Jon Vincent (jonboy@osiris.ml.org)
Thu, 6 Aug 1998 12:33:52 -0400 (EDT)
On Thu, 6 Aug 1998, Martin Grap wrote:
> Well there is probably some data on the magstrip which your friend can not
> interpret but in order to conclude that it is the encrypted PIN he probably
> would have to break the "encryption". And he admits that he has not done
> that yet.
Very true.
> If you do it properly there is simply no technical reason to store the PIN
> or any other secret information in any form on the mag stripe of an ATM card.
> In the worst case (ATM offline), the ATM has to know the PIN generation key.
> If the ATM operates only online the ATM not even has to know the PIN
> generation key.
True again. I was just merely offering some more info to this thread that
might provide useful.
- Jon
The following archive was created by hippie-mail 7.98617-22 on Sat Apr 10 1999 - 01:10:56