Click here to return to the home page.
Image of a road.
Who's Online Now
2 members (Zach, DCH), 222 guests, and 33 robots.
Key: Admin, Global Mod, Mod
Top Posters(30 Days)
+8Rich 99
John V6 57
Newest Members
phenompilot52, Orjan, John Courtney, vince Indiana US, Garage Andreas
9,635 Registered Users
Newest Topics
Eurotunnel – is it a Car or Motorcycle?
by Chris99 - 13/09/26 05:44 PM
Body Mounting Bolts
by M3WMW - 13/09/26 02:02 PM
What Matt Humphries has been up to
by Bunny - 13/09/26 10:01 AM
Contributions to the forum
by +8Rich - 13/09/26 07:47 AM
small hose from air cleaner - 1989
by Carbuilder - 12/09/26 04:50 PM
New member in NYC
by SEG - 12/09/26 04:13 PM
Door card removal ?
by Pittsartist - 12/09/26 11:35 AM
Latest Photos
New to me 95 plus 4 daily driver
New to me 95 plus 4 daily driver
by SailingTom2, September 12
Bits to give away
Bits to give away
by TigerTim, September 11
1989 Morgan Plus 4 in Ontario, Canada
1989 Morgan Plus 4 in Ontario, Canada
by Carbuilder, September 5
First anniversary of Plus 4
First anniversary of Plus 4
by Strathaven, September 5
Wales
Wales
by Joske Vermeule, September 1
Forum Statistics
Forums39
Topics49,911
Posts838,147
Members9,635
Most Online1,063
Jun 14th, 2026
Today's Birthdays
dogmanjack, Frabro
Previous Thread
Next Thread
Print Thread
Page 1 of 2 1 2
Joined: Dec 2018
Posts: 1,309
Likes: 6
Bonesie Offline OP
Has a lot to Say!
OP Offline
Has a lot to Say!
Joined: Dec 2018
Posts: 1,309
Likes: 6
So from time to time things come along that I cant figure out ( like women for example )

If someone knows the answer to my confusion here, spill the beans.

Ok

When I do my online banking I have to use my card reader to log in.
So I pop in my card and press sign, I then enter my pin number in the card reader and a number comes up on the little screen.
This number I then have to input into the login area on my PC

How in tarnation does my PC/online bank know that number is a correct number ?? There is no link from card reader to my PC.

Ive resisted googling it as Id wanted to work it out myself but I'm at a loss.

What dont you understand ? Can the Morgan collective answer the burning questions rattling around your swede ?


Bonesie

Current stead -'The Captain' Black +4

'Life is like a garden, dig it' *Joe Dirt farmer
Joined: Aug 2017
Posts: 731
Likes: 58
D
Talk Morgan Regular
Offline
Talk Morgan Regular
D
Joined: Aug 2017
Posts: 731
Likes: 58
Funny you should say that.............it's all black magic to me. That's why I stick to real banks, but alas i do live in a City with a bank!!


Navy Dave
1976 Morgan 4/4
Joined: Feb 2016
Posts: 8,702
Likes: 416
Needs to Get Out More!
Offline
Needs to Get Out More!
Joined: Feb 2016
Posts: 8,702
Likes: 416
The card reader when supplied probably has a unique to your account mirror image of the processing algorithms stored at head office, so it knows in advance cronologically what code will be provided by its card in your standalone device.

This is the somewhat long-winded security system my partner has with her NatWest account, causing me to question how it worked. Thankfully it doesn't need to be used for general online login.


Richard

2018 Roadster 3.7
1966 Land Rover S2a 88
2024 Royal Enfield Guerrilla 450
1945 Guzzi Airone
Joined: Jul 2007
Posts: 28,912
Likes: 354
Salty Sea Dog
Member of the Inner Circle
Offline
Salty Sea Dog
Member of the Inner Circle
Joined: Jul 2007
Posts: 28,912
Likes: 354
Originally Posted by RichardV6
The card reader when supplied probably has a unique to your account mirror image of the processing algorithms stored at head office, so it knows in advance chronologically what code will be provided by your standalone device.

I used to have one of these when I banked with Barclays. Things may be different now, but I remember being in branch to effect a long forgotten transaction, had the card reader with me. Teller used a bank supplied reader on her desk to access my account (wouldn't use mine in case it had been "tampered" with).
I did wonder at the time whether it had something to do with the date/time of access to generate a code, but never got to the bottom of it.
When I moved banks I offered to drop the reader off at a branch, but was told to bin it as its security could be suspect.

Last edited by Graham, G4FUJ; 28/12/21 08:24 AM.

Graham (G4FUJ)

Sold L44FOR 4/4 Giallo Fly
'11 MINI Countryman Cooper D All4
'90 LR 90 SW
Joined: Feb 2021
Posts: 185
Likes: 2
L - Learner Plates On
Offline
L - Learner Plates On
Joined: Feb 2021
Posts: 185
Likes: 2
Originally Posted by Bonesie
So from time to time things come along that I cant figure out ( like women for example )

If someone knows the answer to my confusion here, spill the beans.

Ok

When I do my online banking I have to use my card reader to log in.
So I pop in my card and press sign, I then enter my pin number in the card reader and a number comes up on the little screen.
This number I then have to input into the login area on my PC

How in tarnation does my PC/online bank know that number is a correct number ?? There is no link from card reader to my PC.

Ive resisted googling it as Id wanted to work it out myself but I'm at a loss.

What dont you understand ? Can the Morgan collective answer the burning questions rattling around your swede ?



I used to have a Nat West account and used my Nationwide card reader for access when the Nat West reader ran out of power. Figure that one out!

Thankfully life has moved on and I can now access things with my fingerprint - unless I have the smallest of cuts on the appropriate digit and then I'm completely screwed.


2005 Plus 4
2020 Hyundai eKona
2020 Mitsubishi Outlander PHEV
Joined: Nov 2018
Posts: 6,676
Likes: 441
TBM Offline
Talk Morgan Sage
Offline
Talk Morgan Sage
Joined: Nov 2018
Posts: 6,676
Likes: 441
Originally Posted by Bonesie
Ive resisted googling it as Id wanted to work it out myself but I'm at a loss.


If you do resort to google, look for "Chip Authentication Program".


"Y mae dafad ddu ym mhob praidd"
1972 4/4, 1981 MGBGT, 1984 FLHT1340, 1980 XLH1000, 1990 ZX10
Joined: Nov 2012
Posts: 308
Likes: 31
Learner Plates Off!
Offline
Learner Plates Off!
Joined: Nov 2012
Posts: 308
Likes: 31
Hmm, I would speculate it is something like this:

the card readers do not have any user unique information in them.
your debit card has a unique number (eg your bank account number), B - this is not secret and can be read visually from the car and is known by the bank.
your debit card card has a secret PIN, P, only known to you and the bank.

When you put the card in the reader and press identify the reader asks for your PIN and checks this against the card. If good it continues, if not it stops.
The card then uses some sort of encryption algorithm to generate a key (this is the number that is used to identify you to the bank when you login online). The key, I, is based on P, B and a current time T (but that would mean the card reader has to have a correctly set real time clock in it which seems unlikely).

Since the bank knows B and P it can decode I and find out the if I was created within the last 60 seconds.

There may be some other bank specific constants included in the encryption to make things a bit more secure.

But I don't think my speculation is correct - the need for a real time clock in the card reader seems a bit implausible - what happens if it drifts or if you take too long to change the battery? So this append is jjust a long winded way of saying I don't know.... :-(

No doubt there are IEEE etc standards for this - I will have a look.


Dave
Blue 4/4 1969, Green +4 1953, (different) Green +8 1977
Joined: Nov 2012
Posts: 308
Likes: 31
Learner Plates Off!
Offline
Learner Plates Off!
Joined: Nov 2012
Posts: 308
Likes: 31
Ah, I was confused. If you use your phone to generate the 8 digit key that allows you to login online, then that 8 digit key is indeed timed out after 60 seconds. But that is because the phone can talk to the bank and/or the phone has an accurate clock in it. In fact the phone is going to be able use a much more secure algorithm than the chip and pin reader as the phone can talk directly to the bank.

If you are using the old style physical card reader, then there is no 60 second time out as there is no real time clock in the card reader. Your debit card contains a sequence number (presumably set to a random number when the card is issued). The sequence number is included in the key I when it is generated, and updated and saved on the card each time you generate key I. And the bank knows the initial sequence number that was given to your card. So the bank knows the sequence of keys I1, I2, I3 etc that your card reader will generate. If it ever sees a key that does not form part of this sequence or a key is presented that has already been used, or a key is presented that has an earlier sequence number than a key that has been successfully used previously, then the login attempt will be rejected.


Dave
Blue 4/4 1969, Green +4 1953, (different) Green +8 1977
Joined: Apr 2008
Posts: 12,265
Likes: 321
Scruffy Oik
Member of the Inner Circle
Offline
Scruffy Oik
Member of the Inner Circle
Joined: Apr 2008
Posts: 12,265
Likes: 321
Here's a little analogy that might help:

1. you have a secret you want to send to a friend. You want to lock the message in a box, but you don't want to let him have the key to your lock.

2. Put the message in the box. Put your padlock through the handle and lock it so no-one can open it. Send it to your friend

3. Your friend knows the message is valid and it came from you because he's got a list of all the serial numbers of the valid padlocks. He can't open it though because he doesn't have your key.

4. Your friend puts his own padlock through the handle next to yours and sends it back to you

5. You know it got to your friend OK, because you know the serial number of his padlock, even though you can't open it as you don't have a copy of his key.

6. You know it's safe, so you remove your padlock and send it back to your friend

7. Your friend now removes his padlock, opens the box and reads the message.

You have successfully exchanged a secret message without either of you knowing the other's secret code/key.

Now imagine this done with software in microseconds.


Tim H.
1986 4/4 VVTi Sport, 2002 LR Defender, 2022 Mini Cooper SE
Joined: Mar 2009
Posts: 11,535
Likes: 321
Smile, it confuses them
Member of the Inner Circle
Offline
Smile, it confuses them
Member of the Inner Circle
Joined: Mar 2009
Posts: 11,535
Likes: 321
Here you go Bonsie - a confused guide to the whole shaboodle.

The logic is called multifactor authentication. The more factors I can ascertain the more I have confidence.

In general this is along the lines of 3 factors being
Your identity (a username, not enough to trust you)
Something you know (Password when you first setup the PIN reader, better but easy to find these days)
Something you have (pin reader is most secure, SMS to your phone, app on your phone - so I have three things including something physical in your hand - safer)

The "have" stops "impossible travel" e.g. logging in from UK and then China ten minutes later which is the sort of thing they monitor. It is a bit like getting the emails saying - I have just seen a password request from blah blah - if it was not you then you will know a hack is being attempted.(sorry I use quotes as these are nerd terms which mean something to nerds but may not stand out to normal humans!)

They do need to trust you as the level of money they lose to fraud each year has to go back into the costs and hence charges to you in some way, but you want free transactions or even worse cash back! If you want a look at the size of the fraud - https://www.ukfinance.org.uk/system/files/Fraud%20The%20Facts%202021-%20FINAL.pdf So the tighter you get it the more you have for cashback!

So this needs to go beyond just a username and password which can be compromised fairly easily these days unless you follow the NCSC rules. It can be a pain but then so is having all your money stolen, that stuffs a day up big time. It also needs to allow for a PC and a phone etc etc. You can browse from yout smart TV these days, heaven knows if that is secure.....

So I log in to my phone (biometrics in front of username and password from account etc) which means I have at least the three above (name+pwd+device) so the bank knows it is highly likely to be me.

Now comes the decision between PITA and risk, part yours and part the banks. The bigger the risk the more likely they are to force a PIN type device or some additional confirmation requirement from you. New supplier, new payment type, large amount. Some of these you will be able to set yourself to reduce/increase the level of intrusion/protection.

Your card has the little partitioned silver blob on it when you apply power it chirps a code. When you first got your PIN reader you would have had to initialise it with your card and a PIN. This ties together the elements for future authentication allowing both sides to know what the other should tell them. The PIN is to ensure it is you using the card reader each time and also possibly part of the code it generates depending on the implementation.

You you have opened your phone 3 things but if you are on a PC it does not yet have enough trust as these do not need password and may not have an encrypted hard disc (see below)
You have opened your banking app (again probably three things through the handset biometrics)
It demands your PIN sentry (if setup for good security so offsetting the potential weak PC)
You enter the PIN on the PS (it knows it's you - good)
You insert the card which then derives a number based on the card chip and PIN + other stuff probably.
It uses this plus a big sum thingy to give you a little code.
The bank mean while is performing the same thing based on the initial setup which it knows and is waiting for a matching number.
Numbers match bingo they have approval not dependant on your PC or phone so feel safe.

The specific details of each implementation will be kept as quiet as possible to reduce possible corruption.
The use of date is not a big issue as the low power of IPU means a couple of tiny cells will run them for a long time. In most cases you loose them before they run out!

It represents a thorough way of making certain it is you at the keyboard. Protects you and them so it is a good thing.

If you change accounts I would highlight this as one of the things you should put at the top of your list on "are they a good match for me" and let an employee demo
1. What they expect on your PC or phone (which OS on the phone)
2. Can you flex the limits up and down to suite your needs
3. Can you turn it on/off for various options
4. How difficult is it to swap devices (phones) if you are an iOS fashion junkie like me and swap every 2 years

The reason for a separate device was more to reinforce trust in banking when we used to use PC and web browsers, they wanted people to use the Interweb so they could close branches and save costs. Now that phones are a far tighter ecosystem it is less necessary and most banks are flipping them out for dedicated apps with some form of message (SMS etc) which costs less and is now considered acceptable and less restrictive. The workload in buying, distributing, supporting, software development for them as well as the "annoy the user" and resulting support means they are less effective now. PIN Sentry type devices still hold a good place for people who simply will not trust the Interweb or a single device, not unreasonable.

NFC & Swipe Theft.
Many now have NFC (near field - close - communications) allowing a number to be read without contact to the silver blob. This number authenticates it as being you (device and application) and is effectively the same as the silver blob but over the air (3-4 inches). If you want to understand how questionable I find this then just get one of the "square/stripe/szettle" payment units linked to your mobile, key in <£45 as a charge and wave the payment fob past a persons handbag/back pocket on the bus/queue/street. It needs to be close for NFC but beware of people brushing up against your bottom. Maybe it is not your bottom they are after. Unless your card is in a faraday wallet you could have just had your money boosted. As they pass the sqaure fob past your back jeans pocket the fob reads the NFC and Bluetooths to their phone then makes the transaction over the WiFi/GSM to the bank as you stand their. A bit like the discussion of keyless car access NFC needs even more protection. Many different styles of wallet offer this now and it is worth having it.

PC or Phone.
If you are using a modern (<3 year old) Android or iOS device you have a good platform. It will default to asking you for a account and password on setup. You may even be smart and make the password longer given it can use finger/face to overlay this for ease. Also the whole device is encrypted unless unlocked. If you put a cable into it you cannot read it without opening with the password/biometrics. The data on the disc is encrypted making it damn hard to read.

The PC not so much. I can take most PC's and get everything. You simple take the disc out and put it as a second drive to a working PC. You have a password on your account, no problem I can still read it. Unless your account is setup well and you have turned on "bitlocker" disc encryption (in which case keep that recovery password word SAFE) the PC is a way bigger problem even with Windows 10/11. Somewhat better on MacOS but only if you turn on disc encryption there as well.

Next Gen Safest?
I am working with a couple of peeps on a four factor package at the moment - it adds a toolkit to enforce the activity to be restricted to known good locations so your accountant cannot be draining your account whilst sitting on a Bermudan beach. If anyone has a £1m to spare as seed money please do PM me!

Sorry it got a bit long but I wanted to place it in context.


Everyone loves a Morgan. Even me, unless it's broken again.
Page 1 of 2 1 2

Moderated by  TalkMorgan 

Link Copied to Clipboard
Powered by UBB.threads™ PHP Forum Software 7.7.5