PIN number analysis (2012)
datagenetics.com
datagenetics.com
It's also staggering how often a system requires a passcode but the operator's of the system don't want to use one, or the system needs to be provided with a known passcode so the client can log into it for the first time.
Often, also, passcodes serve as courtesy locks, where the intention isn't to make it impossible to gain access (far from it, often on industrial systems you might need night shift to be able to get in and change settings in an emergency) but to signal to an operator that they're entering an area of the program where they shouldn't touch anything without explicit instructions.
In either of these cases, an easily guessable (I'd go so far as to say 'standard') PIN strikes the right balance between no security at all, and actually keeping out people who might need access.
Neat
Would be interesting to look at the email addresses associated and see if you can see a pattern and maybe filter those out.
There's also little point in hashing a 4-digit PIN. If the PINs were perfectly distributed, it would only take an average of 5,000 guesses to find the original PIN given the hash. Of course, this analysis has shown that they're anything but perfectly distributed; a quarter of them would take less than 20 tries.
E.g. with a phone SIM card's PIN, you theoretically have the laughable space of 10000 variants, but you only get to try 9 times, the 10th should either be correct, or the SIM card stops working. This gives you about 1% chance of guessing right. With trying the common PINs first, likely maybe 10% chance. Still makes an attempt to break in impractical in very many cases.
"The combination is 1...2...3...4...5..."
"That's the stupidest combination I ever heard in my life... That's the kind of thing an idiot would have on his luggage."
http://www.globalzero.org/files/bb_keeping_presidents_in_the...
This is absolutely stupid. You can reverse the dataset almost completely from the provided data (images and fixed points).
FFS it's only a two column spreadsheet with columns "pin" and "count"/"frequency". It has no additional security implications after the release of this article.
Only if they know you’re a geek. The above fact won’t reach John Doe and influence his PIN choice.
[1] https://en.wikipedia.org/wiki/X86It's not a PIN number
You can't have a Personal Identification Number Number
I get that it's what people say, but that doesn't make it right.
/rant
The Department of Redundancy Department are hiring.
No it's not. "What is your debit PIN number" is not short for "what is your debit number that is a pin".
Nearly everyone that gets called out for it isn't really thinking about what PIN stands for and they certainly don't lamely defend it with this disambiguation excuse. The context in which people ask for someone's PIN essentially never has any accidental swap with "pen" or "pan".
"Type your pan on the keypad."
"Choose a 4-digit pen."
Please, English is bad enough, don't bury it with more bullshit.
As in, "PIN" is a name – not a macro that is supposed to expand to the decompressed phrase – and "number" is the kind. The name disambiguates it from others of the same kind, and the kind sometimes helps to disambiguate the name:
"Enter your number" vs. "Enter your pin" vs. "Enter your pin number"
"Go there and talk to the guy named Bob" vs. "Go there and talk to Bob"
Ftfy
in my defence, i'm using 2 pins, one for all debit cards, one for all credit cards.
This is mainly a recent change, as with contactless I rarely have to use the PIN
If one wanted to go all geek, one could of course do some mental hashing, e.g. by using the digits of the primary pin as indices into the string of digits prominently printed on the secondary card.
Pins are a bit of a safe playground for schemes like that, because the schemes are never significantly more unsafe than the best four-digit number.
Some banks enforce to change this PIN yearly on date Card was issued, & some others enforce that you can not use 3+ repetitive digits and/or your last N PINs, n being most commonly 10.