Hacker News new | ask | show | jobs
by jbj 1345 days ago
not if that machine is an ATM
2 comments

So in case of ATMs we now need to make sure we soft touch some random buttons to ensure this trick doesn't work.
I have already seen some ATMs that shuffle the numbers on the numberpad around for each PIN entry. It is inconvenient for muscle memory, but prevents this kind of attack.
I know somebody working at a bank talking about their implementation, and how many elderly customers block their cards after wrongly entering their pin.
Also, to mitigate the problem somewhat, one could obfuscate the order at which the numbers were pressed by setting a custom pin with repeating numbers. Ideally, just repeating one./s
With an ATM you are already using a hardware token ;)