Here is a condensed summary for a quick reference guide:
| Method | Security Level | Convenience | Risk | |--------|---------------|-------------|------| | | Very high (chip + PIN + challenge) | Low (needs physical device) | Physical loss / battery death | | HSBC Mobile App Authenticator | High (biometric + device binding) | High (always on phone) | Phone compromise / malware | | SMS OTP | Medium (vulnerable to SIM swap) | High | SS7 attacks, social engineering | | Software TOTP (Google Authenticator) | High (if securely stored) | Medium | Seed extraction if phone rooted | hsbc pinsentry
When you first receive a physical Secure Key, you must set a personal 6-digit PIN to lock the device itself. Changes to digital banking - HSBC UK Here is a condensed summary for a quick
PINsentry was a pioneering and highly secure 2FA solution that protected millions from online fraud. In 2026, it feels dated but remains a gold standard for transaction-level security—at the cost of convenience. For most users, HSBC’s mobile authenticator offers a better balance. For those requiring maximum protection against remote attacks (and willing to carry an extra gadget), PINsentry still delivers. For most users, HSBC’s mobile authenticator offers a
Online forums (e.g., Reddit’s r/UKPersonalFinance) frequently feature complaints: “I can’t log in because I left my PINsentry at work” or “The screen is fading – do I have to wait 5 days for a new one?”
For high-risk activities like large transfers to new payees, the device can generate a "Transaction Data Signing" code to verify the specific details of that payment.
PINsentry is a roughly the size of a calculator. It combines: