Do not type your PIN in reverse at an ATM

For the stupid lolwuts:

1. PINs are encrypted...
2. Putting it in wrong, leads to an error
3. In older systems, there's no way to identify the PIN was "entered backwards". The encryption algorithm cannot determine that.
4. On Chip cards, putting in the PIN backwards leads to an error condition, and decrements a PIN counter on the card's chip. Do it enough and you need to go see your bank for a new card they will likely charge you for.

People really need to be educated about how card payment systems work.. its amazing how many STUPID people are among us.
Please point me to a website or document that explains all this in detail, so that I can stop being stupid. Especially 1 and 4.
 
Last edited:
Please point me to a website or document that explains all this in detail, so that I can stop being stupid.

Its called "thinking about how things work" and the info is on Wikipedia.
As a bank account holder, it is in your best interests to know how the things work, that way you empower yourself against being scammed or being robbed.
 
Its called "thinking about how things work" and the info is on Wikipedia.
As a bank account holder, it is in your best interests to know how the things work, that way you empower yourself against being scammed or being robbed.
Please give me the reasoning that establishes with certainty that the PIN is encrypted. Would also like to see how you reason to a "PIN counter" on the chip that decrements on error. I can think of five other possibilities.
 
For the stupid
1. PINs are encrypted

Oh really? Please do educate us stupid people :crylaugh:
And perhaps explain why that is even relevant to the conversation.

^^Arthur's right, Randy's ignorance is amplified by calling others stupid.
 
Last edited:
Please give me the reasoning that establishes with certainty that the PIN is encrypted. Would also like to see how you reason to a "PIN counter" on the chip that decrements on error. I can think of five other possibilities.

Give us those possibilities?
 
Oh really? Please do educate us stupid people :crylaugh:
And perhaps explain why that is even relevant to the conversation.

If a PIN is encrypted, there is no way to determine what the actual PIN is. It compares the PIN you enter to a stored hash. You cannot recover the PIN from the hash. So typing it in reverse would merely mean a wrong PIN, the system does not know it's your PIN in reverse.
 
If a PIN is encrypted, there is no way to determine what the actual PIN is. It compares the PIN you enter to a stored hash. You cannot recover the PIN from the hash. So typing it in reverse would merely mean a wrong PIN, the system does not know it's your PIN in reverse.

This is what its about....

Except that that's not how it's done. Perhaps you need to back up your argument with an article explaining it.
PIN offset is your clue.
As for encryption, it is sent encrypted over the wire for verification and decrypted on the other side (the pin you punch in, not the pin associated with your card though they should technically be the same if it's yours and you haven't made a mistake). That, however, is irrelevant to the discussion.
Pin offset is used to verify your pin and is not a hash or encrypted representation of your pin.
 
Last edited:
Please point me to a website or document that explains all this in detail, so that I can stop being stupid. Especially 1 and 4.

Never mind that there are people who still do not know how to use an ATM yet banks issue them cards. Can't think how many times I have stood there looking on as people have security help them make their withdrawal. These people have no business owning an ATM card though, as they keep the PIN on a scrap of paper, which is even worse.
 
Except that that's not how it's done. Perhaps you need to back up your argument with an article explaining it.
PIN offset is your clue.
As for encryption, it is sent encrypted over the wire for verification and decrypted on the other side (the pin you punch in, not the pin associated with your card though they should technically be the same if it's yours and you haven't made a mistake). That, however, is irrelevant to the discussion.
Pin offset is used to verify your pin and is not a hash or encrypted representation of your pin.

The bank lied to me :( :rolleyes:

Seriously, I'm NOT going to trawl Google for an article.

Go to the bank and see if anyone can tell you what your PIN is. The PIN cannot be derived from the encryption by anyone.
 
how pin blocks are calculated according to the iso standard:
To protect the PIN during transmission from the PIN entry device to the verifier, the standard requires that the PIN be encrypted, and specifies several formats that may be used. In each case, the PIN is encoded into a PIN block, which is then encrypted by an "approved algorithm", according to part 2 of the standard).
https://en.wikipedia.org/wiki/ISO_9564

how pin blocks are encrypted, using DUKPT (Derived Unique Key Per Transaction)
In cryptography, Derived Unique Key Per Transaction (DUKPT) is a key management scheme in which for every transaction, a unique key is used which is derived from a fixed key. Therefore, if a derived key is compromised, future and past transaction data are still protected since the next or prior keys cannot be determined easily. DUKPT is specified in ANSI X9.24 part 1.
https://en.wikipedia.org/wiki/Derived_unique_key_per_transaction
 
The bank lied to me :( :rolleyes:

Seriously, I'm NOT going to trawl Google for an article.

Go to the bank and see if anyone can tell you what your PIN is. The PIN cannot be derived from the encryption by anyone.

But the pin is never stored. If it were encrypted and stored, it could be decrypted. The only thing that is encrypted is what you punch into the pin pad which may or may not be the pin. It is encrypted for transport and verification against the pin offset which is stored.
 
Top
Sign up to the MyBroadband newsletter
X