|
obermd wrote: I have yet to understand how PIN numbers are more secure than passwords.
It is most likely a numeric pin and not a password because manufacturing and maintaining a numeric keypad ATM machine is far more economical than producing one with a full fledged QWERTY keyboard. It almost always comes down to the costs.
|
|
|
|
|
obermd wrote:
I have yet to understand how PIN numbers are more secure than passwords. Face it, there are only 10,000 combinations, yet even an alphabetic, case insensitive, PIN would have 456,976 combinations. I would expect being able to brute force a pin number, regardless of length, would be easy for modern computers that can break 128-bit key based encryption systems in hours.
I wondered that too for a long while. If you dig into the various places where PINs are used, you will find that anywhere a PIN is used, there is strong protection behind it to back it up.
PINs generally have very strong limitations on how many times you can get them wrong (i.e. 3 times) -- because failure lockout reset can be controlled externally by more secure methods (2FA, MFA, big brother style behavior pattern matching, etc.)
Offline attacks toward a PIN tend not to work because the PIN is not the primary secret. So the use limitation of the PIN protects the use of the much stronger public/private key encryption which protects the actual data you wish to protect.
Credit/debit cards have those cryptography chips now -- those hold the public/private key encryption, locked into read-only memory in nanometer scale size, and the PIN protects the use of that strong encryption, any funny business using it -- and that strong encryption becomes invalid -- it's new card time.
|
|
|
|
|
OriginalGriff wrote: 1234
"That's amazing. I've got the same combination on my luggage."
"These people looked deep within my soul and assigned me a number based on the order in which I joined."
- Homer
|
|
|
|
|
"I've lost the bleeps. I've lost the creeps. And I've lost the sweeps."
|
|
|
|
|
"How many assholes have we got on this ship anyway?"
YO!
Software Zen: delete this;
|
|
|
|
|
"I am your father's brother's, nephew's, cousin's, former roomate."
"What does that make us?"
"Absolutely nothing."
|
|
|
|
|
I use the last 4 digits of old phone numbers I've had, like from my childhood.
I'm not likely to forget them, and good luck tying them to me.
Check out my IoT graphics library here:
https://honeythecodewitch.com/gfx
And my IoT UI/User Experience library here:
https://honeythecodewitch.com/uix
|
|
|
|
|
honey the codewitch wrote: good luck tying them to me.
My phone number (number*s*, now that I've joined the club and carry a phone) has had the same last 4 digits for my entire life...
If I used that as my PIN, anyone who knows my phone number would have a pretty good chance at guessing it.
|
|
|
|
|
You have the same phone number you did when you were a child?
Check out my IoT graphics library here:
https://honeythecodewitch.com/gfx
And my IoT UI/User Experience library here:
https://honeythecodewitch.com/uix
|
|
|
|
|
Cell phones have been around long enough, twentysomethings very well could.
Of course I'm old enough they've changed the numbering system since we banged rocks together when I was little .
Software Zen: delete this;
|
|
|
|
|
Cell phones were still a long way away when I was a child. The 72 in my username on CP is my birth year.
|
|
|
|
|
Actually, it wasn't that far away Our first cellular phone network was established in 1981, covering the Scandinavian countries (Wikipedia: NMT[^].
NMT ("1G") replaced older mobile phone systems, "OLT" in Norway, established in 1966. When NMT was introduced, OLT had approx. 30,000 subscriber in a population of 4 million - scaled to population size, that would correspond to 2.5 million subscribers in today's USA. So at the 1981 introduction of the cellular NMT technology, we were familiar with mobile phones here in Norway.
OLT was not "cellular": To make a call, you hooked up to your closest base station. You had to stay within range of that base for the duration of the call; an ongoing call couldn't automatically be switched to another base station. So OLT was less suited to fast moving vehicles. The low transmission frequency (somewhat higher than FM transmitters) meant that a single base station could cover a large area; it was a lesser problem than you might think. (But total network capacity was a bigger problem than you might think!)
The 1981 NMT system was fully automatic (OLT required operator assistance), and cellular, so you could move freely from one base station to another. The sound was analog, FM modulation.
Digital cellular phones (GSM standard, "2G") were not introduced until 1991 - but it really didn't make a big difference to us: We had extended use of cellular NMT mobile phones at the time, so to us, buying a new GSM phone was just another cellular. Another aspect easing GSM adoption in Norway (and other countries) is that we agreed upon one single standard. Roaming was included in the initial base standard, so phones would work in all European (and gradually all) countries, while USA let four incompatible standards compete to select the best through economic bloodshed. GSM didn't make a great impact until the battle left the original US warriors all laying severely wounded on the battleground
(We had that same story repeated with digital radio: While European and other countries started preparing for and implementing a fully digital DAB radio system, US authorities let a number of alternate standards stab each other to death. The last I have heard is that no digital FM replacement seems ready to take over in the US, not even today. (Correct me if I am wrong! Yes, I certainly know of HD Radio, but being available is different from taking over!)
Religious freedom is the freedom to say that two plus two make five.
|
|
|
|
|
Y'know...after initially glancing at the wall of text, I was tempted to go cynical and reply with "cool story, bro".
But after having actually read it, I must say, that was a rather informative history lesson. Thanks for that.
But, I still wouldn't have been carrying a cell phone under decades later.
|
|
|
|
|
The last 4 digits, yes. When I got a smartphone and needed a new number, I specifically asked if there was anything available that ended with WXYZ (replace with actually digits). I even had a choice between 2 different exchanges (the 3-digit part).
|
|
|
|
|
I do the same thing -- a landline number that hasn't existed in 30 years since my folks sold my childhood house.
Be wary of strong drink. It can make you shoot at tax collectors - and miss.
Lazarus Long, "Time Enough For Love" by Robert A. Heinlein
|
|
|
|
|
That's clever.
There are no solutions, only trade-offs. - Thomas Sowell
A day can really slip by when you're deliberately avoiding what you're supposed to do. - Calvin (Bill Watterson, Calvin & Hobbes)
|
|
|
|
|
Now someone needs to pin this post. We should probably do it in numbers.
I’ve given up trying to be calm. However, I am open to feeling slightly less agitated.
I’m begging you for the benefit of everyone, don’t be STUPID.
|
|
|
|
|
As having personally used a pin number I had to guess in order to use, I'd have to say "It's not how you used the pin number to "get in", it's how do you change it that really matters".
|
|
|
|
|
Whelp! Time to change all my pins to more secure ones! 9596 it is!
/s
|
|
|
|
|
I had no choice in the matter; I just got a letter saying that this is your PIN number.
|
|
|
|
|
That's normal in the UK as well, but every bank I know allows you to set it to your preferred one once you know the one they gave you. THat's probably for security - a PIN you remember has got to be better than one written down and kept in your wallet / purse.*
* Herself did that: her PIN was on a piece of paper wrapped round her debit card ...
"I have no idea what I did, but I'm taking full credit for it." - ThisOldTony
"Common sense is so rare these days, it should be classified as a super power" - Random T-shirt
AntiTwitter: @DalekDave is now a follower!
|
|
|
|
|
Oops, I guess using a particular year is not so unique anymore (and I'm guessing padding it with zeroes in 6 digit pins ain't either)
|
|
|
|
|
I'm smart, to many would use 5050, so 5150
|
|
|
|
|
Good, but! Back to real life. How many tries do you have, until ATM eats your credit/debet card? Here in Europe exactly 3 times. IDK how it's overseas, but I hope it's similarly limited, too. Soooo, unless PIN is explicitly linked to a card number, I think we are generally safe, aren't we? On the other hand, I checked, and my PIN is nowhere near the first hundred thousand (I didn't look further), so I can sleep like a baby one more night.
|
|
|
|
|
Wordle 1,094 6/6
⬜⬜⬜⬜⬜
⬜⬜🟨🟨⬜
🟩🟨🟨⬜⬜
🟩🟩🟩⬜🟨
🟩🟩🟩🟩⬜
🟩🟩🟩🟩🟩
|
|
|
|