Not quite as frightening as the schemes some financial institutions use... one that immediately comes to mind is 6 digits, no more or less, and probably stored in plaintext. Then again, bruteforcing attempts are usually very easily noticed and kept from succeeding on such systems.