BofA mails your PIN to the same address as the card it unlocks
scrollinondubs.com
scrollinondubs.com
Also, he worries about the PIN being stored somewhere in plain text. If one-way hashes were used, anyone obtaining the hash would only need to test it against 10k possible values to get the original.
HMAC means Hash based Message Authentication Code.
HMAC(K,m) = H((K ⊕ opad) ∥ H((K ⊕ ipad) ∥ m)).
HMAC(key, password) instead of hash(password) or hash(salt+password)
Even using bcrypt set to take 1 second to verify a hash wouldn't be great -- it'd take about two hours and 45 minutes to break a PIN. And yes, while this is significantly better than not hashing at all (where it takes no time to get a pin) it would be trivial to target specific people to get their pin's given the hashed database.
Sure, you could make it take 10 seconds to verify a hash, but now all you've done is make me take a day to break the pin.
Still a pretty small rainbow table, I guess.
Next hyperbolic headline: B OF A TRACKS YOUR ACCOUNT BALANCE AND RECORDS EVERY PURCHASE!
Holy fuck, if a bank were to actually track every purchase I make, I'd freak out and switch banks. I always keep a bit of cash on hand so I have the freedom of buying something that isn't tracked by anyone. It's nice to be able to buy a beer without your bank knowing about it, you know?
I really really hope no bank every tries to pull anything like that. Even those of you who use cards for everything must appreciate the idea that you're able to buy things without your bank knowing what you bought, or even that you bought anything at all?
I tend to use cash simply because I'd rather have more of the money I spend go to the actual retailer (especially if it's a small business) than the bank. As a former retail business owner, I know how oppressive transaction fees are... yes, even debit card purchases.
As for sending the PIN in the mail, sometimes people forget their PIN. He lists three forms of communication he claims are more secure: voice, fax & inbox on the https site. Banks can more easily verify the mailing address because it's easier. At least with that you've got a mailman checking that the name matches the address. I realize that's not foolproof, but what is? It's easier than trying to verify a phone or fax number actually belongs to the right person. And with https, not everyone owns a computer, but it's rare for a bank opening an account for someone without a fixed address. Even when account statements are sent to a P.O. Box, they generally ask for a physical address for their records.
All three can be secure if there's proper authentification, but again, if he didn't need or ask for it in the first place then that's the real problem.
Edit: another problem with voice is the the bank employee on the other end of the line has to be able to see the plaintext PIN to speak it. Banks I have worked at strictly limited the number of people with access to that info, you couldn't just walk up to a teller and have them look up your PIN, for example.
They may have generated a new PIN and it just happened to be his old one? Could be.
Do they send it registered mail? What would happen if someoene did get to your mail before you - could they use the card? what would the bank do when informed of it?
Whwther or not it's bad for you, the consumer, depends on all these things.
As to storing the PIN in plaintext, that's not even the bank's decision, a single bank can't decide to go against the entire chip+pin system.
Side question: AFAIK, chip+pin is far less common in America than in UK/Europe, with many people still using magnetic+signiture. Am I out of date, or is this still the case?
Most stores will take ATM/debit cards (using PIN) as an alternative to credit cards (using signature), but the ATM/debit cards use magnetic stripe like the credit cards.
I've never thought about it before, but a bank really has to reason no send your pin number to you in print, or store it in a form that they could access.
Or do they?