{"id":435,"date":"2012-03-30T18:22:09","date_gmt":"2012-03-30T17:22:09","guid":{"rendered":"http:\/\/www.floyd.ch\/?p=435"},"modified":"2022-02-09T11:14:34","modified_gmt":"2022-02-09T10:14:34","slug":"postfinance-digipass-810","status":"publish","type":"post","link":"https:\/\/www.floyd.ch\/?p=435","title":{"rendered":"PostFinance Digipass 810"},"content":{"rendered":"<p>Here in Switzerland, PostFinance (the bank of the national mail company) uses a small, yellow card reader for the two-factor authentication (I don&#8217;t want to talk about how good this two-factor authentication is, but errrr). Because I don&#8217;t need my device anymore I decided to poke around a little bit. First of all, it&#8217;s really nice that they tell you from the beginning which type of card reader it is (sticker on the back):<\/p>\n<p>Digipass 810<br \/>\nMADE IN CHINA<br \/>\nWWW.VASCO.COM<br \/>\nUS PATENTS: 4.599489 and 4.609777<\/p>\n<p>Easy start. If you look <a href=\"https:\/\/web.archive.org\/web\/20120124015158\/http:\/\/www.vasco.com\/products\/digipass\/digipass_readers\/digipass_800_range\/digipass_810.aspx\" target=\"_blank\" rel=\"noopener\">Digipass 810<\/a> up, you&#8217;ll see that it is compliant to something called &#8220;Europay-Mastercard-Visa Chip Authentication Program Enhancements&#8221;. A card which has no chip at all, will get you the error message &#8220;Falsche Karte&#8221; (&#8220;wrong card&#8221; in German). It doesn&#8217;t like my debit cards either (which have chips on them), it displays different error messages: &#8220;Karte Ung\u00fcltig&#8221; (&#8220;invalid card&#8221;) and &#8220;card error&#8221;. So I simply tried my credit cards and both (Visa and Mastercard) did work. The reader prompts for a code\/challenge, I just entered 1234 and it asked for my PIN. Interestingly it will only accept the correct PIN which was set for the credit card and will then output some TAN. A wrong PIN will result in an error message. Funny!<\/p>\n<p>So a malicious person who wants to try out the PINs for your credit card, but doesn&#8217;t want to risk to be recorded by a security camera at the ATM can use a Digipass 810 instead.<\/p>\n<p>TODO (i still need my credit card):<br \/>\n&#8211; Check if you really only have 3 tries<br \/>\n&#8211; Check if card is really locked (e.g. in store or at an ATM) after 3 tries<br \/>\n&#8211; Of course there is much more card stuff out there, eg. a presentation at <a href=\"https:\/\/web.archive.org\/web\/20210628134844\/http:\/\/dev.inversepath.com\/download\/emv\/emv_2011.pdf\" target=\"_blank\" rel=\"noopener\">PHNeutral 2011<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here in Switzerland, PostFinance (the bank of the national mail company) uses a small, yellow card reader for the two-factor authentication (I don&#8217;t want to talk about how good this two-factor authentication is, but errrr). Because I don&#8217;t need my &hellip; <a href=\"https:\/\/www.floyd.ch\/?p=435\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[65],"tags":[68,67,66],"class_list":["post-435","post","type-post","status-publish","format-standard","hentry","category-hardware","tag-credit-card","tag-digipass-810","tag-postfinance"],"_links":{"self":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts\/435","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=435"}],"version-history":[{"count":14,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts\/435\/revisions"}],"predecessor-version":[{"id":1254,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=\/wp\/v2\/posts\/435\/revisions\/1254"}],"wp:attachment":[{"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=435"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=435"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.floyd.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}