Should PINs be seen as weak?

Niklas
Niklas
Community Member

I have a few reward programs and one of them has a common-type 4-number PIN. Just like my credit card. Should these should be visible in the Weak Passwords smart folder? I'm not so sure, for once I can't use anything else than numbers if I were to change them, and even then it would by all accounts be limited to four numbers still. It also requires physical access to the card itself.

Comments

  • Megan
    Megan
    1Password Alumni

    Hi @Niklas,

    Thanks for the question! Our developers are looking for a way to exclude items like PIN codes from the 'Weak Passwords' section of the Security Audit. Obviously, a 4-digit number has limited security and is not as strong as a 20 character randomly generated password, but if you are constrained to this structure, there is limited usefulness to see them in the 'Weak Passwords' section. :)

  • Niklas
    Niklas
    Community Member

    Exactly my thoughts.

    Thanks for your response and that you are considering this.

  • Megan
    Megan
    1Password Alumni

    Hi @Niklas,

    As always, thanks for the feedback - we're glad that you're keeping your eyes open and helping us ensure that 1Password is as awesome as it can be!

  • Robs
    Robs
    Community Member

    Just wanted to post the same thing. Good that someone else noted that too ;)

  • Megan
    Megan
    1Password Alumni

    Thanks for the keen eyes, @Robs,

    I'll be sure the developers know you are keen on seeing this implemented!

  • UKenGB
    UKenGB
    Community Member

    Considering how long 1Password has been in existence, it's rather worrying that you're still only just thinking about this obvious difference between a PIN and a Password.

    I've just discovered that there is a PIN field in a Credit Card record and it's not type Text or even Password really as there is NO password generator icon next to it when editing. So this actually appears to be a (much required) third field type. Unfortunately...

    • You cannot create fields of this type. You can only choose text or password and then have the interfering generator problem.

    • If you delete this field, you can't get it back. So you now have a Credit Card record with NO field of type PIN and you're stuck with password type and the problems that entails.

    It's disappointing to return to 1Password and find stuff like this is still so bad. As I said, disappointing.

  • Thanks for the feedback!

This discussion has been closed.