"The Same PIN, Just Longer": On the (In)Security of Upgrading PINs from 4 to 6 Digits
Collins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant, Elena Korkes, Blase Ur, Adam J. Aviv
摘要
With the goal of improving security, companies like Apple have moved from requiring 4-digit PINs to 6-digit PINs in contexts like smartphone unlocking. Users with a 4-digit PIN thus must "upgrade" to a 6-digit PIN for the same device or account. In an online user study (n = 1 010), we explore the security of such upgrades. Participants used their own smartphone to first select a 4-digit PIN. They were then directed to select a 6-digit PIN with one of five randomly assigned justifications. In an online attack that guesses a small number of common PINs (10-30), we observe that 6-digit PINs are, at best, marginally more secure than 4-digit PINs. To understand the relationship between 4-and 6-digit PINs, we then model targeted attacks for PIN upgrades. We find that attackers who know a user's previous 4-digit PIN perform significantly better than those who do not at guessing their 6-digit PIN in only a few guesses using basic heuristics (e.g., appending digits to the 4-digit PIN). Participants who selected a 6-digit PIN when given a "device upgrade" justification selected 6-digit PINs that were the easiest to guess in a targeted attack, with the attacker successfully guessing over 25% of the PINs in just 10 attempts, and more than 30% in 30 attempts. Our results indicate that forcing users to upgrade to 6-digit PINs offers limited security improvements despite adding usability burdens. System designers should thus carefully consider this tradeoff before requiring upgrades.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 被引用 5 次
- Unmasking the Security and Usability of Password MaskingYuqi Hu, Suood Alroomi, Sena Sahin, Frank LiCCS 2024 · 被引用 1 次
- Why Users (Don't) Use Password Managers at a Large Educational InstitutionPeter Mayer, Collins W. Munyendo, Michelle L. Mazurek, Adam J. AvivUSENIX Security 2022
它引用的顶会 Paper4
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 被引用 100 次
- This PIN Can Be Easily Guessed: Analyzing the Security of Smartphone Unlock PINsPhilipp Markert, Daniel V. Bailey, Maximilian Golla, Markus Dürmuth 等S&P 2020 · 被引用 65 次
- Practical Recommendations for Stronger, More Usable Passwords Combining Minimum-strength, Minimum-length, and Blocklist RequirementsJoshua Tan, Lujo Bauer, Nicolas Christin, Lorrie Faith CranorCCS 2020 · 被引用 49 次
相关 Paper
- Driving 2FA Adoption at Scale: Optimizing Two-Factor Authentication Notification Design PatternsMaximilian Golla, Grant Ho, Marika Lohmus, Monica Pulluri 等USENIX Security 2021 · 被引用 48 次
- User Perceptions and Experiences with Smart Home UpdatesJulie M. Haney, Susanne M. FurmanS&P 2023
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 被引用 1 次
- ArmSpy: Video-assisted PIN Inference Leveraging Keystroke-induced Arm Posture ChangesYuefeng Chen, Yicong Du, Chunlong Xu, Yanghai Yu 等INFOCOM 2022 · 被引用 4 次
- WINK: Wireless Inference of Numerical Keystrokes via Zero-Training Spatiotemporal AnalysisEdwin Yang, Qiuye He, Song FangCCS 2022 · 被引用 14 次
