<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>Comments on: PINs still under attack!</title>
	<atom:link href="https://javacard.vetilles.com/2011/08/27/pins-still-under-attack/feed/" rel="self" type="application/rss+xml" />
	<link>https://javacard.vetilles.com/2011/08/27/pins-still-under-attack/</link>
	<description>A weblog on Java Card, security, and other things personal</description>
	<lastBuildDate>Thu, 18 May 2017 07:26:32 +0000</lastBuildDate>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=4.0.32</generator>
	<item>
		<title>By: Thoth</title>
		<link>https://javacard.vetilles.com/2011/08/27/pins-still-under-attack/#comment-20306</link>
		<dc:creator><![CDATA[Thoth]]></dc:creator>
		<pubDate>Fri, 22 Apr 2016 13:34:51 +0000</pubDate>
		<guid isPermaLink="false">http://javacard.vetilles.com/?p=734#comment-20306</guid>
		<description><![CDATA[One obvious method to prevent smartphone screen password attacks by motion sensors in the phone is to randomise the keyboard which have long been implemented by Cyanogen.

In fact the more secure method is to include a PIN or biometric entry on the security device/smart card for on-device authenticatiin then press a OK or Cancel transaction on the securitu device/smart card.

The Zwipe product includes a fingerprint sensor on a smart card and the likes of Plastc and other E-ink cards are embedding touchscreen E-ink or buttons on smart cards.

Finally, the Ledger Blue hardware is a personal security device integrating a ST31 secure element tied to a touchscreen with USB, NFC and BLE connectivity for secure applications and PIN entry onto a single device to make scraping PIN much harder.]]></description>
		<content:encoded><![CDATA[<p>One obvious method to prevent smartphone screen password attacks by motion sensors in the phone is to randomise the keyboard which have long been implemented by Cyanogen.</p>
<p>In fact the more secure method is to include a PIN or biometric entry on the security device/smart card for on-device authenticatiin then press a OK or Cancel transaction on the securitu device/smart card.</p>
<p>The Zwipe product includes a fingerprint sensor on a smart card and the likes of Plastc and other E-ink cards are embedding touchscreen E-ink or buttons on smart cards.</p>
<p>Finally, the Ledger Blue hardware is a personal security device integrating a ST31 secure element tied to a touchscreen with USB, NFC and BLE connectivity for secure applications and PIN entry onto a single device to make scraping PIN much harder.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
