bloomberg on supermicro: sky is falling

Naslund, Steve SNaslund at medline.com
Wed Oct 10 16:39:18 UTC 2018


It is good but has several inherent problems (other than almost no one using it).  Your card number is static and so is your pin.  If they get compromised, you are done.  Changing token/pin resolve the static number problem completely, compromise of a used token has no impact whatsoever.

Steven Naslund
Chicago IL

>
>IVR credit card PIN entry is a thing
>
>For example - https://www.hdfcbank.com/personal/making-payments/security-measures/ivr-3d-secure




More information about the NANOG mailing list