That's a terrible idea. This isn't a library card. You're PIN shouldn't be known by anyone who knows your phone number.
That's a terrible idea. This isn't a library card. You're PIN shouldn't be known by anyone who knows your phone number.
Why dont you send the card and PIN out separately like a bank?
Every "normal" credit and debit card I've received in the mail has used this same procedure -- call a number on a removable sticker stuck to the card to activate it where the only verification is the phone number you're calling from (and caller ID is easily faked).
How is this any worse than how every other card activates?
And how do you propose they get around the mail interception problem? Have a courier deliver it to you and place it in your hand?
As for interception, I guess you could require a signature for delivery but that's a pita. You just have to weigh the risks in that situation and the convenience of not requiring a signature obviously outweighs the risks of theft.
EDIT: grammar
Where I am, PIN and Card arrive in different letters, and the Card letter is only sent once you confirmed via your online banking interface (which uses 2FA) that you received the PIN letter. And you need to confirm online in your banking interface to have received the card to be able to use it.
I'd like a chip card that requires a PIN (and that is accepted widely in the US) because such a card would make unauthorized charges less likely after the card is lost or stolen, but was not able to find one.
Require the customer to verify that he/she received the card in their online banking interface.
Mark it as invalid/stolen/whatever before that.
If the attacker already has access to the online banking account, then he/she can do much worse things anyway.
And it only delays the process by 2 days. At maximum.
The fact that you can even say "well it's only 2 days delay" seems insane to me.
I don't know if this is now normal in the UK. The previous time I opened an account in-branch was 2004, when the chip card arrived by post a few days later, with the PIN in a separate letter.
In fact, I’ll go next friday to the bank to get a new debit card, as my existing one stopped working a few months ago.
It's been a long time since I was into telephony stuff, but IIRC caller ID is easily faked but ANI is not. Do verifications use CID or ANI?
this is also why caller ID blocking (as provided by your telco) doesn't work when calling toll-free numbers.
1: https://en.wikipedia.org/wiki/Automatic_number_identificatio...
Part of the appeal of bitcoin to many is "Banks are so unnecessarily expensive to transmit value", the bitcoin industry has slowly and painfully been learning one disaster after another that maybe some of that cost isn't unnecessary after all.
EDIT: My point is that a financial service is more than just the protocols used. Actually the protocols are the least important thing to the average customer. The more important thing is trust. I trust that my money in the bank will stay there and that transactions made using my bank will go to the person I say they should. Part of the reason for my trust is in the regulation around the banking industry. E.g. the savings guarantee here in the UK(/EU?). The bitcoin industry (not the protocol but the services around it) have yet to provide me that level of trust coupled with comparative ease of use.
I think that many people hold bitcoin and bitcoin businesses to a higher standard than they would companies that operate outside this sphere.
I hold them to exactly the same standard as traditional financial services. I can see you point in that for many people bitcoin is just voodoo (on the other hand for many people traditional financial services are voodoo and people trust them with their pensions).
At least, it would be an unmitigated disaster for the Wild West style of regulating fiat currencies.
People hold BTC businesses to a higher standard because after your BTC is stolen by 'hackers' in an ex-Soviet republic, you have absolutely zero recourse. They hold BTC to a higher standard because no individual in the fiat world siphoned off a trillion dollars into his accounts last year. They hold BTC to a higher standard because the companies operating in the space absolutely refuse to properly protect their customers.
What about the $1bn stolen from moldovan banks?
There has been no customer recourse there.
Trillion? Really? That is an order of magnitude grater than bitcoins total market cap.
Depending on how you want to measure the amount of fiat currency in circulation, 7% of that would be close to a trillion dollars.
I was more thinking of institutional theft (i.e. embezzlement). I'm almost certain my bank won't just vanish the money I have lent them through my savings account. Of course the same cannot be said of "Random Investment Company Name" who was recommended to me on a forum/down the pub. As yet (and I hope that this changes) non of the bitcoin service companies have risen above this level of trust (for me personally).
EDIT: Added fact that my assessment of trust is my personal subjective opinion and shouldn't be taken as a fact.
.. which isn't really true in the EU ("Faster Payments"). It's only true in the US because the regulation is fragmented and reflexively in favour of the capitalist over the consumer. It's the banking equivalent of Comcast.
Are you from Iceland?