How does this little gizmo work? Online banking thingy.....
Discussion
Just transferred a bit of dosh using HSBCs online banking at work. After typing in all details to log on, you then have to press a button on a small keyring thingy with a 6 digit LCD built in. A random number is shown and then you type that in, on the 'log on' page, to access the system....Each time you log on, it gives a different 6 digit number...How on earth does this work?
The token you have runs an algorith to generate a number every 6-10 seconds, and has a corresponding piece of software on the banks side also capable of understanding and generating the correct algorithm to match. When that number is used, it cant be used again
So when you enter 454882 the software is expecting that number (plus maybe a 4 digit password in addition). It will also allow for world time changes, timeslip and a few other things.
One downside with the tokens is batteries. Some companies who sell them replace them, other companies dont, you have to be issued with a new token.
You can also do it via SMS where the password is sent to your phone and can only be used once, or have a soft token (on screen)
Have a look at RSA Security, Vasco, Cryptocard, pinSentry and google 2 factor/strong authentication for more info
So when you enter 454882 the software is expecting that number (plus maybe a 4 digit password in addition). It will also allow for world time changes, timeslip and a few other things.
One downside with the tokens is batteries. Some companies who sell them replace them, other companies dont, you have to be issued with a new token.
You can also do it via SMS where the password is sent to your phone and can only be used once, or have a soft token (on screen)
Have a look at RSA Security, Vasco, Cryptocard, pinSentry and google 2 factor/strong authentication for more info
andy-xr said:
The token you have runs an algorith to generate a number every 6-10 seconds, and has a corresponding piece of software on the banks side also capable of understanding and generating the correct algorithm to match. When that number is used, it cant be used again
So when you enter 454882 the software is expecting that number (plus maybe a 4 digit password in addition). It will also allow for world time changes, timeslip and a few other things.
One downside with the tokens is batteries. Some companies who sell them replace them, other companies dont, you have to be issued with a new token.
You can also do it via SMS where the password is sent to your phone and can only be used once, or have a soft token (on screen)
Have a look at RSA Security, Vasco, Cryptocard, pinSentry and google 2 factor/strong authentication for more info
What he said.So when you enter 454882 the software is expecting that number (plus maybe a 4 digit password in addition). It will also allow for world time changes, timeslip and a few other things.
One downside with the tokens is batteries. Some companies who sell them replace them, other companies dont, you have to be issued with a new token.
You can also do it via SMS where the password is sent to your phone and can only be used once, or have a soft token (on screen)
Have a look at RSA Security, Vasco, Cryptocard, pinSentry and google 2 factor/strong authentication for more info
andy-xr said:
The token you have runs an algorith to generate a number every 6-10 seconds, and has a corresponding piece of software on the banks side also capable of understanding and generating the correct algorithm to match. When that number is used, it cant be used again
So when you enter 454882 the software is expecting that number (plus maybe a 4 digit password in addition). It will also allow for world time changes, timeslip and a few other things.
One downside with the tokens is batteries. Some companies who sell them replace them, other companies dont, you have to be issued with a new token.
You can also do it via SMS where the password is sent to your phone and can only be used once, or have a soft token (on screen)
Have a look at RSA Security, Vasco, Cryptocard, pinSentry and google 2 factor/strong authentication for more info
Blimey! Cheers AndySo when you enter 454882 the software is expecting that number (plus maybe a 4 digit password in addition). It will also allow for world time changes, timeslip and a few other things.
One downside with the tokens is batteries. Some companies who sell them replace them, other companies dont, you have to be issued with a new token.
You can also do it via SMS where the password is sent to your phone and can only be used once, or have a soft token (on screen)
Have a look at RSA Security, Vasco, Cryptocard, pinSentry and google 2 factor/strong authentication for more info
E31Shrew said:
Just transferred a bit of dosh using HSBCs online banking at work. After typing in all details to log on, you then have to press a button on a small keyring thingy with a 6 digit LCD built in. A random number is shown and then you type that in, on the 'log on' page, to access the system....Each time you log on, it gives a different 6 digit number...How on earth does this work?
We use HSBC business banking and think its a top notch system. Excellent user numptyness allowed for.We've never had a problem with the token thingy, but occasionaly it throws up a number that the system doesn't accept. It then defaults to your other security questions, so make sure you set these carefully!
The battery has not expired in 2 years of use, yet anyhow.......

E31Shrew said:
Just transferred a bit of dosh using HSBCs online banking at work. After typing in all details to log on, you then have to press a button on a small keyring thingy with a 6 digit LCD built in. A random number is shown and then you type that in, on the 'log on' page, to access the system....Each time you log on, it gives a different 6 digit number...How on earth does this work?
Explanation already given above - the the idea is that it's more secure if you need two things to log on rather than just one.So it's something you know - your pin.
and something you have - the token.
If you lose the token, nobody can use it. If your password gets stolen (i.e. by some malware on your computer) nobody can use it.
The voodoo with the numbers is just some clever stuff to come up with a way that you can remotely verify that the end person does have the token. The sequence of numbers is pseudo-random and an attacker won't be able to generate the next number in the sequence.
Gassing Station | The Pie & Piston Archive | Top of Page | What's New | My Stuff


