There’s no definitive way to end the password versus personal identification number (PIN) debate because they serve two different purposes, but when it comes to which is more secure, PINs win. A password allows you to log in to various online accounts, from social networks and streaming services to cloud storage and banking platforms. PIN codes, on the other hand, are used to grant access to a device or local system. In these scenarios, a copy of your password is stored somewhere on a server, while a PIN is stored locally and linked to the device. This is what makes PINs more secure, even if the user has had difficulty creating a particularly strong password.
Suppose someone accesses your password. If you’ve reused it on websites that don’t have it in a multi-factor authentication (MFA) setup, that person can easily access those accounts and steal your personal information. If they have your PIN, on the other hand, they can only use it on the device you created it on (if they can get their hands on it) – they can’t use it remotely. With the increasing incidence of data breaches, the prevalence of phishing attacks, and the speed at which people reuse their passwords, PINs have become more secure since they are tied to a device.
You can securely log in to websites with a PIN
Yes, a PIN is just a sequence of numbers that can easily be deciphered with the sophisticated tools used by hackers. That’s why it wouldn’t make sense to use them as a way to log into a website or app on your own. But these days, you can use them to log into websites instead of a password, because they are used to unlock passwords, another form of authentication that is more powerful than passwords.
When a website or app asks your device for a password before you log in, one way to give it access to the password is to enter your PIN. For example, on a Windows device, this will be your Windows Hello PIN, and on an iPhone, this will be your passcode (a six-digit numeric code). However, because PINs are not transmitted over the Internet, a hacker cannot use a Man-in-the-Middle (MiTM) attack to intercept them. So even if a hacker were to gain access to your device, they would still have difficulty determining your PIN.
Even if they have hacked your device, the PIN is encrypted and protected by hardware security modules, such as the Trusted Platform Module (TPM) on Windows, the Secure Enclave on Apple devices, and the Trusted Execution Environment (TEE) on Android. Passwords are not, which is why you should never store them on your device.
How to ensure your PIN is strong and secure
Although a PIN is more secure than a password, it must be strong to avoid giving hackers access to your passwords if they steal your device. There are certain PIN combinations that thieves will try first and which you should avoid, such as 1-2-3-4-5-6 or 2-5-8-0 (it’s in the middle column of the number pad). You should also avoid including personal information in the PIN. That means no birthdays, addresses or the last four to six digits of your phone number.
Don’t use a repeating sequence of numbers like 0000, 1111111, or 9999. Also make sure your PIN is at least six digits long. This is the default for something like Android phones and iPhones. On Windows, the minimum is four digits, but you can increase it in the Local Group Policy Editor or Registry Editor.
To protect your PIN, make it a habit to use your device’s biometric authentication methods, such as fingerprint and facial recognition, especially when you’re in public, so no one can see you entering your PIN. Your face and fingerprints cannot be guessed or stolen. They can be spoofed, but it’s not as simple as you might think. For example, to get a mold of your fingerprints, hackers would have to use something like plasticine, but unless you’re unconscious or physically incapacitated, putting it on your fingers poses a significant challenge.
