ext_27570: Richard in tricorn hat (Default)
posted by [identity profile] sigisgrim.livejournal.com at 01:58pm on 30/05/2008
Barclays say their card reader

We're still waiting for ours from Barclays.


isn't account-specific

That's very interesting. In that case I'd guess that something is sent initially from the reader to the bank that identifies the account and then the bank sends something else back to the reader that identifies which seed to use. But that is less secure; once you've identified the link between seed identifier and seed the thing is cracked and that link is on the bit of hardware that everyone has. Also if one could intercept the account identifier and the returned seed identifier that would reveal which seed was associated with a particular account.

October

SunMonTueWedThuFriSat
      1
 
2
 
3
 
4
 
5
 
6
 
7
 
8
 
9
 
10
 
11
 
12
 
13
 
14
 
15
 
16
 
17
 
18
 
19
 
20
 
21
 
22
 
23
 
24
 
25
26
 
27
 
28
 
29
 
30
 
31