrypted by bank staffs then it can be decrypted by others as well. I was surprised to hear they'll send me the same pin by post in readable format. Its something like, I am the admin of this website and I will know whatever password users will enter, so when users forget their password I'll send it to them via email.
I believe Bank and Financial institutes should apply as secure method as possible. Sending the Pin by post in readable format is not secure at all (given that you cannot change the pin again)
- nmc 13y agoI mostly agree. Two nuances: - they will assure you that the PIN re-issuing process is completely automated, and no employee has the authority to actually read your PIN; nice touch, but you still have to take their word for it - they will immediately block your card whenever you request it So I think the most common rationale about this is along the lines of: 1. Some clients will inevitably compromise their PIN 2. Thus we need the system to be very good at dealing with compromised PINs 3. So we do not need to be extra careful about PINs, because we are good at handling compromised PINs Do not forget they are bank. Their main and unique goal is PROFIT. Nothing else matters, they only see the financial aspects of things.