Sending PINs over SMS

What about the pin being sent through SMS but the card being inactive until it registers a pin change event? At that point the card becomes enabled?

Or the card is frozen by default and you unfreeze within the app when you confirm you have changed the pin.

Why? I consider it to be more secure to leave it as-is. The bank will do a better job of generating a random number than a human, and it means my PIN changes fairly regularly. Drastically more secure than me coming up with a number and then repeatedly using it on every card.

4 Likes

So you would rather wait another 3 to 5 days for pin to arrive in post when all you have to finish memorise & delete text or change pin at an ATM and delete text? :weary:

1 Like

God I have about ten cards. Only A person with a photographic memory could possibly remember 10 random pin numbers totally disagree.

2 Likes

Nah, weā€™re just out of practice on remembering numbers. Before everyone had mobiles permanently attached, most of us could reel off a friends/relatives number with no trouble. I reckon you knew/know telephone numbers for more than 10 people.

Iā€™d just rather it wasnā€™t sent as an SMS which the phone will save. Class 0 SMS, shown in app, etc. would all be possible alternatives.

Still very keen towards the ā€œone-time-passwordā€ style PIN reset though.

SMS is mostly not considered a secure two factor, sending out pins through SMS is a bad idea.

Instead using in app notifications would be less risky as the communication channel is known, authenticated and encrypted.

Even though the SMS suggests changing pin, using an in app notification might actually remove the need to suggest people should change the PIN.

2 Likes

Iā€™ve moved your post here as your comments follow on nicely from the earlier discussion about this process. It looks like the team agree with your solution too :slight_smile:

1 Like

I donā€™t have a problem with a PIN via SMS for the CA. The balance is Zero, so itā€™s not like anyone else can get any money. You can then change your pin before you transfer any money in if you wanted to.

1 Like

I think pin over SMS is a great idea.

1 Like

Why not in-app push notification? Youā€™ve got all the advantages of SMS without the insecurity.

1 Like

there are those that will like the PIN hidden in their app behind a retinal scan and voiceprint, personally I would rather it just come thru on an SMS text messageā€¦but a regular one not a flash SMS so it stays on my phone for a few hours until I can drive to an ATM

In-app message and being accessible without retinal scan and voiceprint are not mutually exclusive. They could just use their existing ā€œview PINā€ functionality but simply not require Touch ID when viewing the PIN for the first time.

1 Like

with the SMS if I go to an ATM in an area with poor GSM signal I can still view my SMS to know what PIN to input.

if I have to go in my app to view the PIN and it is in an area of poor signal I canā€™t view my PIN due to not having a mobile data connection

The PIN can be retrieved in advance and stored encrypted on the deviceā€¦ but the likelihood of you just receiving your card for the first time (so not knowing the PIN) and you having bad signal at the ATM is in my opinion pretty insignificant.

i live in a small town where only one networkā€™s signal can be received in the town centre so you have to walk out of the town to some fields or up a hill to get a signal. Tried paying with my phone which required being online and no signal in the supermarket. Not in remote celtic fringes but northeast Essex!