Thread: Oyster Renewal
View Single Post
  #37   Report Post  
Old September 3rd 09, 08:32 AM posted to uk.transport.london
[email protected] boltar2003@yahoo.co.uk is offline
external usenet poster
 
First recorded activity at LondonBanter: Oct 2003
Posts: 459
Default Oyster Renewal

On Wed, 2 Sep 2009 18:46:39 +0100
Paul Terry wrote:
When a new PIN is selected, an offset generated by a complex hash is
recorded, and the bank will have a record of this offset. This allows
them to issue a PIN reminder without the necessity of storing a
vulnerable list of PIN numbers.


If the PIN can easily be recreated just using a formula then its just as
vulnerable as if they stored it directly.

B2003