FYI: Trusted Reviews | Visa Revamps Humble Credit Card.
James Firth
ukcrypto at chiark.greenend.org.uk
Wed, 12 Nov 2008 18:11:47 -0000
Charles Lindsey wrote:
> But this seems to rely on some purely internal mechanism to generate the
> next in some pseudo-random sequence, so how does Visa know whereabouts in
> the sequence your card is?
Usually in such devises the sequence is [somewhat loosely]
time-synchronised. Codes have a lifetime of one minute +- n minutes.
Of course it does not solve the phishing-type attack, unless the
authentication process starts with the entry of a code provided by the
website, allowing the card to verify that the requestor is an authorised
source.
James Firth