"The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits (2024)

Authors:

Collins W. Munyendo, The George Washington University; Philipp Markert, Ruhr University Bochum; Alexandra Nisenoff, University of Chicago; Miles Grant and Elena Korkes, The George Washington University; Blase Ur, University of Chicago; Adam J. Aviv, The George Washington University

Abstract:

With the goal of improving security, companies like Apple have moved from requiring 4-digit PINs to 6-digit PINs in contexts like smartphone unlocking. Users with a 4-digit PIN thus must "upgrade" to a 6-digit PIN for the same device or account. In an online user study (n=1010), we explore the security of such upgrades. Participants used their own smartphone to first select a 4-digit PIN. They were then directed to select a 6-digit PIN with one of five randomly assigned justifications. In an online attack that guesses a small number of common PINs (10–30), we observe that 6-digit PINs are, at best, marginally more secure than 4-digit PINs. To understand the relationship between 4- and 6-digit PINs, we then model targeted attacks for PIN upgrades. We find that attackers who know a user's previous 4-digit PIN perform significantly better than those who do not at guessing their 6-digit PIN in only a few guesses using basic heuristics (e.g., appending digits to the 4-digit PIN). Participants who selected a 6-digit PIN when given a "device upgrade" justification selected 6-digit PINs that were the easiest to guess in a targeted attack, with the attacker successfully guessing over 25% of the PINs in just 10 attempts, and more than 30% in 30 attempts. Our results indicate that forcing users to upgrade to 6-digit PINs offers limited security improvements despite adding usability burdens. System designers should thus carefully consider this tradeoff before requiring upgrades.

Open Access Media

USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.

BibTeX

@inproceedings {279940,
author = {Collins W. Munyendo and Philipp Markert and Alexandra Nisenoff and Miles Grant and Elena Korkes and Blase Ur and Adam J. Aviv},
title = {"The Same {PIN}, Just Longer": On the ({In)Security} of Upgrading {PINs} from 4 to 6 Digits},
booktitle = {31st USENIX Security Symposium (USENIX Security 22)},
year = {2022},
isbn = {978-1-939133-31-1},
address = {Boston, MA},
pages = {4023--4040},
url = {https://www.usenix.org/conference/usenixsecurity22/presentation/munyendo},
publisher = {USENIX Association},
month = aug
}

Presentation Video

"The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits (2024)
Top Articles
The Benefits of 'In The Money Calls'
What are the most useful tools for smart contract development?
Evil Dead Movies In Order & Timeline
Maxtrack Live
9.4: Resonance Lewis Structures
Unity Stuck Reload Script Assemblies
Wisconsin Women's Volleyball Team Leaked Pictures
Unitedhealthcare Hwp
Math Playground Protractor
craigslist: south coast jobs, apartments, for sale, services, community, and events
Here's how eating according to your blood type could help you keep healthy
Soap2Day Autoplay
Lesson 1 Homework 5.5 Answer Key
B67 Bus Time
Connexus Outage Map
Think Up Elar Level 5 Answer Key Pdf
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
Theresa Alone Gofundme
Brett Cooper Wikifeet
Cyndaquil Gen 4 Learnset
Milanka Kudel Telegram
Galaxy Fold 4 im Test: Kauftipp trotz Nachfolger?
Craigslist Pennsylvania Poconos
Mandy Rose - WWE News, Rumors, & Updates
Amelia Chase Bank Murder
Impact-Messung für bessere Ergebnisse « impact investing magazin
Firefly Festival Logan Iowa
Stockton (California) – Travel guide at Wikivoyage
*!Good Night (2024) 𝙵ull𝙼ovie Downl𝚘ad Fr𝚎e 1080𝚙, 720𝚙, 480𝚙 H𝙳 HI𝙽DI Dub𝚋ed Fil𝙼yz𝚒lla Isaidub
Stouffville Tribune (Stouffville, ON), March 27, 1947, p. 1
APUSH Unit 6 Practice DBQ Prompt Answers & Feedback | AP US History Class Notes | Fiveable
Willys Pickup For Sale Craigslist
Where Can I Cash A Huntington National Bank Check
Boondock Eddie's Menu
Wbli Playlist
Ducky Mcshweeney's Reviews
Uhaul Park Merced
Waffle House Gift Card Cvs
Claim loopt uit op pr-drama voor Hohenzollern
Merkantilismus – Staatslexikon
Anya Banerjee Feet
D-Day: Learn about the D-Day Invasion
Dee Dee Blanchard Crime Scene Photos
Nba Props Covers
Weather Underground Cedar Rapids
Tlc Africa Deaths 2021
Aznchikz
Erespassrider Ual
Bellelement.com Review: Real Store or A Scam? Read This
Anonib New
Myapps Tesla Ultipro Sign In
Latest Posts
Article information

Author: Ms. Lucile Johns

Last Updated:

Views: 5682

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Ms. Lucile Johns

Birthday: 1999-11-16

Address: Suite 237 56046 Walsh Coves, West Enid, VT 46557

Phone: +59115435987187

Job: Education Supervisor

Hobby: Genealogy, Stone skipping, Skydiving, Nordic skating, Couponing, Coloring, Gardening

Introduction: My name is Ms. Lucile Johns, I am a successful, friendly, friendly, homely, adventurous, handsome, delightful person who loves writing and wants to share my knowledge and understanding with you.