• HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
Tuesday, September 23, 2025
BIOENGINEER.ORG
No Result
View All Result
  • Login
  • HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
        • Lecturer
        • PhD Studentship
        • Postdoc
        • Research Assistant
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
  • HOME
  • NEWS
  • EXPLORE
    • CAREER
      • Companies
      • Jobs
        • Lecturer
        • PhD Studentship
        • Postdoc
        • Research Assistant
    • EVENTS
    • iGEM
      • News
      • Team
    • PHOTOS
    • VIDEO
    • WIKI
  • BLOG
  • COMMUNITY
    • FACEBOOK
    • INSTAGRAM
    • TWITTER
No Result
View All Result
Bioengineer.org
No Result
View All Result
Home NEWS Science News

How secure are four and six-digit mobile phone PINs?

Bioengineer by Bioengineer
March 11, 2020
in Science News
Reading Time: 4 mins read
0
IMAGE
Share on FacebookShare on TwitterShare on LinkedinShare on RedditShare on Telegram

Apple and Android implement a number of measures to protect their users’ devices. An international team of IT security experts has investigated how useful they are.

IMAGE

Credit: RUB, Marquard


A German-American team of IT security researchers has investigated how users choose the PIN for their mobile phones and how they can be convinced to use a more secure number combination. They found that six-digit PINs actually provide little more security than four-digit ones. They also showed that the blacklist used by Apple to prevent particularly frequent PINs could be optimised and that it would make even greater sense to implement one on Android devices.

Philipp Markert, Daniel Bailey, and Professor Markus Dürmuth from the Horst Görtz Institute for IT Security at Ruhr-Universität Bochum conducted the study jointly with Dr. Maximilian Golla from the Max Planck Institute for Security and Privacy in Bochum and Professor Adam Aviv from the George Washington University in the USA. The researchers will present the results at the IEEE Symposium on Security and Privacy in San Francisco in May 2020. A preprint of the paper can be found online: https://arxiv.org/abs/2003.04868.

Extensive user study

In the study, the researchers had users on Apple and Android devices set either four or six-digit PINs and later analysed how easy they were to guess. In the process, they assumed that the attacker did not know the victim and did not care whose mobile phone is unlocked. Accordingly, the best attack strategy would be to try the most likely PINs first.

Some of the study participants were free to choose their PIN at random. Others could only choose PINs that were not included in a blacklist. If they tried to use one of the blacklisted PINs, they received a warning that this combination of digits was easy to guess.

In the experiment, the IT security experts used various blacklists, including the real one from Apple, which they obtained by having a computer test all possible PIN combinations on an iPhone. Moreover, they also created their own more or less comprehensive blacklists.

Six-digit PINs not more secure than four-digit ones

It emerged that six-digit PINs do not provide more security than four-digit ones. “Mathematically speaking, there is a huge difference, of course,” says Philipp Markert. A four-digit PIN can be used to create 10,000 different combinations, while a six-digit PIN can be used to create one million. “However, users prefer certain combinations; some PINs are used more frequently, for example, 123456 and 654321,” explains Philipp Markert. This means users do not take advantage of the full potential of the six-digit codes. “It seems that users currently do not understand intuitively what it is that makes a six-digit PIN secure,” supposes Markus Dürmuth.

A prudently chosen four-digit PIN is secure enough, mainly because manufacturers limit the number of attempts to enter a PIN. Apple locks the device completely after ten incorrect entries. On an Android smartphone, different codes cannot be entered one after the other in quick succession. “In eleven hours, 100 number combinations can be tested,” points out Philipp Markert.

Blacklists can be useful

The researchers found 274 number combinations on Apple’s blacklist for four-digit PINs. “Since users only have ten attempts to guess the PIN on the iPhone anyway, the blacklist does not make it any more secure,” concludes Maximilian Golla. According to the researchers, the blacklist would make more sense on Android devices, as attackers can try out more PINs there.

The study has shown that the ideal blacklist for four-digit PINs would have to contain about 1,000 entries and differ slightly from the list currently used by Apple. The most common four-digit PINs, according to the study, are 1234, 0000, 2580 (the digits appear vertically below each other on the numeric keypad), 1111 and 5555.

On the iPhone, users have the option to ignore the warning that they have entered a frequently used PIN. The device, therefore, does not consistently prevent entries from being selected from the blacklist. For the purpose of their study, the IT security experts also examined this aspect more closely. Some of the test participants who had entered a PIN from the blacklist were allowed to choose whether or not to enter a new PIN after the warning. The others had to set a new PIN that was not on the list. On average, the PINs of both groups were equally difficult to guess.

More secure than pattern locks

Another result of the study was that four and six-digit PINs are less secure than passwords, but more secure than pattern locks.

The most popular PINs

According to the study, the ten most popular four-digit PINs are: 1234, 0000, 2580, 1111, 5555, 5683, 0852, 2222, 1212, 1998

The ten most popular six-digit PINs are: 123456, 654321, 111111, 000000, 123123, 666666, 121212, 112233, 789456, 159753

###

Media Contact
Philipp Markert
[email protected]
49-234-322-8669

Original Source

https://news.rub.de/english/press-releases/2020-03-11-it-security-how-secure-are-four-and-six-digit-mobile-phone-pins

Tags: InternetSystem Security/HackersTechnology/Engineering/Computer Science
Share12Tweet8Share2ShareShareShare2

Related Posts

AI Predicts Recovery in TBI Intensive Care Programs

September 23, 2025
Exploring the Potential of Drones as First Responders: A Feasibility Study in Northern Virginia

Exploring the Potential of Drones as First Responders: A Feasibility Study in Northern Virginia

September 23, 2025

Sleep Duration Influences Screen Time’s Impact on Kids

September 23, 2025

UCLA to spearhead $16 Million National Research Initiative on AI in Breast Cancer Screening

September 23, 2025
Please login to join discussion

POPULAR NEWS

  • Physicists Develop Visible Time Crystal for the First Time

    Physicists Develop Visible Time Crystal for the First Time

    69 shares
    Share 28 Tweet 17
  • Breakthrough in Computer Hardware Advances Solves Complex Optimization Challenges

    156 shares
    Share 62 Tweet 39
  • Tailored Gene-Editing Technology Emerges as a Promising Treatment for Fatal Pediatric Diseases

    50 shares
    Share 20 Tweet 13
  • Scientists Achieve Ambient-Temperature Light-Induced Heterolytic Hydrogen Dissociation

    49 shares
    Share 20 Tweet 12

About

We bring you the latest biotechnology news from best research centers and universities around the world. Check our website.

Follow us

Recent News

AI Predicts Recovery in TBI Intensive Care Programs

Exploring the Potential of Drones as First Responders: A Feasibility Study in Northern Virginia

Sleep Duration Influences Screen Time’s Impact on Kids

  • Contact Us

Bioengineer.org © Copyright 2023 All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Homepages
    • Home Page 1
    • Home Page 2
  • News
  • National
  • Business
  • Health
  • Lifestyle
  • Science

Bioengineer.org © Copyright 2023 All Rights Reserved.