2012
DOI: 10.1007/978-3-642-32946-3_3
|View full text |Cite
|
Sign up to set email alerts
|

A Birthday Present Every Eleven Wallets? The Security of Customer-Chosen Banking PINs

Abstract: Abstract. We provide the first published estimates of the difficulty of guessing a human-chosen 4-digit PIN. We begin with two large sets of 4-digit sequences chosen outside banking for online passwords and smartphone unlock-codes. We use a regression model to identify a small number of dominant factors influencing user choice. Using this model and a survey of over 1,100 banking customers, we estimate the distribution of banking PINs as well as the frequency of security-relevant behaviour such as sharing and r… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1
1

Citation Types

4
124
1

Year Published

2012
2012
2020
2020

Publication Types

Select...
5
3
1

Relationship

0
9

Authors

Journals

citations
Cited by 121 publications
(129 citation statements)
references
References 13 publications
4
124
1
Order By: Relevance
“…However, we believe that the attack could still be practical when selecting from a limited set of PINs since users do not select their PINs randomly [19]. It has been reported that around 27% of all possible 4-digit PINs belong to a set of 20 PINs, 4 including straightforward ones like "1111", "1234", or "2000".…”
Section: Identification Of Pin Digitsmentioning
confidence: 99%
See 1 more Smart Citation
“…However, we believe that the attack could still be practical when selecting from a limited set of PINs since users do not select their PINs randomly [19]. It has been reported that around 27% of all possible 4-digit PINs belong to a set of 20 PINs, 4 including straightforward ones like "1111", "1234", or "2000".…”
Section: Identification Of Pin Digitsmentioning
confidence: 99%
“…As an example, in addition to user name and passwords, HSBC authenticates their customers through TouchID 17 and voice ID. 18 Another example is Smile to Pay facial recognition app 19 where deep learning is applied to overcome the difficulty of face authentication when the face photograph is not in the normal form. Recently Yahoo has also introduced its ear-based smartphone identification system.…”
Section: Biometric Sensorsmentioning
confidence: 99%
“…We present a comparison of the security properties against guessing adversaries of several ZeTA parameters with passwords and PINs in Table 1: a listing of the bit strength of alphanumeric passwords in practice, as reported by Bonneau [65], and 4 digit PINs both in theory and in practice, as reported by Bonneau et al [66], as well as several theoretical values for ZeTA as presented in Table 2.…”
Section: Comparison Of Example Parametersmentioning
confidence: 99%
“…Sharing of PIN among users or family members also add more security risks. Studies [12][13][14] have reported that most users use their date of births as PINs. Such tendency leads to a critical security vulnerability as date of birth can be known from different sources, such as a co-worker, family member, relative, various record management systems etc.…”
Section: Personal Identification Numbers (Pins)mentioning
confidence: 99%