NatWest - home card reader?

Mar 07, 2018 132 Replies

The transaction profiler should catch that, and trigger a hold until the bank has verified it's a genuine transaction by an independent channel.

Until all your payees mysteriously vanish and you have to set them up all over again.

Happened to me last year. Never could understand Barclays 'explanation'.

I suggested a while ago that banks could setup a (opt-in ?) mechanism whereby entering the PIN backwards triggers an "insufficient funds" message - and a call to the local plod ?

in 1983, having banked with Barclays for a year, they managed to put my account into overdraft (I was 17). I had to physically call into the bank. They tried to explain it as a mix up between my and my mothers account.

I am *still* waiting for the letter that the manager promised they would send explaining everything.

In a way, it was a blessing in disguise, as it highlighted how utterly, absolutely, incredibly *and* unbelievably incompetent *all* large organisations are at a very early age. Although to be fair, my parents experiences with Nat West previously were a good indicator.

I sent a cheque and credit slip to the address on my cheque book, only to find that the branch had been closed and redirection had expired,

They certainly cope with changes in the last four digits of the card. Barclays change the 16 digit number each time a new debit card is issued and I can assure you this does not require a new Pinsentry machine.

Just like all the urban legends then? ;-). Not a bad idea, just never been implemented.

formatting link

Tim

Did you try a new battery? You can adjust the contrast on the Nationwide/NatWest ones.

Tim

You can use it to log into online banking as an alternative to the "passcode/memorable word" method. You just need your debit card's PIN.

I find it rather annoying that payees disappear after a year of inaction. I only pay my water bill once a year so it tends to disappear and I have to set it up again with the danger of getting it wrong.

on 07/03/2018, Andrew supposed :

So, anyone could borrow anyone else's reader and it should work, certainly if it the same bank? There is nothing coded in the reader, to the account?

I thought it was 13 months for that very reason.

That's my understanding. I don't see this as an issue though because it is the combination of the last four digits and the PIN that generates the eight digit code. As long as you keep your PIN secret, you are in much the same position as you would be at an ATM (which is also not coded to any particular bank/account).

I got the idea from an alarm salesman (ADT ?). He said the alarm had a "hostage" mode which entering the PIN in reverse triggered.

It apparently placed a silent call to the monitoring centre (which, in reality, was what they were selling).

Card numbers have a weak parity ... Luhn enconding ???

I wonder if you are thinking of Direct Debits. A Direct Debit mandate usually lapses after 12 months without use - to avoid the risk of companies having vast numbers of mandates on their systems from past customers.

Payees for online banking are different. I have had payees which went unused for several years but then worked fine when needed.

Or you could have changed the batteries.

Nope. You put your card in and then your PIN.

The Natwest in our local small town is closing. Why? Because in November last year, they had 57 customers come through the doors. 57. In a month. No business can continue like that.

The readers all implement the same standard crypto signing system, so although the banks don't all use them in exactly the same way, the machines themselves should be interchangeable. Its the chip on the card combined with your pin that makes the thing unique.

I haven't tried it, but I assume that entering the same 8-digit code on a subsequent login occasion would generate an error, implying that the bank stores all the previous codes. This means that it's no use to someone who intercepts it for re-use. The "one-time password" system.

This contrasts with "two factor authentication" which assumes possession of a specific object, such as the user's mobile phone (or a card reader which *is* special to the user), plus a PIN or password.

There's also "challenge-response authentication" where the bank will provide a code which has to be entered into a card reader - using the "Respond" button on PINsentry.

That's just the impression I get of how it is supposed to work.

The point of 2FA (two factor authentication) is that it requires two separate stages in the security. In this case it verifies something you know - i.e. account details, password, and bank card PIN etc, and also verifies something you physically have - i.e. your bank card.

The reader is just a mechanism to allow you to safely transmit securely something that proves you are in possession of the card - itself it does not form part of the authentication since they are all the same.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required