Thread: Oyster Renewal
View Single Post
  #1   Report Post  
Old September 2nd 09, 05:46 PM posted to uk.transport.london
Paul Terry Paul Terry is offline
external usenet poster
 
First recorded activity at LondonBanter: Jan 2005
Posts: 106
Default Oyster Renewal

In message
, Andy
writes

I know that the PIN is held by the bank, otherwise it would be
very hard for a reminder to be sent.


I don't think that even the PIN is held directly by the bank. They will
have a record of the underlying security number of the card, which is
not revealed to the customer and can never be changed.

When a new PIN is selected, an offset generated by a complex hash is
recorded, and the bank will have a record of this offset. This allows
them to issue a PIN reminder without the necessity of storing a
vulnerable list of PIN numbers.
--
Paul Terry