We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
CHIP - contact if mobile phone unavailable?
Comments
-
Just tested this (albeit with a reinstall, rather than a new device) and the Secure login (PIN and fingerprint settings) are not persistent.
So SMS message is the only authentication factor, for app/account access. Funds are protected by the connected bank security.1 -
Yes, I have a record of some 4-digit password for Chip that I was probably asked only once.Regarding the connected/linked bank, can't it be changed if someone gets into my Chip account? Or is it the customer name that must be the same for both Chip and the linked bank account?0
-
k_man said:Just tested this (albeit with a reinstall, rather than a new device) and the Secure login (PIN and fingerprint settings) are not persistent.
So SMS message is the only authentication factor, for app/account access. Funds are protected by the connected bank security.Well that is disappointing. Renders it completely pointless as if anyone ever gets unlocked access to the device, they can simply clear data, open the app, receive SMS and they are in.grumbler said:Regarding the connected/linked bank, can't it be changed if someone gets into my Chip account? Or is it the customer name that must be the same for both Chip and the linked bank account?I don't know what security steps are taken when adding a linked account, but someone would indeed need to open a current account in your name to steal your money by this route.0 -
masonic said:grumbler said:fonesaver said:masonic said:You can normally get a replacement SIM within a few days. In the event you cannot retain your old number, you'd need to contact them to associate your account with your new number (which will mean going through ID verification again). You can contact them via email for advice if you find yourself in this situation.I don't know if Chip allows you to log in from multiple devices (e.g. a tablet and phone). This can serve as a useful backup option, but not all providers support it.I'd always recommend keeping enough money in a non app-only account to cover your spending needs for at least a week or two in case of such an event.Does this mean that anyone who finds my phone with a SIM that isn't locked, can put this SIM into another phone, install Chip app there and get access to my account?I was told earlier that a fingerprint is needed only to unlock the app. If so, the only authentication factor remaining that is needed is the code sent by a SMS.You can set up biometrics to unlock the app, but as with all secure biometric access, this is specific to the device on which you activate it and never leaves that device. On a new device, there would not be the option to use biometrics until after a successful login, and those biometrics would be the ones stored on the new device.No app security is set up by default, but you have the option to set a PIN, which is requested when opening the app. I believe this is a prerequisite of the biometric lock and is the secret that the biometric challenge unlocks. Therefore, if someone got hold of your SIM and it didn't have a SIM-PIN (or they did a SIM swap attack), then they could download the app, enroll the new device, but would need the app PIN to get in to your account.0
-
Band7 said:masonic said:grumbler said:fonesaver said:masonic said:You can normally get a replacement SIM within a few days. In the event you cannot retain your old number, you'd need to contact them to associate your account with your new number (which will mean going through ID verification again). You can contact them via email for advice if you find yourself in this situation.I don't know if Chip allows you to log in from multiple devices (e.g. a tablet and phone). This can serve as a useful backup option, but not all providers support it.I'd always recommend keeping enough money in a non app-only account to cover your spending needs for at least a week or two in case of such an event.Does this mean that anyone who finds my phone with a SIM that isn't locked, can put this SIM into another phone, install Chip app there and get access to my account?I was told earlier that a fingerprint is needed only to unlock the app. If so, the only authentication factor remaining that is needed is the code sent by a SMS.You can set up biometrics to unlock the app, but as with all secure biometric access, this is specific to the device on which you activate it and never leaves that device. On a new device, there would not be the option to use biometrics until after a successful login, and those biometrics would be the ones stored on the new device.No app security is set up by default, but you have the option to set a PIN, which is requested when opening the app. I believe this is a prerequisite of the biometric lock and is the secret that the biometric challenge unlocks. Therefore, if someone got hold of your SIM and it didn't have a SIM-PIN (or they did a SIM swap attack), then they could download the app, enroll the new device, but would need the app PIN to get in to your account.Are you sure that you can 'call' Chip CS? I thought the only options were in-app messaging and email. The apparent lack of a phone service does weaken the security somewhat, as an offline discussion through messaging allows for improvisation and makes it much less likely that suspicion would be aroused.This is of minor concern to me because of the challenge someone would have linking an account that would be accepted by Chip. However, the critical vulnerability in their biometric and PIN security is of far greater concern, as it shows a fundamental naivety on their part and is something I will be following up with them.0
-
You are right, it’s “contact”, not “call”1
-
Seems that there are very few reasons why adding a PIN to lock your SIM would not be a good idea (even if it was just the same as your phone unlock PIN, although ideally something else).0
-
flaneurs_lobster said:Seems that there are very few reasons why adding a PIN to lock your SIM would not be a good idea (even if it was just the same as your phone unlock PIN, although ideally something else).
1 -
masonic said:flaneurs_lobster said:Seems that there are very few reasons why adding a PIN to lock your SIM would not be a good idea (even if it was just the same as your phone unlock PIN, although ideally something else).3
-
masonic said:flaneurs_lobster said:Seems that there are very few reasons why adding a PIN to lock your SIM would not be a good idea (even if it was just the same as your phone unlock PIN, although ideally something else).
I often see the advice that you will be aware of this happening if your phone loses service. So that's about 6 times a day as I walk around the city centre.
Are "big four" providers better at protecting their customer's assets than the MVNOs? Are there specific actions or instructions you can give to your supplier to make it more rigorous (and, of course, onerous)?0
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 350.3K Banking & Borrowing
- 252.8K Reduce Debt & Boost Income
- 453.2K Spending & Discounts
- 243.3K Work, Benefits & Business
- 597.8K Mortgages, Homes & Bills
- 176.6K Life & Family
- 256.3K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.1K Discuss & Feedback
- 37.6K Read-Only Boards