PIN Security Concerns
The cluster discusses the security strengths and weaknesses of PIN codes, especially 4-digit ones, for phones, bank cards, and accounts, debating brute-force risks, rate limiting, hardware protections, and alternatives like longer PINs or passphrases.
Activity Over Time
Top Contributors
Keywords
Sample Comments
if you're paranoid don't use a 4 digit PIN. use a passphrase. problem solved
It is an option. Make them use a randomized keypad when setting the pin, and make them enter it three times.
4 digits pin codes aren't passwords either. Sometimes good enough is good enough.
What's to stop them from mutilating you until you reveal your pin?
The 4 digit PIN is rate limited. How is that a single point of failure?
Not a bad idea, except there's a limit on the number of attempts. Otherwise you could easily brute force the PIN.
Why is a pin more secure than a password?
A PIN is a de-facto very weak password. Of course it can be brute forced!
It would be nice if they would start requiring a PIN.
I guess it's time to move to a 5-digit PIN in order to prevent this sort of leak from being feasible in the future.