USENIX Security2022Top-tier venue
"The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits
Collins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant, Elena Korkes, Blase Ur, Adam J. Aviv
Abstract
With the goal of improving security, companies like Apple have moved from requiring 4-digit PINs to 6-digit PINs in contexts like smartphone unlocking. Users with a 4-digit PIN thus must "upgrade" to a 6-digit PIN for the same device or account. In an online user study (n = 1 010), we explore the security of such upgrades. Participants used their own smartphone to first select a 4-digit PIN. They were then directed to select a 6-digit PIN with one of five randomly assigned justifications. In an online attack that guesses a small number of common PINs (10-30), we observe that 6-digit PINs are, at best, marginally more secure than 4-digit PINs. To understand the relationship between 4-and 6-digit PINs, we then model targeted attacks for PIN upgrades. We find that attackers who know a user's previous 4-digit PIN perform significantly better than those who do not at guessing their 6-digit PIN in only a few guesses using basic heuristics (e.g., appending digits to the 4-digit PIN). Participants who selected a 6-digit PIN when given a "device upgrade" justification selected 6-digit PINs that were the easiest to guess in a targeted attack, with the attacker successfully guessing over 25% of the PINs in just 10 attempts, and more than 30% in 30 attempts. Our results indicate that forcing users to upgrade to 6-digit PINs offers limited security improvements despite adding usability burdens. System designers should thus carefully consider this tradeoff before requiring upgrades.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 792e06fa-394a-4e1d-a245-73ead9a7b469Cited by top-tier papers3
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 5 citations
- Unmasking the Security and Usability of Password MaskingYuqi Hu, Suood Alroomi, Sena Sahin, Frank LiCCS 2024 · 1 citation
- Why Users (Don't) Use Password Managers at a Large Educational InstitutionPeter Mayer, Collins W. Munyendo, Michelle L. Mazurek, Adam J. AvivUSENIX Security 2022
Builds on4
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
- This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINsPhilipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth et al.S&P 2020 · 65 citations
- Practical Recommendations for Stronger, More Usable Passwords Combining Minimum-strength, Minimum-length, and Blocklist RequirementsJoshua Tan, Lujo Bauer, Nicolas Christin, Lorrie Faith CranorCCS 2020 · 49 citations
Related papers
- Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design PatternsMaximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri et al.USENIX Security 2021 · 48 citations
- User Perceptions and Experiences with Smart Home UpdatesJulie M. Haney, Susanne M. FurmanS&P 2023
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 1 citation
- ArmSpy: Video-assisted PIN Inference Leveraging Keystroke-induced Arm Posture ChangesYuefeng Chen, Yicong Du, Chunlong Xu, Yanghai Yu et al.INFOCOM 2022 · 4 citations
- WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal AnalysisEdwin Yang, Qiuye He, Song FangCCS 2022 · 14 citations
