How Common Is Your PIN? (datagenetics.com) 114
phantomfive writes: We've seen password frequency lists, here is an analysis of PIN frequency with a nice heatmap towards the bottom. There is a line for numbers starting with 19*, which is the year of birth, a cluster around MM/DD for people's birthdays, and a hard diagonal line for the same digit repeated four times.
hey, if you type in your pw, it will show as stars (Score:5, Funny)
(Cthon98) hey, if you type in your pw, it will show as stars
(Cthon98) ********* see!
(AzureDiamond) hunter2
(AzureDiamond) doesnt look like stars to me
(Cthon98) (AzureDiamond) *******
(Cthon98) thats what I see
(AzureDiamond) oh, really?
(Cthon98) Absolutely
(AzureDiamond) you can go hunter2 my hunter2-ing hunter2
(AzureDiamond) haha, does that look funny to you?
(Cthon98) lol, yes. See, when YOU type hunter2, it shows to us as *******
(AzureDiamond) thats neat, I didnt know IRC did that
(Cthon98) yep, no matter how many times you type hunter2, it will show to us as *******
(AzureDiamond) awesome!
(AzureDiamond) wait, how do you know my pw?
(Cthon98) er, I just copy pasted YOUR ******'s and it appears to YOU as hunter2 cause its your pw
(AzureDiamond) oh, ok.
- http://bash.org/?244321 [bash.org]
Re:hey, if you type in your pw, it will show as st (Score:4, Insightful)
Still funny today.
Re: (Score:2)
I still have a hard time not laughing when I read the one about the robe and wizard hat in its entirety. I dunno? Maybe I really am a five year old.
Re: (Score:2)
Care to share with the rest of us? Got a link?
Re: (Score:2)
It's all over the place on the web, this one has a few of his chat logs [megalomaniac.com]
Re: (Score:2)
That's perfection. I think that's the whole collection. I'm gonna read 'em again. I can't help it. I'm a five year old.
*holds up his hand with his fingers spread* I'm this many years old!
I must be 'cause that's funny as hell.
Re: (Score:2)
Muros' link is perfect. Note, it's important to read all of it. As the robe and wizard hat make multiple appearances. Two, to be exact. However, the whole thing is fantastic. I'm gonna read it again.
Re: (Score:2)
I put a video game character named Hunter2 into one of my novels because of that piece.
1234 passwords (Score:3, Interesting)
Those 1234 passwords that people always talk about, those are just from temporary e-mail addresses that people create when they want something anonymous.
I've created plenty of accounts with incredibly easy passwords, because I only used them once and didn't care if the accounts would be hacked a minute after creation.
PIN numbers are not the same thing as passwords.
This is not an analysis of PIN frequency, it's an analysis of 4-digit numeric-only passwords.
Re:1234 passwords (Score:4, Interesting)
I'm thinking particularly of the pin# for Windows 10. For some things, I pick numbers that few will think of other than me. For others, like say my work account, I picked the 4-digit number of the building of my employer's headquarters, since there's a good chance that I'd have to share that w/ colleagues.
I don't exactly see the point of trying to create a complicated PIN, since there are just 10,000 combinations. So might as well pick something that's easily remembered.
Ha... (Score:4, Funny)
My psycho/retard ex would *always* uses "0852" for her PIN. Why? Sheer fucking laziness.
Re: (Score:2)
You say that now.... but.... actual conversation that happened (names have been changed to protect the terrible):
(driving down the road with a friend I had recently started hanging out with)
me: "I know a family lives down that street, fucking crazy as fuck. Friend of mine dated their daughter, it was terrible, the day I picked him up and we loaded his shit into my car, she was telling him she was 'pregnant' again"
her: "Lol my Brother had a kid with a crazy girl on that steet, Jodie Simpson"
And we are not in
Not even PIN data (Score:4, Informative)
From TFA
Obviously, I don’t have access to a credit card PIN number database. Instead I’m going to use a proxy. I’m going to use data condensed from released/exposed/discovered password tables and security breaches.
By combining the exposed password databases I’ve encountered, and filtering the results to just those rows that are exactly four digits long [0-9] the output is a database of all the four digit character combinations that people have used as their account passwords.
Re: (Score:2)
I would guess that it's a reasonable proxy for PINs that people get to choose themselves, such as those for SIM cards and phone unlock codes. Where I live, you don't get to choose the PIN for your debit card.
As for my phone: it has an encryption password, an unlock code, and a SIM PIN, in order of decreasing complexity, related to the potential for damage if someone guesses it right and to the number of tries before the system locks/wipes itself.
Re: (Score:3)
I would guess that it's a reasonable proxy for PINs that people get to choose themselves
I don't think so. I often use something like "1234" for some stupid throwaway account on a website that shouldn't even have accounts in the first place. But I use something pseudo-random (meaningful to me, but random to anyone else) for anything important, like a bank card.
Re: (Score:1)
Exactly, I wonder if there's any significant difference between the PIN and passwords people use for different types of services.
Personally I use three types of passwords, for throwaway accounts that I gave no personal info/payment info, like newspaper sites, xda, etc, I just use "password" as the password, adding a "!" and or "0" as needed.
For sites that I sort of want to hold on to the account but has no personal/payment info (/. for example), I use my old phone number for it.
I only actually attempt to us
Re: (Score:3)
Re: (Score:2)
> TFA also explains why the author believes the dataset is relevant for ATM PINs and similar.
Believing is most certainly not good enough. It's just an excuse to make his finding look more interesting than it is, which is: hacked password lists contain many simple passwords, nobody really knows what for.
At least my pin 8068 is safe (Score:5, Funny)
Re: (Score:3)
Which is monumentally STUPID! That leads to people writing it down just so they can remember it. I can see my idiot brother even writing it on the card so he doesn't have to remember it!
Re:At least my pin 8068 is safe (Score:5, Interesting)
Which is monumentally STUPID! That leads to people writing it down just so they can remember it. I can see my idiot brother even writing it on the card so he doesn't have to remember it!
People get all panicked about "writing down their passwords." I have never seen a case where a hacker was able to reach through the internet and shoulder surf that piece of paper. Offline analog storage has a much better security profile than the average bureaucrat's Excel spreadsheet full of passwords.
Sure, local attacks on the paper are possible, but extremely rare when compared to online attacks. Paper records have a much lower risk profile.
Re: At least my pin 8068 is safe (Score:5, Funny)
I have a Post-It stuck to the bottom of my keyboard with the word "pa$$word1" written on it, and have for years. I like to imagine that one day someone will try logging in to my account with that, thinking to themselves "wow, the sysadmin has a terrible password" just before it doesn't work.
It's the little things that get you through the day...
Re: At least my pin 8068 is safe (Score:5, Insightful)
You should find a way to use it as the duress password so that, if used, it sets off a loud klaxon alarm complete with the brilliant strobing lights. It would be awesome.
Re: (Score:1)
Re: (Score:2)
Okay, that made me laugh. That's a pretty good one.
I once found a password stickied to the monitor of a dean of a major state university. The thing is, the password was the dean's initials and year of birth, so I'm not really sure why he needed it to be stickied there. Possibly it was for the rest of the staff to get in and do things for him when necessary, but it still made me roll my eyes.
Re: (Score:2, Interesting)
I've never seen anyone needing a cheat-sheet to enter their PIN around here. So, it appears that the French population at large is able to remember a 4-digit number.
I'm sorry to hear that the average American is unable to do that.
By the way, the way it's done, they give you your credit card at the counter or in the mail, and send you your PIN in a separate mail, your banker never knows the PIN either. The mail with the PIN contain safety instructions: memorize it, keep it confidential, never store it along
Re: (Score:1)
Providing PINs (which is a 4-digit number) look a very welcome idea to me! * it's something like already occurs here in Brazil, with SIM PINs and bank ATM machines ^^
Re: (Score:2)
The main thing, IMO, is that the PIN is permanent. My ATM PIN was bank-selected, and though I can change it, I've never had any reason to do so. The numbers aren't connected to me, but I remember them just because I've always had them.
Re: (Score:2)
"I set my ATM card's number to "0001" because I'm number one!"
Let me introduce you to this thing call 0-base numbering. Because with *my* PIN of "0000", I'm #1 and you are a poor excuse for a #2
Re: (Score:2)
Super old blog (Score:5, Informative)
I thought this blog posting on PIN numbers looked familiar - then I looked at the publish date. September 3rd, 2012.
Um, guys?
Re: (Score:2)
This is /. so that's new and exciting information. Just be happy it was only almost 4 years ago.
This is why I use... (Score:4, Funny)
the last for digits of Pi for my PIN.
Re: This is why I use... (Score:1)
Plot twist...they are 12 3 4.
Re: (Score:2)
Re: (Score:1)
Also, don't you mean Jesus?
Technically, Jesus and God are one in the same. John 1 and Collossians 1 both talk about Jesus as the Creator of all things. He just didn't have the name Jesus until approximately 1AD when He came to dwell among us in the flesh.
Re: (Score:2)
I think that's the trinity folk and not all Christians subscribe to that, as far as I know. There's God the Father, God the Sun, and God the Holy Ghost. They are one and the same divinity, the holy trinity, but different manifestations of that self.
At least that's how I understand it. I am not actually a Christian but I know some. I even spent some time studying with the Jehovah's Witnesses and, at one point, spent a goodly amount of time with a young lady who was a Mormon. For the record, no we did not hav
Re: (Score:3)
There's God the Father, God the Sun, and God the Holy Ghost
So, it's basically, God, Ra [wikipedia.org], and God again? :-P
Re: (Score:2)
There's God the Father, God the Sun, and God the Holy Ghost
So, it's basically, God, Ra [wikipedia.org], and God again? :-P
I dunno if he made a typo but Jesus is actually the Sun and may as well be Ra.
Re: (Score:1)
maybe 98% of "christians" don't know the bible from a hole in the ground. at least that is how it seems from the fruit that they bear. the majority of what people call "christians" (catholics) also worship graven images and the mother of jesus and believe that you need to confess your sins to a priest when jesus did away with the whole jewish mediator thing in the first place.
the whole point of the bible is that you can go and read it for yourself and find god for yourself.. you don't need anyone else, who
Re: (Score:2)
Quick, someone make a website (Score:2)
Re: (Score:2)
Thankfully most people's account number is more random than their PIN.
Re: Somebody send this to the FBI,... (Score:1)
Imagine if they finally got Apple's help, and the PIN was 123456.
Always nice to see this again... (Score:2)
I guess it has been over six months since it was last posted on /. but a dupe none the less...
So why does the FBI want Apple to crack the iPhone (Score:1)
We all know the real reason...
Re: (Score:2)
If I recall correctly, the FBI wants Apple to disable the feature that disables or formats the device after too many incorrect attempts. Just because it is possible to crack 1 in 5 accounts after a handful of attempts doesn't mean that you will be able to crack a particular account in a handful of attempts (particularly if that person is paranoid).
Weird (Score:1)
Am I the only one who uses a random number generator to pick their pin numbers?
The banks I've dealt with also don't allow numbers like 1111 or 1234.
Re:Weird (Score:4, Interesting)
Back in the eighties, I was opening a bank account and the guy told me to pick a PIN. I pulled out my trusty Casio programmer's calculator, hit the random button 4 times, and wrote down the last digit of each.
So, no. You're not alone.
Re: (Score:2)
I did something like that to get a random PIN, and the bank system rejected it because I had repeated the same digit twice in a row.
Re: (Score:1)
stupid password rules... There's tons if it everywhere!
Re: (Score:2)
Sadly, you probably ARE the only one.
Clarification (Score:2)
and a hard diagonal line for the same digit repeated four times.
No - or at least not entirely. The hard diagonal line represents the same pair of digits repeated - 1010, 2424, 8585.
There are brighter spots on that diagonal line for each of the "same digit" combinations.
The price of a cheese.... (Score:2)
Re: (Score:2)
That's handy, until your your password changes with inflation.
Re: (Score:1)
Re: (Score:2)
I've more or less missed Futurama, let alone any references. I never got past "It's not the Simpsons." (Speaking of, nice handle, by the way.)
Interesting (Score:5, Interesting)
Re: (Score:2)
Chantilly lace and a pretty face?
Err... Yes, yes I am old. Whatever gave you that idea? I know what you like... Fortunately, Ms. KGIII is still awake and my (bad) signing and attempts to sit-wiggle/sit-dance aren't awakening her.
Is the least-password list outdated yet? (Score:1)
I'm just wondering whether those "bottom 100" are still at the bottom.
On another topic, how many people use their /. ID number as their PIN? Go ahead, raise your hands, don't be shy.
No respect for Tommy Tutone (Score:3)
Re: (Score:2, Informative)
"The fouth most popular seven digit password is 8675309"
Bank security compromised? (Score:2)
El Reg a few years back had a story that in the nineties, one of the big four banks in the UK had its security team compromised. New cards had a PIN set from only one of three choices. That meant that anyone intercepting a card who knew the three could go haywire with the account. The customer wouldn't know and the bank couldn't explain it.
Could have been cock and bull, but it's a possible small source of non-randomness.
42069? What is it? (Score:2)
FTA: "For five digit passwords, [...] All the usual suspects occur, but a new addition is the puerile addition in position #20 of the concatenation of 420 and 69."
Am I competely sutpid, or is there some cultural reference here, which I don't get? Why "42069"? Why is it puerile?
Re:42069? What is it? (Score:4, Insightful)
420 = weed.
69 is, well, 69.
You may continue to speculate...
Re: (Score:2)
Thanks. Yes, 69 was obvious, but not 420.
Re: (Score:1)
Safe! (Score:4, Funny)
Looks like it's 1234 (Score:5, Funny)
factor in the importance of data being protected (Score:3)
I would be interested in seeing the results of an investigation into a similar study that also factors in the importance of what is *behind* the password.
I don't think I'm the only one who puts more effort into choosing a 'good' password for things that are of value. I choose really quite poor passwords for things I really don't care about - eg have no sensitive information behind the login. For things like cash point cards, and other things in front of my actual money, I attempt to use much better passwords.
I think there are many things of little or no value, while just a few of high value. I guess this might skew the numbers somewhat. It's probably quite difficult to factor in this aspect, but it makes me question the conclusions.
Security (Score:1)
The funny thing is that my desk phone at work requires a more secure password for f***ing voicemail than my bank account does. The work one needs to be changed every few months, and you can't re-use your previous passwords. My bank would be happy to accept 1-1-1-1 for perpetuity.
In Autstria (Score:1)
Re: Old news (Score:2)
You are worthy of the nerd card. Very few others are. I bet that feels really good. You're special, for sure.