Analysis of bank PIN numbers
datagenetics.com
datagenetics.com
So if you're actually trying to break into people's accounts, it would be advantageous to know your victims' ethnicity. It's quite likely that cards stolen in Koreatown will have a different distribution of PIN numbers than those stolen in Chinatown.
http://translate.google.co.kr/?tab=wT#en/ko/one%20thousand%2...
You could argue one thousand four is actually easier to misinterpret because it could easily (although incorrectly) be read to mean "one thousand fours."
edit: typo.
100 2/3
102/3Just to make it worse for you: why don't people also pronounce 1492 as "one thousand and four hundred and ninety and two"?
100 2/3 - one hundred ... and two thirds
102/3 - one hundred and two ... thirds
Alternatively, use "plus" instead of "and" in the first case.
100 2/3 - One hundred and two-thirds. 102/3 - One hundred two over three.
I became even more surprised when I was told that I don't have to restrict myself to 4 digits! So, I entered a sequence of 12 or so digits that I happen to be able to remember easily but that otherwise follows no patterns as e.g. the ones mentioned in this article.
I thought I was so smart!
Except when I later found out that a lot of card readers in convenience stores accept a maximum of 8 digits for card PINs :-( I can't use my card there. So much for being a paranoid computer scientist...
[1]: http://www.datagenetics.com/blog/november12011/index.html
For reference I have (afaik fully random) bank-assigned PIN on my card.
* Bank of America
* Chase
* Citibank
* Wells Fargo $ pins() { seq -f '%04.0f' 0 9999; }
$ pins | egrep -c '(.)\1'
2710
$ pins | egrep -c '(.).*\1'
4960
$ $ pins |
> sed -r '
> :a; s/^([0-9])(.*)\1/\1\2a/; ta; s/[0-9]/a/
> :b; s/a([0-9])(.*)\1/a\1\2b/; tb; s/[0-9]/b/
> s/([0-9])\1/cc/; s/[0-9]/c/
> s/[0-9]/d/
> ' |
> sort | uniq -c | sort -n
10 aaaa
90 aaab
90 aaba
90 aabb
90 abaa
90 abab
90 abba
90 abbb
720 aabc
720 abac
720 abbc
720 abca
720 abcb
720 abcc
5040 abcd
$Of course, my not being aware doesn't mean you can't, but I know from experience that most of the big banks let you do it, and I can't think of a single example of either me not being able to do it or me hearing of anyone else not being able to do it.
I suspect there's no way to know which of our guesses is closer to the truth without a bank providing stats, which seems unlikely to happen. Or a poll somewhere..
Received card, no pin, called, sent new, recieved card, no pin, pin came 2 weeks later.. for the first card, no pin for second card, third attempt nothing was sent, went to the bank, they told me I had to call, gave up after 2 months, over the next year they sent me several new cards (security breaches?), but I never had a pin to activate them.
One year later they change their terms and contions, impose new fees, deplete my checking account, deplete my savings overdraft account, and then send me to collections... all for opening a couple of accounts and depositing a few hundred dollars.
Sure the PIN sucks, but ATM security is actually two factor, something you have and something you know. The cards can be duplicated, they've made good inroads on that but haven't rolled those cards out in the states.
Its an example of "good enough" security. Not only is the barrier to theft much higher than the cash next to it in their wallet, you only have a 30% chance of getting into their account before the ATM eats the card. If you do get in, you can typically only withdraw $300 and your face has been recorded.
Which kinda sucks that security is compromised to make more profit.
I find it kind of strange that you're picking up on this, do you not read everything on HN as a stream of soul-crushing money-first attitudes too?
His PIN? 4321
So the trick is to find their anniversary or first child's birthday.
In Turkey, most ATMs accept my extra-long PIN, but very few have UIs designed to fit more than 4 digits. On many of them, the digits will continue outside of the form field and sometimes all the way off the screen.
I had a 8 digit PIN, but only the first 4 mattered to the ATM. The screen would blink after the first 4 numbers, too, to help you notice you already had it.
Then two weird things:
1. The bank got bought by someone else, and the new bank demanded 6 digits. I had stopped using anything past the first 4, but they were still the first six from the original form I filled out years earlier.
2. They sent me my full PIN in the mail. At first I was surprised by this, since one-way-hash and all that jazz, but on reflection one-way hashing a six-digit PIN is pretty silly.
Is it a usability issue, or don't they realise that more digits means more pin options?
Strangely, there was one ATM that accepted 4 digits and then automatically continued to verification of the PIN. I never got a chance to enter the rest of the digits, but it still passed verification and allowed me to withdraw.
Given that users have a free choice for their password, ifusers select a four digit password to their online account, it’s not a stretch to use this as a proxy for four digit PIN codes.
but I highly disagree with that extrapolation.
> but I highly disagree with that extrapolation.
That's great, but your counter-claim isn't obvious at all. So please elaborate. Are you alluding to banks generally setting people's PINs for them, using more appropriate distributions? Or, God forbid, do you believe that users are more careful when picking sensitive PINs?I have serious doubts about the latter.
Well yes, of course.
Firstly, Banks do set the pin first, and the vast majority of people probably never change it.
On your second point, for a bank I would pick a complicated pin and/or password, for some throwaway website/app/game account I'd choose something simpler and easy to remember, many people probably use the same pin for loads of services, but wouldn't use it for their bank for obvious reasons.
Most people have some perception of levels of security, even if they only have a binary concept of 'involves my money' or not, and trying to extrapolate from website logins for some unimportant data to banking pins which involve real losses for the user involved is not at all convincing.
> Most people have some perception of levels of security
We're just trading intuitions here, of course, but I'm virtually certain that people's sensitive passwords are as abysmal as their non-sensitive ones. Sure, you'd pick a good password; however, the mere fact that you're debating this point and that you know what password goodness entails tells me that you're not a helpful sample of the population in question (namely everyone).I'm going to look into finding some data pertaining to this issue. What I'll definitely grant you is that the extrapolation isn't perfect.
That's certainly not the case at my bank. I live in Canada, so perhaps things are done differently here, but when I was issued my card they made me choose my PIN.
Whyyyyyyyyyyyyyy!!!!!
Potentially relevant XKCD: http://xkcd.com/1108/
So Benford's Law will apply even on a data set that has no numerical meaning in itself, transitively from the real sources of the numbers.
That's cool, mine is now 8093
But a lot of people will knowingly use an unsecure password for a site like linkedin, because they don't really care if its hacked. Using a secure password for bank accounts, email, etc. is critical, but I don't think it's realistic to ask people to have unique, secure passwords for their account on forums.49ersfans.com. That just isn't going to happen. It's interesting, but I'm skeptical his sources are even remotely a good proxy for bank account PIN numbers.
I stuck with my old bank who used a secure entry keypad so I could set my pin.
When I last did it the PIN was a secure keypad, and online banking required them to send a letter and then authenticate in branch.
Photo ID was required for both steps.
(I'd also venture that one of the reasons 2468 is so much more popular than 1357 is because of the nice symmetry that 2468 has)
I'm curious.
I still prefer the korean explanation, though
Does this happen to anyone else?
Incidentally, codes with repeated digits make it harder to guess your code based on fingerprints, as there are more possible combinations.
... uh... shoot. ^H^H^H^H^H^H^H CARRIER LOST
Pleased to say my pin occupies one of the darker regions of the heatmap :)
I guess they're right, mine is 1234