This PIN can be easily guessed
this-pin-can-be-easily-guessed.github.io
this-pin-can-be-easily-guessed.github.io
as a basic rule of thumb, any paper on cybersecurity that does not start the discussion with a reference attack vector and listed assumptions is probably garbage.
a charitable interpretation would be that they left out such details in the leading summary, but those details matter more than the actual findings. if im an IT manager and trying to decide how to lock phones, an accurate threat model is more important than the mitigations. good mitigations against the wrong threat is much, much worse than bad mitigations against the correct threat
EDIT: woops! i did the bad thing thats ruining society and read the web article instead of the paper. the paper has a whole section on picking a threat model. i dont have time to read the whole thing, but my skimming seems to be that the list length of actually used 4 digit pins is of comparable size to 6 digit pins, which is surprising but the paper still feels a little bit published-for-the-sake-of-publishing
I feel like reading the site that presents the paper shouldn’t really count…
Even though lay-person/marketing summaries of papers, and popular reporting summaries very often mess up academic results, or even just leave out details, personally I feel like having some hidden requirement to read through and understand the complete academic sources behind any article is onerous and might be unreasonable, especially if the paper is technical and inaccessible to a lay audience.
I appreciate it when someone like @kryogen1c recognizes and admits their gut reaction was based on incomplete information, that's as valuable to me as hearing comments that research and understand the sources.
Actionable guidance for real world decisions is not the objective of academic research. The objective is to expand the human knowledge base (which hopefully translates to something practical at some point).
If the authors have the domain expertise to weigh in on PINs, but not on attack vectors, then that is what they should do. Let someone else draw the conclusions for IT managers.
Sigh. Shoutout to all of the people who's passwords end with 1. or .1
Time makes it worse - since all of the sites in that era had roughly the same rules about passwords, people adapted their passwords and just always used a password with dot one on every site. So the goal of protecting passwords from dictionary attacks became completely moot.
I mean, it's not as bad as I make it sounds but still. And as always, relevant XKCD: https://xkcd.com/936/
As an aside, Apple’s related MDM password policy is utterly bonkers, as it prevents passcodes with ascending or descending numbers adjacent to each other if you disable “simple” passwords. This was frustratingly humorous when I tried to use a long numeric code and it would constantly run afoul of that check due to statistics while a 6-digit “pattern” passcode would be accepted just fine.
That's just silly. Assuming it also disallows duplicates next to one another, that means that there is only 7 valid digits for position 2 through 4, aka 10 * 7 * 7 * 7 = 3730 possible combinations, less than half the search space.
At this point, the only reason I use a pin is to I can use the touch sensor to open my phone, and to "keep the honest people honest." I really only care about keeping my kids out of my phone.
IMO, what's more important than a secure PIN? I'd like to be able to lock down applications within Android / iOS instead of relying on the application to implement its own password.
Oneplus has this on Android (called "App Locker"). It let's you choose a number of apps where you need to enter the system-level password/fingerprint/pattern/pin.
However, this is not separate from you login credentials, so it is not perfect IMHO. I would prefer to disable biometrics for the apps, but have it enabled for unlocking the phone.
Why on earth are the two related? You can't actually use Apple Pay without Touch ID or a pin.
Apple aspires to a future where there's no point stealing an unattended iPhone, because it'll have an unbypassable lock for sure, and hence zero stolen goods value.
My n=1 experience with people stealing phones is that they couldn't care less whether it was locked or not. I presume worst case it is sold for parts.
iPhones have a feature called activation lock. You can't wipe them without the previous owner's AppleID.
A passcode or touchID is needed to make a payment with Apple Pay, irrespective of whether or not your phone is unlocked.
> Why are the 2 related? I'd like to use ApplePay without TouchID or a PIN.
Also, this lego iPhone testbed is glorious.
And Lego's designers could lend their expertise to creating some wiring routing and harnesses, or design some mounts/surrounds for breadboards. Or mounts for standard SoC boards like the ESP32 or Mega2560.
1. Input "0531" on another iPhone's setup screen.
2. Try "0531" and the other suggested PINs, based on distance from thumb to the option.
He figures if by Friday morning he has not been told, then he will immediately know his execution is on Saturday, thus violating the Judge's order; therefore he cannot be executed on Saturday.
Knowing he can't be executed on Saturday, if on Thursday morning he has not been told, he knows he must be executed on Friday, thus violating the Judge's order. By induction it would violate the Judge's order to execute him on any day of the next week.
The following Tuesday he was thus completely surprised to be taken out to be executed.
7397: Digits 4-8 of the sequence "sum of iterated phi(n)".
1074: Sorry, that's digits 4-8 of log_21(8). Please try again.
6235: Sorry, that's digits 10-14 of an irregular triangle read by row's squarefree quadratic non-residues. Please try again.
2099: Sorry, that's digits 4-8 of the decimal expansion of the x-intercept of the shortest segment from the positive x axis through (2,1) to the line y=x.
Clearly, these are all way too easy to guess for an attacker for you to use them as a PIN number.
https://blog.xkcd.com/2008/01/14/robot9000-and-xkcd-signal-a...
But they can also attach another source, such as inputting an api key to NewsAPI and then to generate each suggestion we take a random news article and take three consecutive words from that article.
What I do worry about, though, is somebody watching me enter the code. And I don't have any paper and a promotion-site with a catchy name to provide, but it feels like catching somebody rapidly entering 4 pseudo-random digits is quite a bit easier than catching them rapidly entering 6 or 8 pseudo-random digits.
It also have the advantage of not having to save it in a password manager, since I have it on my calender (with a lot of other birthdays saved).
4-digit Birthday-pins are probably good as long as they're not your birthday or that of your kids, and you do the last 2 digits of year, last digit of month, last digit of day, go capture as much of the entropy from the date as possible.
On a side note, I remember back in 2004, a colleague born on Feb 29th, 1984 was unable to enter the U.S. H1B renewal website because someone forgot about leap years in their date validation logic.
Are you saying you can’t have a 4 digit pin? Because if you are then I just want to say that you can have 4 digits if you really want, it just defaults to a 6 digit during setup and there is an option to change to a 4 digit if you want.
Also. Password reuse if a bad thing. If you are really going to reuse a 20 year old pin, you might as well disable pin security completely.
What a foolish statement. Having a pin at all prevents a whole lot of attack vectors, even if weak. Like someone at random picking up the phone and getting personal information off it from any app lacking secondary authentication.
Having a weak pin won’t protect you from someone actively seeking to attack you specifically (a targeted attack). But most crimes are crimes of opportunity, not targeted, and any pin at all reduces the opportunity.
It’s not like they’re gonna actually use the PIN.
It is, however, only a five-minute task, so people may not select a super memorable PIN, just one they can remember for the duration of the task.
I think given the design of the task, people may be likely to use their actual device PIN for the task, because although nothing in the task suggests that you should do this, nothing suggests that you should not.
So we are trying to avoid the now-common ones, which (aside from the obvious 4x one digit or 1234, etc.) will result in those becoming less common, and then to re-evaluate we have to submit one in a hundred PINs from all app users and sort of load balance who can use which PIN?
Or we just generate random ones and memorize them. If you care enough to install an app like this, this seems like the easiest solution such an app could offer: read a few bytes from /dev/urandom until there are 4 digits and display them on the screen.
either 4 digit pins are all bad, or they're not. do not pre-define some subset. all this is going to do, if someone was to take this seriously, is make it an extremely user hostile experience by some app. i already hate how some bank apps instead of morphing over to face ID or other secure methods of verification, or even Authy, will harass me to no end to modify the password to some gibberish that they've pre-determined to be 'safe'.
also, if you're building a brute force code breaker are you really going to program the 40 most probable pins upfront and then have a loop? i'd think that you just create n+1 loop starting at 0000 and that's it.
But what is vastly superior is going into the settings and enabling the alphanumeric longer pins (aka passphrase).
It's variable length and does not give any clues as to the length, and it allows for a much larger character set.
This vastly increases the search space. I don't even know how long my passphrase is (never counted), but it is long enough that my wife still can't remember it despite repeatedly telling her what it is.
Before the biometric unlocks I never used a pin because it was a pain, but now with the biometrics I so rarely need it that I think it's a great compromise.
This is not about unlimited guessing, obviously, because 4 or even 6 digits can just be guessed in under a second!
TL;DR: You can find the blacklist this way but not unlock a phone.
http://www.flong.com/projects/slon/
The Secret Lives of Numbers
The Secret Lives of Numbers (2002: Golan Levin, Jonathan Feinberg, Shelly Wynecoop and Martin Wattenberg) is an interactive data visualization and online artwork, commissioned by Turbulence.org. An exhaustive empirical study was conducted to determine the relative popularity of every integer between zero and one million. The resulting information exhibits an extraordinary variety of patterns which reflect our culture, our minds, and our bodies -- forming a numeric snapshot of the collective consciousness. In The Secret Lives of Numbers, these analyses are returned to the public in the form of an interactive visualization, whose aim is to provoke awareness of one's own numeric manifestations.
The authors conducted an exhaustive empirical study, with the aid of custom software, public search engines and powerful statistical techniques, in order to determine the relative popularity of every integer between 0 and one million. The resulting information, presented in an interactive online information visualization, exhibits an extraordinary variety of patterns which reflect our culture, our minds, and our bodies.
For example, certain numbers, such as 212, 486, 911, 1040, 1492, 1776, 68040, or 90210, occur more frequently than their neighbors because they are used to denominate the phone numbers, tax forms, computer chips, famous dates, or television programs that figure prominently in our culture. Regular periodicities in the data, located at multiples and powers of ten, mirror our cognitive preference for round numbers in our biologically-driven base-10 numbering system. Certain numbers, such as 12345 or 8888, appear to be more popular simply because they are easier to remember.
The Secret Lives of Numbers (2002; Taiwanese documentation 2004)
https://www.youtube.com/watch?v=vwwq8vJb9Sw&feature=emb_logo
Photo set
https://www.flickr.com/photos/golanlevin/sets/72157594388612...
The Secret Lives of Numbers was implemented in 2002 as a Java applet. Appropriately-configured browsers can present the online work here at Turbulence.org.
Also consider the attack vector: can an attacker just boot another OS and bypass the lock that way (so a super secure password won't fend off determined attackers anyway), or is it your disk encryption password? Is there a HSM that enforces a limited number of attempts (e.g. bank card)? Etc.
What infuriates me, on the other hand, is that since some Android version the fucking thing demands me to enter the PIN after some time (72 hours, I guess) of successfully using fingerprint-lock only. And I don't think you can turn it off in the settings, I tried, I didn't find a way. And this is really stupid, both because it's not their fucking business if I don't worry about my device security so much, and because the attack vector it protects from is exotic to say the least: so the attacker already has my fingerprints, is successfully using them for the last 3 days to unlock the phone, didn't let the phone to be turned off during that time, but somehow still didn't steal all my data and can only do that after 72 hours after last I unlocked my phone with a PIN? Fuck you, Google, or whoever thought this is a good idea.
precisely. It's obnoxious.