PIN number analysis
datagenetics.com
datagenetics.com
Eventually they got a Polish officer through Interpol to help. On his first day on the case he asked - why are you looking for a guy called "Drivers License"? Cops had simply stopped ordinary traffic violations, and wrote down the name from the international license that was where you usually saw the name on national licenses.
http://www.telegraph.co.uk/news/worldnews/europe/ireland/473...
The apparent number of people who request tattoos in foreign scripts without bothering to check their translation is also surprising.
Noplates
Missing
XXX
NV
At some point I'd really like to see six to eight digit PINs, though...
For that reason I recommend having a 4 digit pin.
Singapore it's mandatory for a 6 digit pin so have no idea if a 4 digit pin will work, anybody been there?
This has however resulted in me forgetting it several times, once I almost got stranded at a station and was lucky to have enough cash to buy a ticket.
I won't tell you what I've done to mitigate against being stranded at random places due to forgetting my PIN but it's not secure. Therefore, I have my reservations about forcing people to remember random numbers.
You modulo that with the pin your bank gives you.
You write the result on the back of the card.
If you forget the pin you can work backwards to the bank issued pin?
Ok I get it now. Sounds crazy.
The only thing is that if you're going to pick the pin you might as well use the secret one.
I think it's pretty obvious that's a bad idea, given all the huge posters also hanging everywhere in the bank, sternly warning people not to pick a dumb PIN. I'm sure that'll work.
4-digit PINs are easy to remember. It's real simple to always come up with some sort of mnemonic. There is no need whatsoever to pick your own.
This way your pin can be verified without needing to call back to the central bank core - the ATM cloud can just move straight on to transactions.
It may save a lot of cash it may be a myth - anyone got details?
When dealing with 'foreign' ATMs (whether domestic or foreign), my pin is sometimes truncated -- anywhere from 8 to 4 digits.
I've also come across ATMs where it won't work.
Bank of America advises you to change it to a 4-digit PIN before traveling internationally (and actually have a paper handout they'll give at the teller window saying such if you tell them you're traveling internationally.
It would be, were it not for the fact that the pin is randomly assigned. I've had a card issued with "2468" as the pin.
"I'd really like to see six to eight digit PINs, though..."
Whilst the default length is 4 digits, you can change it to something longer if you choose.
Not really. You'll break international standards if you do. I used an 8-digit PIN for many years, but it is 100% impossible to use anywhere I tried in Europe. You will be completely without any way to pay other than cash. No machine will allow more than 4 digits in my experience.
"Given that users have a free choice for their password, if users select a four digit password to their online account, it’s not a stretch to use this as a proxy for four digit PIN codes."
Though there probably wouldn't be drastically different phenomenon, I think the actual PIN distribution would be noticeably different. Particularly 1234. It may still be the top PIN, but I don't think it would have the same dominance. People choose trymynewwebservice.ly passwords a lot more callously than their bank password. I have to believe on average people put a little more effort into disguising it.
A lot sites (correctly) prevent people from using very short or simple passwords, including four digit numbers. I'm curious what sites his database comes from.
http://www.cl.cam.ac.uk/~jcb82/doc/BPA12-FC-banking_pin_secu...
(RockYou discussed here:
http://en.wikipedia.org/wiki/RockYou#Controversy
)
The patterns displayed by the codes in the paper are similar to the blog.
The blog is less clear.
upvoted.
Now go explode!!! ;)
Banks don't let you choose 4 consecutive numbers or 4 of the same number making his first conclusion completely invalid. A lot of banks assign pin numbers now making the rest of his conclusions invalid.
I get wanting to analyze PINs, it's interesting, but pretending any old data that looks similar will work is misleading, disingenuous, and half ass.
How anyone can 'analyse' PIN numbers with unrelated data is beyond me.
I'm not sure where YOU live, but there's a WHOLE would out there. In New Zealand, you can choose anything you like on the number terminal they give you. They try to educate you on a good PIN, but it's ultimately up to you.
Unlike 80s there are many counter measures to defend against brute force attacks. No one is going to sit down and guess/brute-force your PIN. Probably not even your other passwords.
It's either going to be fully exposed or not at all, so how random or complicated it is doesn't protect you as much as most people make it sound like
When we talk about secure passwords (Not PINs for the moment, I'll get back to those in a moment), we're mostly worrying about how easy it is to recover someone's password from a database once a system has been compromised. However these days, we don't store the password, we store a hash of the password. To recover the password, the hacker has to successfully 'un-hash' the hashed password, which is done by applying a brute force cryptographic algorithm. The computer detects hits by examining the frequency of letters in the output, knowing that letters don't have an even distribution in passwords (or any other text). Choosing a random password is actually useful in this case, because even if the computer correctly finds the right key for de-hashing, it doesn't recognize your password as 'de-hashed' and just passes right over it.
So, for passwords, it is fairly clear that a random password is going to be safer than a word / name or other commonly used password constructs, in its ability to resist extraction from a compromised database.
Can we make the same claim for PIN codes? It would be harder - you only have 4 digits to work with, which makes it much harder to determine if digits are distributed in a pattern or randomly. You would expect a lot of false positives and false negatives. Nevertheless, distributions in real life numbers do exist - http://en.wikipedia.org/wiki/Benford%27s_law is an obvious example, which leads us to the non-obvious conclusion that making PIN codes longer probably leads to a lower level of security. On the other hand, the scenario in which this is a problem is when a database is compromised, and bank databases are amongst the most hardened targets on the planet, so the increase in risk is probably negligeable.
That's assuming someone is trying to brute force a system 'from the outside', without having access to the list of password hashes for the system. In reality such attempts rarely if ever happen and they are easily defeated by using rate limiting and other techniques.
The problem arises when the attacker has a list of hashed password and is running checks against that list. In those cases, the fact that a password is random won't do any good as the program knows which password hash it is trying to crack.
Furthermore, there is no "de-hashing". Password cracking software is actually hashing commonly used words, letter combinations and/or even random characters, and comparing the output of the hashing operation with the password hash that it is trying to crack. Cryptographic hash functions are unidirectional and cannot be reversed, you can only try to hash raw data and hope to produce a hash which matches the hash you're trying to "reverse".
As for your idea that hash functions can't be reversed, not so much. They can't be easily reversed, but that's not the same thing.
In reality, brute forcing is pretty much the only viable attack left now that salting is commonplace. Still, if you have managed to get your hands on the password table, you can brute force without having to worry about rate limiting etc.
Now, if my card got stolen and I hadn't realized it till a few hours later, I'd be glad my pin wasn't 1234. Also, even if I get the money back from the bank, I won't get the time hassling the bank/insurance or the stress back.
In my company (credit card company) and in most competitors the PIN is a random number generated when the smart cards are being written. Sequential, repetitive, years, et al are all discharged. PINs can be used as a password for transactions. Because my company focus on low-incoming families, this is actually great, they don't need a phone or website to create/change passwords. The problem here is delivering the password securely.
There are banks that do not use PINs at all, the password is stored in their database. This is usually better because if you loose a password you can reset it. This isn't possible using PINs. They are hardwired in the smart card and cannot be changed.
PINs cannot be changed or chosen, if you can change, it's not a PIN, it's an awfully insecure 4 digit password.
Based on properly working random number generator, I would say that 1234 is exactly as common PIN as any other PIN number.
http://www.cbsnews.com/8301-205_162-57539366/the-25-most-com...
And from the longer digit-sequences 292513 (#12) and 38317 (#15) and 42059 (#20). I didn't google those last two, maybe they're common US ZIP codes?