Jonathan Richards
Win luxury hampers plus Waitrose vouchers & guidebooks
"PINsentry" is the Barclays version of what in the US are known as "tokens", a technology which has been around for several years and is designed to combat online fraud.
The principle behind it is known as "two-factor authentication", meaning that in order for a bank to be certain that an online banking customer is who they say they are, two criteria must be satisfied.
The customer must know something - usually a login and password, and they must have something - in this case the device and the number it generates when the user's card is inserted.
In the case of a chip-and-pin transaction, both these are satisfied - the customer needing the card and four-digit code. But to raid a bank account online, all a fraudster requires is the login and password. These can be extracted from a trusting customer on a "phishing" website, which attempts to get customers to hand over their details by posing as a genuine bank website.
Devices like the PINsentry get around this problem by requiring that the customer have their card in order to make a transaction online.
When the card is inserted and the PIN entered, the pocket-sized device feeds back a number at random which is then keyed in to the website in order for the bank to confirm the customer's identity.
There are different levels of security. Some tokens do not require the card or PIN, and simply generate a number at random; Barclays' is one of the more rigorous. The idea underlying all tokens, however, is that if the customer can produce that number when the bank's website demands it, they prove they are in possession of the device, and have not obtained the login and password fraudulently.
Computer security experts said the device was "a good first step" in the fight against the current wave of phishing, which has affected Barclays particularly badly.
They warned, though, that tokens did not protect against the next generation of so-called "man in the middle" attacks, where the fraudster logs onto the bank's real website while simultaneously obtaining details from the victim - including the token number - on a phishing site.
"These devices are a major offensive in the war, and will get Barclays onto the high ground, but as soon as the other banks join them, then the bad guys will start training their artillery up there," said Richard Clayton, a researcher in the computing science department at the Unviersity of Cambridge.
Banks are increasingly focusing their security operations on the swift recovery of lost funds, Mr Clayton said, as they realise that fraudsters will always, eventually, be able to circumvent the latest safeguards.
"The challenge for the bad guys is not getting the passwords. It's getting the money out of the system fast enough so that it can't be clawed back. In many ways the changes in PIN technology are a sideshow," he said.
Read the training tips and advice that helped our London Triathletes
Times Online's new TV show helps you make the right decisions for your pet
Read our exclusive 100 Years of Fleming and Bond interactive timeline, packed with original Times articles and reviews
The latest travel news plus the best hotels and gadgets for business travellers
Shortcuts to help you find sections and articles

Overseas contacts and local business information

Find a course, arrange a game and save money
2007
£47,995
2008
£42,945
06/2006
£40,850
Great car insurance deals online
£33,000
Macmillan Cancer Support
Central/South West
£50k
NHS
Nationwide
£
£30k OTE
Meltwater News
Nationwide
circa £70k
Central Office of Information
London
5% below developer pre-launch price!
Luxury Appts, beautiful gardens w/ Thames views
Great Homes Available on a shared Ownership Basis
Great Investment, River Views
Visit the ‘entertainment capital of the world’
at great sale prices!
Christmas Cruises
From only £995pp
APTs East Coast now from only
£2425pp.
Great travel insurance deals online
Contact our advertising team for advertising and sponsorship in Times Online, The Times and The Sunday Times. Globrix Property Search - find property for sale and rent in the UK. Visit our classified services and find jobs, used cars, property or holidays. Use our dating service, read our births, marriages and deaths announcements, or place your advertisement.
Copyright 2008 Times Newspapers Ltd.
This service is provided on Times Newspapers' standard Terms and Conditions. Please read our Privacy Policy.To inquire about a licence to reproduce material from Times Online, The Times or The Sunday Times, click here.This website is published by a member of the News International Group. News International Limited, 1 Virginia St, London E98 1XY, is the holding company for the News International group and is registered in England No 81701. VAT number GB 243 8054 69.