This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINs
Philipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth, Adam J. Aviv
Abstract
In this paper, we provide the first comprehensive study of user-chosen 4- and 6-digit PINs (n = 1220) collected on smartphones with participants being explicitly primed for device unlocking. We find that against a throttled attacker (with 10, 30, or 100 guesses, matching the smartphone unlock setting), using 6-digit PINs instead of 4-digit PINs provides little to no increase in security, and surprisingly may even decrease security. We also study the effects of blacklists, where a set of "easy to guess" PINs is disallowed during selection. Two such blacklists are in use today by iOS, for 4-digits (274 PINs) as well as 6-digits (2910 PINs). We extracted both blacklists compared them with four other blacklists, including a small 4-digit (27 PINs), a large 4-digit (2740 PINs), and two placebo blacklists for 4- and 6-digit PINs that always excluded the first-choice PIN. We find that relatively small blacklists in use today by iOS offer little or no benefit against a throttled guessing attack. Security gains are only observed when the blacklists are much larger, which in turn comes at the cost of increased user frustration. Our analysis suggests that a blacklist at about 10 % of the PIN space may provide the best balance between usability and security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 203c8f45-da74-4d40-805c-502b6bc7c779Cited by top-tier papers9
- Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design PatternsMaximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri et al.USENIX Security 2021 · 48 citations
- Evaluating the Security Posture of Real-World FIDO2 DeploymentsDhruv Kuchhal, Muhammad Saad, Adam Oest, Frank LiCCS 2023 · 13 citations
- GestureMeter: Design and Evaluation of a Gesture Password Strength MeterEunyong Cheon, Jun Ho Huh, Ian OakleyCHI 2023 · 5 citations
- An Empirical Study on Fingerprint API Misuse with Lifecycle Analysis in Real-world Android AppsXin Zhang, Xiaohan Zhang, Zhichen Liu, Bo Zhao et al.NDSS 2025
- "The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 DigitsCollins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant et al.USENIX Security 2022
Builds on1
Related papers
- Gesture Authentication for Smartphones: Evaluation of Gesture Password Selection PoliciesEunyong Cheon, Yonghwan Shin, Jun Ho Huh, Hyoungshick Kim et al.S&P 2020 · 17 citations
- WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal AnalysisEdwin Yang, Qiuye He, Song FangCCS 2022 · 14 citations
- SysPal: System-Guided Pattern Locks for AndroidGeumhwan Cho, Jun Ho Huh, Junsung Cho, Seongyeol Oh et al.S&P 2017 · 54 citations
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- On Smartphone Users' Difficulty with Understanding Implicit AuthenticationMasoud Mehrabi Koushki, Borke Obada-Obieh, Jun Ho Huh, Konstantin BeznosovCHI 2021 · 8 citations
