Here you go Bonsie - a confused guide to the whole shaboodle.
The logic is called multifactor authentication. The more factors I can ascertain the more I have confidence.
In general this is along the lines of 3 factors being
Your identity (a username, not enough to trust you)
Something you know (Password when you first setup the PIN reader, better but easy to find these days)
Something you have (pin reader is most secure, SMS to your phone, app on your phone - so I have three things including something physical in your hand - safer)
The "have" stops "impossible travel" e.g. logging in from UK and then China ten minutes later which is the sort of thing they monitor. It is a bit like getting the emails saying - I have just seen a password request from blah blah - if it was not you then you will know a hack is being attempted.(sorry I use quotes as these are nerd terms which mean something to nerds but may not stand out to normal humans!)
They do need to trust you as the level of money they lose to fraud each year has to go back into the costs and hence charges to you in some way, but you want free transactions or even worse cash back! If you want a look at the size of the fraud -
https://www.ukfinance.org.uk/system/files/Fraud%20The%20Facts%202021-%20FINAL.pdf So the tighter you get it the more you have for cashback!
So this needs to go beyond just a username and password which can be compromised fairly easily these days unless you follow the NCSC rules. It can be a pain but then so is having all your money stolen, that stuffs a day up big time. It also needs to allow for a PC and a phone etc etc. You can browse from yout smart TV these days, heaven knows if that is secure.....
So I log in to my phone (biometrics in front of username and password from account etc) which means I have at least the three above (name+pwd+device) so the bank knows it is highly likely to be me.
Now comes the decision between PITA and risk, part yours and part the banks. The bigger the risk the more likely they are to force a PIN type device or some additional confirmation requirement from you. New supplier, new payment type, large amount. Some of these you will be able to set yourself to reduce/increase the level of intrusion/protection.
Your card has the little partitioned silver blob on it when you apply power it chirps a code. When you first got your PIN reader you would have had to initialise it with your card and a PIN. This ties together the elements for future authentication allowing both sides to know what the other should tell them. The PIN is to ensure it is you using the card reader each time and also possibly part of the code it generates depending on the implementation.
You you have opened your phone 3 things but if you are on a PC it does not yet have enough trust as these do not need password and may not have an encrypted hard disc (see below)
You have opened your banking app (again probably three things through the handset biometrics)
It demands your PIN sentry (if setup for good security so offsetting the potential weak PC)
You enter the PIN on the PS (it knows it's you - good)
You insert the card which then derives a number based on the card chip and PIN + other stuff probably.
It uses this plus a big sum thingy to give you a little code.
The bank mean while is performing the same thing based on the initial setup which it knows and is waiting for a matching number.
Numbers match bingo they have approval not dependant on your PC or phone so feel safe.
The specific details of each implementation will be kept as quiet as possible to reduce possible corruption.
The use of date is not a big issue as the low power of IPU means a couple of tiny cells will run them for a long time. In most cases you loose them before they run out!
It represents a thorough way of making certain it is you at the keyboard. Protects you and them so it is a good thing.
If you change accounts I would highlight this as one of the things you should put at the top of your list on "are they a good match for me" and let an employee demo
1. What they expect on your PC or phone (which OS on the phone)
2. Can you flex the limits up and down to suite your needs
3. Can you turn it on/off for various options
4. How difficult is it to swap devices (phones) if you are an iOS fashion junkie like me and swap every 2 years
The reason for a separate device was more to reinforce trust in banking when we used to use PC and web browsers, they wanted people to use the Interweb so they could close branches and save costs. Now that phones are a far tighter ecosystem it is less necessary and most banks are flipping them out for dedicated apps with some form of message (SMS etc) which costs less and is now considered acceptable and less restrictive. The workload in buying, distributing, supporting, software development for them as well as the "annoy the user" and resulting support means they are less effective now. PIN Sentry type devices still hold a good place for people who simply will not trust the Interweb or a single device, not unreasonable.
NFC & Swipe Theft.
Many now have NFC (near field - close - communications) allowing a number to be read without contact to the silver blob. This number authenticates it as being you (device and application) and is effectively the same as the silver blob but over the air (3-4 inches). If you want to understand how questionable I find this then just get one of the "square/stripe/szettle" payment units linked to your mobile, key in <£45 as a charge and wave the payment fob past a persons handbag/back pocket on the bus/queue/street. It needs to be close for NFC but beware of people brushing up against your bottom. Maybe it is not your bottom they are after. Unless your card is in a faraday wallet you could have just had your money boosted. As they pass the sqaure fob past your back jeans pocket the fob reads the NFC and Bluetooths to their phone then makes the transaction over the WiFi/GSM to the bank as you stand their. A bit like the discussion of keyless car access NFC needs even more protection. Many different styles of wallet offer this now and it is worth having it.
PC or Phone.
If you are using a modern (<3 year old) Android or iOS device you have a good platform. It will default to asking you for a account and password on setup. You may even be smart and make the password longer given it can use finger/face to overlay this for ease. Also the whole device is encrypted unless unlocked. If you put a cable into it you cannot read it without opening with the password/biometrics. The data on the disc is encrypted making it damn hard to read.
The PC not so much. I can take most PC's and get everything. You simple take the disc out and put it as a second drive to a working PC. You have a password on your account, no problem I can still read it. Unless your account is setup well and you have turned on "bitlocker" disc encryption (in which case keep that recovery password word SAFE) the PC is a way bigger problem even with Windows 10/11. Somewhat better on MacOS but only if you turn on disc encryption there as well.
Next Gen Safest?
I am working with a couple of peeps on a four factor package at the moment - it adds a toolkit to enforce the activity to be restricted to known good locations so your accountant cannot be draining your account whilst sitting on a Bermudan beach. If anyone has a £1m to spare as seed money please do PM me!
Sorry it got a bit long but I wanted to place it in context.