Barclays online banking: pinSentry

Barclays online banking: pinSentry

Author
Discussion

MiniMac

7,625 posts

204 months

Thursday 10th January 2008
quotequote all
andy_quantum said:
Basic 2 factor authentication; something you have and something you know. Many people including myself have been using it for years to access corporate networks (Windows logon etc) using either small keyfobs or SMS. Companies like RSA, Vasco, Cryptocard etc have been doing this for years. Personally I think it's great that it's filtering down, not just in specifically hi-tech companies or large corporates, as it's added security.

To the person who keeps their machine secure, please bear in mind it's only as good as the wekest link and other such IT related cliches, you dont have total control over your machine and everything to make it more secure should be seen as a good thing.
We are intro-ing RSA fobs here for VPN / OWA. But I check my accounts from work / home / trusted friends / parents house. I dont want to have to lug this round aswell.

Please post the pinsentry article (or PM it)

rich1231

17,331 posts

261 months

Thursday 10th January 2008
quotequote all
There is nothing worse than something touted as safe to the masses when it isnt.

Glassman

22,625 posts

216 months

Thursday 10th January 2008
quotequote all
PinSentry said:
I do have transcript of the original article if it would interest anyone.

chris_tivver

583 posts

207 months

Thursday 10th January 2008
quotequote all
Safe? There is nothing that is safe. If you want secure encryption then you use one-time pads. But then communicating them is not secure.

Yes a man-in-middle can defeat it, but only at the time. My understanding (and I'm guess from how it appears to work) is that they could not log on again a bit later- that is a major improvement.

Man-in-the-middle also defeats a secure password and indeed most other solutions available to the banks, of not all.

Personally I'd rather have this system than not, nothing above has dissuaded me so far

reddog03

1 posts

194 months

Wednesday 19th March 2008
quotequote all
PinSentry said:
andy_quantum said:
Basic 2 factor authentication; something you have and something you know. Many people including myself have been using it for years to access corporate networks (Windows logon etc) using either small keyfobs or SMS. Companies like RSA, Vasco, Cryptocard etc have been doing this for years. Personally I think it's great that it's filtering down, not just in specifically hi-tech companies or large corporates, as it's added security.

To the person who keeps their machine secure, please bear in mind it's only as good as the wekest link and other such IT related cliches, you dont have total control over your machine and everything to make it more secure should be seen as a good thing.
pinSentry was also hacked a month or two ago. The head of a security company which was purchased by IBM in early 2007 made a right cock up by announcing it at a security press conference.

You can introduce a man in the middle attack against the device and inject web pages to take over an account and divert funds.

It appears that IBM legal have been rather speedy on this one as the story has vanished from the original source, Barclays needless to say are not happy bunnies.

I do have transcript of the original article if it would interest anyone.
Yeah, I would like to see th transcript if you have a copy. I have heard about this but not see the article

andynoquantum

13,204 posts

205 months

Wednesday 19th March 2008
quotequote all
Internet Security Systems by any chance? hehe

oyster

12,643 posts

249 months

Wednesday 19th March 2008
quotequote all
reddog03 said:
PinSentry said:
andy_quantum said:
Basic 2 factor authentication; something you have and something you know. Many people including myself have been using it for years to access corporate networks (Windows logon etc) using either small keyfobs or SMS. Companies like RSA, Vasco, Cryptocard etc have been doing this for years. Personally I think it's great that it's filtering down, not just in specifically hi-tech companies or large corporates, as it's added security.

To the person who keeps their machine secure, please bear in mind it's only as good as the wekest link and other such IT related cliches, you dont have total control over your machine and everything to make it more secure should be seen as a good thing.
pinSentry was also hacked a month or two ago. The head of a security company which was purchased by IBM in early 2007 made a right cock up by announcing it at a security press conference.

You can introduce a man in the middle attack against the device and inject web pages to take over an account and divert funds.

It appears that IBM legal have been rather speedy on this one as the story has vanished from the original source, Barclays needless to say are not happy bunnies.

I do have transcript of the original article if it would interest anyone.
Yeah, I would like to see th transcript if you have a copy. I have heard about this but not see the article
Don't expect him to provide it anytime soon. 1 post in 2 months doesn't exactly show regular attendance. wink

Hooli

32,278 posts

201 months

Wednesday 19th March 2008
quotequote all
i've been forced into it now & its bloody annoying.
the joke machne looks like a fisher price my first calculator too

Blib

44,311 posts

198 months

Wednesday 19th March 2008
quotequote all
I use Barclays pin sentry daily. Pretty straight forward little machine. However, I cant work out how the feck the online banky bit knows what number the little blue machiney thing will come up with confused

I am 48

AngryS3Owner

15,855 posts

230 months

Wednesday 19th March 2008
quotequote all
Seems to work pretty well, i have to admit when I received the thingy and saw the messages online i was not impressed but since using it a few times I'm not going to moan.

Silent1

19,761 posts

236 months

Wednesday 19th March 2008
quotequote all