Tweets

måndag 30 juli 2012

Security concerns and possibilities with BankID on bank card

Some months ago I couldn't pay for lunch since I had forgotten my VISA card at home. The frustrating thing was that I had my wallet but not my VISA card. Where was it? I then remembered that my bank had simplified the identification needed to access the online bank services. It had become possible to login and sign transactions using a bank card with BankID, card PIN number and a card reader. Compared to the previous solution this meant less input from the user, entering a PIN is enough. The catch is however not to forget the VISA card in the reader when your done with your online bank errands. Well, I forgot.

VISA card with BankID, a card reader asking for card PIN to access online bank services

Some days ago I started thinking about how I could use the simplified identification without running the risk of forgetting my card in the reader. What if I just had two VISA cards? Having one official extra card would come with an extra fee. So, what about having an inofficial extra card, meaning I order a new and keep my old. Yes, the old would be blocked for payment, but I am only interested in its BankID function. I called my bank and they told me it was not possible to login with an old card since it would be blocked as soon as the new was activated. They even double checked that with BankID personnel while I was waiting on the phone. However, I ordered a new card.

Today I received the new card and tried log in with it using BankID. It worked. I tried to log in with the old card and it worked. Since my new card wasn't activated I then activated it through the online bank serice. This didn't make any difference, both cards are valid for log in and transaction signing using BankID.

This is great, I can now keep new card in my wallet and the old in the card reader. But this means also that if you lose your card, you cannot simply order a new one without being fully safe. There is a risk that, if someone has your (old) card and PIN, a person could monitor your transactions and transfer your money to other accounts!

UPDATE 2013-12-09: received a new card with new card numbers. So, once again I was in need to get a second card for my card reader. But this time I was honest when calling SEB and explained fully the purpouse of the second card. The operator said that having two cards with same number and using BankID was "technically not possible". He said that he knew this since he had been working long time with BankID. However, a second card is now on the way.

In addition, when a credit card is completely blocked then BankID stops working the same second.