Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Passwords and PINs are not the same thing (at least in most places).

In my company (credit card company) and in most competitors the PIN is a random number generated when the smart cards are being written. Sequential, repetitive, years, et al are all discharged. PINs can be used as a password for transactions. Because my company focus on low-incoming families, this is actually great, they don't need a phone or website to create/change passwords. The problem here is delivering the password securely.

There are banks that do not use PINs at all, the password is stored in their database. This is usually better because if you loose a password you can reset it. This isn't possible using PINs. They are hardwired in the smart card and cannot be changed.

PINs cannot be changed or chosen, if you can change, it's not a PIN, it's an awfully insecure 4 digit password.



Why awfully insecure?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: