Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

isn't the same attack valid with token based cards (I'm only familiar with RSA's tokens) .. as long as you're in the middle, anything goes..


All tokens distributed by banks I've seen until now here display the amount and the receivers account number prior to generating the transaction confirmation number. So you can double check that everything is correct


Some of these tokens (active ones) display the transferred amount. I dont know if these are still actively used, though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: