How do I create a strong PIN?

Our security analyst recently shared this at our Lexington Team Huddle, which makes for a good information to know if you want to create a strong PIN code.  This content is from a blog post by DataGenetics. If you love statics, you must read the entire post, PIN number analysis (datagenetics.com); it’s fantastic.

We create PINs to lock our phone, to get money out of an ATM, to get into our computers, to enter websites, etc.  The length of many PINs are only 4 digits, which means there’s 10,000 possible combinations of digits 0 – 9.

Are you creating strong PINs?

We are going to find out now.

Unfortunately, there have been numerous breaches with data posted to the dark web in “clear text”, that means unencrypted plain text. In other words, cyber-criminals can clearly see your password.

Data Genetics looked at password tables from these security breaches. When examining the database of close to 7 million all-numeric passwords, approximately half of them were the four-digit codes that were examined.  We are fairly certain theses same 4-digit passwords are also used for PINs.  Whether it is creating passwords or PINS, people are generally very bad at doing so.

This is what they found.

First people preferred even numbers, like 2468 over odd, like 1357.

Many use what seems to be a year as their PIN, with 1972 being the most popular (think of birthdays, anniversaries). Every combination starting with “19” can be found in the top 20% of passwords.

They also like to repeat numbers, like 0101 or 5555.

Does this sound like something YOU do when creating PINs and Passwords?

The most popular password is 1234.  Nearly 11% of the 3.4 million passwords are 1234.  That is 374,000!   It was found more often than the lowest 4,200 codes combined.

The second most popular 4-digit PIN is 1111 at almost 6% (204,000).

With 10,000 combinations, these top 20 combinations below would make up 0.2% of the total. What they found is the top 20 make up over 26%!

So, how easy is it to figure out PINs?

RankPINFreq
#1123410.713%
#211116.016%
#300001.881%
#412121.197%
#577770.745%
#610040.616%
#720000.613%
#844440.526%
#922220.516%
#1069690.512%
#1199990.451%
#1233330.419%
#1355550.395%
#1466660.391%
#1511220.366%
#1613130.304%
#1788880.303%
#1843210.293%
#1920010.290%
#2010100.285%
Ranking of Top 20 4-digit passwords. From https://datagenetics.com/blog/september32012/index.html

As you can see, even when making a longer password, humans are still very predictable. Longer passwords are better than short ones, but they need to be random and you can’t remember all of them. Use a Password Management Application (like 1Password) and make your password life easier and your cyber-defense stronger.

#5 6 7 8 9 10 
 PSWD%PSWD%PSWD%PSWD%PSWD%PSWD%
#11234522.802%12345611.684%12345673.440%1234567811.825%12345678935.259%123456789020.431%
#2111114.484%1231231.370%77777771.721%111111111.326%9876543213.661%01234567892.323%
#3555551.769%1111111.296%11111110.637%888888880.959%1231231231.587%09876543212.271%
#4000001.258%1212120.623%86753090.465%876543210.815%7894561231.183%11111111112.087%
#5543211.196%1233210.591%12343210.220%000000000.675%9999999990.825%10293847561.293%
#6135791.112%6666660.577%00000000.188%123412340.569%1472583690.591%98765432100.971%
#7777770.618%0000000.521%48300330.158%696969690.348%7418529630.455%00000000000.942%
#8222220.454%6543210.506%76543210.154%121212120.320%1111111110.425%13579246800.479%
#9123210.412%6969690.454%52013140.128%112233440.293%1234543210.413%11223344550.441%
#10999990.397%1122330.417%01234560.124%123443210.275%1236547890.378%12345123450.402%
#11333330.338%1597530.283%28480480.124%777777770.262%1478523690.356%12345543210.380%
#12007000.261%2925130.250%70054250.120%999999990.223%1112223330.304%55555555550.259%
#13902100.244%1313130.235%10804130.111%222222220.219%9638527410.255%12121212120.244%
#14888880.217%1236540.228%78951230.107%555555550.205%3216549870.253%99999999990.231%
#15383170.216%2222220.212%18695100.102%333333330.176%4204204200.241%22222222220.219%
#16098760.185%7894560.209%32233260.100%444444440.165%0070070070.227%77777777770.206%
#17444440.179%9999990.194%12121230.096%666666660.160%1357924680.164%31415926540.195%
#18987650.169%1010100.190%14789630.088%111122220.140%3970290490.158%33333333330.186%
#19012340.160%7777770.188%22222220.085%131313130.131%0123456780.154%78945612300.165%
#20420690.154%0070070.186%55555550.082%100410040.127%1236987450.152%12345678910.161%
Top 20 Passwords with more than 4 digits.

To get people to make better passwords, we taught them to replace letters and numbers with symbols, like in the first box of the below cartoon.

This example would take 3 days at 1000 guesses/second to crack.  You can have more fun HERE seeing how long it would take to crack a password you create.

This approach has a huge flaw since we use common substitutions which makes it easy to program a computer to hack.

XKCD Cartoon xkcd: Password Strength

Finally, in 2017, we got new password recommendations, but unfortunately they haven’t been embraced very well. 

The lower box in the cartoon demonstrates how Four Random Common Words put together make a password that would take 550 years to crack at 1000 guesses/second.

“Through 20 years of effort, we’ve successfully trained everyone to use passwords that are hard for humans to remember, but easy for computers to guess.”