Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

At least in my country I've seen a common practice for the bank to mail (separately, days before/after) an envelope with a temporary PIN to the customer, so that they can activate the card and change it.

Not sure if they do that in the US or if they'd do it for corporate cards as well, but I guess it wouldn't be a problem to intercept the second envelope for whoever intercepts the cards. In that case the PIN wouldn't add any value.

Now regarding card destruction, I wonder how hard would it be for them to just print fake cards with fake chips that just have the same numbers.

Probably a better solution would be forcing to activate the card in an atm, so that the chip would be validated.. cumbersome but safer.



In my experience, you'll receive the card and temporary PIN separately in the mail for debit cards in the U.S.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: