Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

February 22nd, 2012, 12:10 GMT · By Eduard Kovacs

Experts: Many 4-Digit PINs Not Hard to Guess

SHARE:

Adjust text size:


Many 4-digit PINs are not hard to guess
Enlarge picture
Security researchers from University of Cambridge performed a study to find out how vulnerable 4-digit banking PINs are to “guessing attacks” and the results revealed that a significant percentage of individuals use their own birth dates to form the code that should protect their financial assets.

While most people use random PINs, or at least ones that are hard to figure out, there are still enough that use some weak ones, such as “1234” or even their own birth dates, raising the chances for an opportunistic thief to succeed in guessing them.

The experts surveyed 1,300 Internet users to determine precisely the “strength” of their PINs. Of course, they weren’t requested to provide the actual digits, instead they were asked certain questions that could allow for a categorization.

The figures showed that around 25% of the respondents use the random sequence assigned to them by the bank when they received the credit card. More than one third use something related to phone numbers, or other IDs they already know, but statistically speaking these practices don’t expose card holders to the dangers of guessing attacks.

It turns out that 63.7% utilize a pseudorandom PIN and 5% rely on a numeric pattern such as “2323”. Around 9% use a password choosing technique that’s popular among many users, the one where they remember the position of the keys on the keypad, instead of the actual digits.

While this gives an attacker a possible rate of success lower than 2%, the other 23% of subjects tip the balance in the attacker’s favor. This last 23% chose a PIN that represents a date, around 30% using their own birth dates.

Since 99% of respondents admitted that their birth date is listed somewhere in their wallet, the attacker’s rate of success jumps to 9%.

Researchers suggest that banks should blacklist the top 100 PINs, maneuver which would decrease the guessing rate down to 0.2%. However, the use of birth dates still represents a major threat to the integrity of one’s bank account in case he/she physically loses the card.
FILED UNDER:
PIN
report
bank

TELL US WHAT YOU THINK:

1,045 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Groupon and LivingSocial Scam Sites Found

23-Year-Old Admits to Stealing Information of 8 Million Users

CULT Order Confirmation Steals BoA, Steam and Facebook Accounts

Authentic-Looking Wells Fargo Phishing Emails Spotted

Google Fixes One Wallet Vulnerability, Brute-Force Attacks Still Possible

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM