• HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
Thursday, November 6, 2025
BIOENGINEER.ORG
No Result
View All Result
  • Login
  • HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
        • Lecturer
        • PhD Studentship
        • Postdoc
        • Research Assistant
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
  • HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
        • Lecturer
        • PhD Studentship
        • Postdoc
        • Research Assistant
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
No Result
View All Result
Bioengineer.org
No Result
View All Result
Home NEWS Science News

How secure are four and six-digit mobile phone PINs?

Bioengineer by Bioengineer
March 11, 2020
in Science News
Reading Time: 4 mins read
0
IMAGE
Share on FacebookShare on TwitterShare on LinkedinShare on RedditShare on Telegram

Apple and Android implement a number of measures to protect their users’ devices. An international team of IT security experts has investigated how useful they are.

IMAGE

Credit: RUB, Marquard


A German-American team of IT security researchers has investigated how users choose the PIN for their mobile phones and how they can be convinced to use a more secure number combination. They found that six-digit PINs actually provide little more security than four-digit ones. They also showed that the blacklist used by Apple to prevent particularly frequent PINs could be optimised and that it would make even greater sense to implement one on Android devices.

Philipp Markert, Daniel Bailey, and Professor Markus Dürmuth from the Horst Görtz Institute for IT Security at Ruhr-Universität Bochum conducted the study jointly with Dr. Maximilian Golla from the Max Planck Institute for Security and Privacy in Bochum and Professor Adam Aviv from the George Washington University in the USA. The researchers will present the results at the IEEE Symposium on Security and Privacy in San Francisco in May 2020. A preprint of the paper can be found online: https://arxiv.org/abs/2003.04868.

Extensive user study

In the study, the researchers had users on Apple and Android devices set either four or six-digit PINs and later analysed how easy they were to guess. In the process, they assumed that the attacker did not know the victim and did not care whose mobile phone is unlocked. Accordingly, the best attack strategy would be to try the most likely PINs first.

Some of the study participants were free to choose their PIN at random. Others could only choose PINs that were not included in a blacklist. If they tried to use one of the blacklisted PINs, they received a warning that this combination of digits was easy to guess.

In the experiment, the IT security experts used various blacklists, including the real one from Apple, which they obtained by having a computer test all possible PIN combinations on an iPhone. Moreover, they also created their own more or less comprehensive blacklists.

Six-digit PINs not more secure than four-digit ones

It emerged that six-digit PINs do not provide more security than four-digit ones. “Mathematically speaking, there is a huge difference, of course,” says Philipp Markert. A four-digit PIN can be used to create 10,000 different combinations, while a six-digit PIN can be used to create one million. “However, users prefer certain combinations; some PINs are used more frequently, for example, 123456 and 654321,” explains Philipp Markert. This means users do not take advantage of the full potential of the six-digit codes. “It seems that users currently do not understand intuitively what it is that makes a six-digit PIN secure,” supposes Markus Dürmuth.

A prudently chosen four-digit PIN is secure enough, mainly because manufacturers limit the number of attempts to enter a PIN. Apple locks the device completely after ten incorrect entries. On an Android smartphone, different codes cannot be entered one after the other in quick succession. “In eleven hours, 100 number combinations can be tested,” points out Philipp Markert.

Blacklists can be useful

The researchers found 274 number combinations on Apple’s blacklist for four-digit PINs. “Since users only have ten attempts to guess the PIN on the iPhone anyway, the blacklist does not make it any more secure,” concludes Maximilian Golla. According to the researchers, the blacklist would make more sense on Android devices, as attackers can try out more PINs there.

The study has shown that the ideal blacklist for four-digit PINs would have to contain about 1,000 entries and differ slightly from the list currently used by Apple. The most common four-digit PINs, according to the study, are 1234, 0000, 2580 (the digits appear vertically below each other on the numeric keypad), 1111 and 5555.

On the iPhone, users have the option to ignore the warning that they have entered a frequently used PIN. The device, therefore, does not consistently prevent entries from being selected from the blacklist. For the purpose of their study, the IT security experts also examined this aspect more closely. Some of the test participants who had entered a PIN from the blacklist were allowed to choose whether or not to enter a new PIN after the warning. The others had to set a new PIN that was not on the list. On average, the PINs of both groups were equally difficult to guess.

More secure than pattern locks

Another result of the study was that four and six-digit PINs are less secure than passwords, but more secure than pattern locks.

The most popular PINs

According to the study, the ten most popular four-digit PINs are: 1234, 0000, 2580, 1111, 5555, 5683, 0852, 2222, 1212, 1998

The ten most popular six-digit PINs are: 123456, 654321, 111111, 000000, 123123, 666666, 121212, 112233, 789456, 159753

###

Media Contact
Philipp Markert
[email protected]
49-234-322-8669

Original Source

https://news.rub.de/english/press-releases/2020-03-11-it-security-how-secure-are-four-and-six-digit-mobile-phone-pins

Tags: InternetSystem Security/HackersTechnology/Engineering/Computer Science
Share12Tweet8Share2ShareShareShare2

Related Posts

Children’s Cardiomyopathies: MRI Insights from Experts

November 6, 2025
Alien Nudibranch: Scyphozoan Predation and Nematocyst Dynamics

Alien Nudibranch: Scyphozoan Predation and Nematocyst Dynamics

November 6, 2025

Unraveling Causes and Solutions for Same-Day Surgery Cancellations

November 6, 2025

Black Soldier Fly Larvae: Innovations in Sustainable Waste Management

November 6, 2025
Please login to join discussion

POPULAR NEWS

  • Sperm MicroRNAs: Crucial Mediators of Paternal Exercise Capacity Transmission

    1299 shares
    Share 519 Tweet 324
  • Stinkbug Leg Organ Hosts Symbiotic Fungi That Protect Eggs from Parasitic Wasps

    313 shares
    Share 125 Tweet 78
  • ESMO 2025: mRNA COVID Vaccines Enhance Efficacy of Cancer Immunotherapy

    205 shares
    Share 82 Tweet 51
  • New Study Suggests ALS and MS May Stem from Common Environmental Factor

    138 shares
    Share 55 Tweet 35

About

We bring you the latest biotechnology news from best research centers and universities around the world. Check our website.

Follow us

Recent News

Children’s Cardiomyopathies: MRI Insights from Experts

Alien Nudibranch: Scyphozoan Predation and Nematocyst Dynamics

Unraveling Causes and Solutions for Same-Day Surgery Cancellations

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 68 other subscribers
  • Contact Us

Bioengineer.org © Copyright 2023 All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
    • Home Page 1
    • Home Page 2
  • News
  • National
  • Business
  • Health
  • Lifestyle
  • Science

Bioengineer.org © Copyright 2023 All Rights Reserved.