<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: And change the combination on my luggage!</title>
	<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage/</link>
	<description>Comments on MetaFilter post And change the combination on my luggage!</description>
	<pubDate>Wed, 19 Sep 2012 12:16:33 -0800</pubDate>
	<lastBuildDate>Wed, 19 Sep 2012 12:16:33 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>And change the combination on my luggage!</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage</link>	
		<description>&lt;a href=&quot;http://www.datagenetics.com/blog/september32012/&quot;&gt;What are the most common and least common 4-digit PINs?&lt;/a&gt;  Using data from recent password database leaks, an analysis of PINs. (via &lt;a href=&quot;http://www.schneier.com/blog/archives/2012/09/analysis_of_pin.html&quot;&gt;Schneier&lt;/a&gt;)</description>
		<guid isPermaLink="false">post:www.metafilter.com,2012:site.120076</guid>
		<pubDate>Wed, 19 Sep 2012 12:11:07 -0800</pubDate>
		<dc:creator>fings</dc:creator>		<category>password</category>		<category>passwords</category>		<category>security</category>		<category>atm</category>
	</item>	<item>
		<title>By: carsonb</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574218</link>	
		<description>This is presumably why I have to look at a picture, type a pass phrase and user number, and also mouse-click my 6-digit PIN to log into my bank account these days.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574218</guid>
		<pubDate>Wed, 19 Sep 2012 12:16:33 -0800</pubDate>
		<dc:creator>carsonb</dc:creator>
	</item>	<item>
		<title>By: dabug</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574223</link>	
		<description>Interesting article and +12345 points for the post title.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574223</guid>
		<pubDate>Wed, 19 Sep 2012 12:20:19 -0800</pubDate>
		<dc:creator>dabug</dc:creator>
	</item>	<item>
		<title>By: ColdChef</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574227</link>	
		<description>Bosco.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574227</guid>
		<pubDate>Wed, 19 Sep 2012 12:21:47 -0800</pubDate>
		<dc:creator>ColdChef</dc:creator>
	</item>	<item>
		<title>By: Burhanistan</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574228</link>	
		<description>I recently stopped using the same PIN that I started using when I set up my first debit card 20 years ago in high school. I miss that PIN.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574228</guid>
		<pubDate>Wed, 19 Sep 2012 12:22:33 -0800</pubDate>
		<dc:creator>Burhanistan</dc:creator>
	</item>	<item>
		<title>By: inturnaround</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574229</link>	
		<description>&lt;em&gt;Bosco&lt;/em&gt;

That episode always bothered me. When did ATMs use alphas?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574229</guid>
		<pubDate>Wed, 19 Sep 2012 12:22:50 -0800</pubDate>
		<dc:creator>inturnaround</dc:creator>
	</item>	<item>
		<title>By: muddgirl</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574230</link>	
		<description>I actually really like that analysis... so of course I have to minorly nitpick at it:&lt;blockquote&gt;A staggering 26.83% of all passwords could be guessed by attempting these 20 combinations!&lt;/blockquote&gt;Presuming from context that by &apos;all passwords&apos; he means &apos;all PIN codes,&apos; I think there&apos;s an unspoken assumption here - that the sample of users who use a 4-digit number as their password is a reasonable representation of all people who have to use a 4-digit banking PIN code. I would want to see a more rigorous analysis of this assumption before accepting it, because if we take a sample of all hacked passwords and then only select a subset of people with &apos;weak&apos; passwords, pre-selecting people with the habit of picking weak passwords.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574230</guid>
		<pubDate>Wed, 19 Sep 2012 12:23:06 -0800</pubDate>
		<dc:creator>muddgirl</dc:creator>
	</item>	<item>
		<title>By: lesbiassparrow</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574238</link>	
		<description>I was using dates of wars for a long time. And then I ran out of wars (or at least wars whose dates I could actually remember),* which should say something about having too many pins that you have to change on a regular basis. Now I&apos;m on to massacres. I don&apos;t think I&apos;m going to run out of those. 


*Which was a surprising number. Thank you history teachers!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574238</guid>
		<pubDate>Wed, 19 Sep 2012 12:26:36 -0800</pubDate>
		<dc:creator>lesbiassparrow</dc:creator>
	</item>	<item>
		<title>By: Tell Me No Lies</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574240</link>	
		<description>&lt;i&gt;because if we take a sample of all hacked passwords and then only select a subset of people with &apos;weak&apos; passwords, pre-selecting people with the habit of picking weak passwords.&lt;/i&gt;

The hacked passwords were leaked by having the master database compromised, not the individual passwords.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574240</guid>
		<pubDate>Wed, 19 Sep 2012 12:28:17 -0800</pubDate>
		<dc:creator>Tell Me No Lies</dc:creator>
	</item>	<item>
		<title>By: Vorteks</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574243</link>	
		<description>&lt;blockquote&gt;&lt;q&gt;&lt;i&gt;I actually really like that analysis... so of course I have to minorly nitpick at it:

A staggering 26.83% of all passwords could be guessed by attempting these 20 combinations!&lt;/i&gt;&lt;/q&gt;&lt;/blockquote&gt;

Plus you have to remember that most debit cards/ATM cards are automatically deactivated after 3 or so incorrect PIN entries. So even if every card in the world had one of those 20 combinations, the chances of correctly guessing the pin before the card was locked down would only be 3 in 20, or 15%.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574243</guid>
		<pubDate>Wed, 19 Sep 2012 12:28:48 -0800</pubDate>
		<dc:creator>Vorteks</dc:creator>
	</item>	<item>
		<title>By: GenjiandProust</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574244</link>	
		<description>The people with the least-frequently used PIN number are cursing right now. Nice going, Analysts!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574244</guid>
		<pubDate>Wed, 19 Sep 2012 12:29:04 -0800</pubDate>
		<dc:creator>GenjiandProust</dc:creator>
	</item>	<item>
		<title>By: jaduncan</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574247</link>	
		<description>Yes, this is flawed. It should probably be titled &quot;what idiots who can&apos;t pick passwords use for their passcodes&quot;, but even setting this aside it&apos;s quite rational to have a easy to remember code for a junk commenting account and still have at least a birthdate or something more than 0000 on one&apos;s ATM cards.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574247</guid>
		<pubDate>Wed, 19 Sep 2012 12:29:30 -0800</pubDate>
		<dc:creator>jaduncan</dc:creator>
	</item>	<item>
		<title>By: Ceci n&apos;est pas un sockpuppet</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574249</link>	
		<description>Dang, I&apos;m not in the top twenty, but choosing my 9th grade locker number does indeed put me in the huge 19XX segment of the population. Maybe next time I have to replace my debit card I&apos;ll switch it up.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574249</guid>
		<pubDate>Wed, 19 Sep 2012 12:30:29 -0800</pubDate>
		<dc:creator>Ceci n&apos;est pas un sockpuppet</dc:creator>
	</item>	<item>
		<title>By: perhapses</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574250</link>	
		<description>My nine-year-old daughter&apos;s friend was over one day with her iPod Touch. She had activated the access code function and was amazed when my daughter &quot;cracked&quot; it on the first try. 1234. So she challenged my daughter to create an access code on her iPhone (an older, bricked one) so she could attempt to break into it. My daughter used our street address and her poor friend was unable to get it. I was amazed at how brilliant her friend thought my daughter was for being able to do that.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574250</guid>
		<pubDate>Wed, 19 Sep 2012 12:30:43 -0800</pubDate>
		<dc:creator>perhapses</dc:creator>
	</item>	<item>
		<title>By: muddgirl</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574251</link>	
		<description>One of the nice things about memorizing the first 50 digits of Pi was that it generates a lot of nice &apos;random&apos; 4-digit numbers (although if a hacker knew I was using that scheme, it would be more vulnerable). Note to hackers: I don&apos;t use that scheme anymore.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574251</guid>
		<pubDate>Wed, 19 Sep 2012 12:30:45 -0800</pubDate>
		<dc:creator>muddgirl</dc:creator>
	</item>	<item>
		<title>By: figurant</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574254</link>	
		<description>Highly amused by the prominence of 8675309 in the 7-digit list.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574254</guid>
		<pubDate>Wed, 19 Sep 2012 12:31:13 -0800</pubDate>
		<dc:creator>figurant</dc:creator>
	</item>	<item>
		<title>By: carsonb</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574255</link>	
		<description>&lt;i&gt;&quot;what idiots who can&apos;t pick passwords use for their passcodes&quot;&lt;/i&gt;

Don&apos;t forget people with Credit Union-issued cards that use those networked standalone ATMs. Some of those cards are issued with a set PIN and it&apos;s a real hassle to get them changed.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574255</guid>
		<pubDate>Wed, 19 Sep 2012 12:32:06 -0800</pubDate>
		<dc:creator>carsonb</dc:creator>
	</item>	<item>
		<title>By: Shepherd</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574259</link>	
		<description>I created my PIN using two related math facts: first using the first two-digit number to be surrounded by primes, then following those two digits with the smallest number to be surrounded by numbers with the same number of divisors as it has. Guaranteed unguessable! Foolproof!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574259</guid>
		<pubDate>Wed, 19 Sep 2012 12:32:55 -0800</pubDate>
		<dc:creator>Shepherd</dc:creator>
	</item>	<item>
		<title>By: shothotbot</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574261</link>	
		<description>Good thing no one here uses estimates of physical constants as a PIN!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574261</guid>
		<pubDate>Wed, 19 Sep 2012 12:34:01 -0800</pubDate>
		<dc:creator>shothotbot</dc:creator>
	</item>	<item>
		<title>By: kjh</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574263</link>	
		<description>Am I the only one disappointed that there&apos;s no link to the full list?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574263</guid>
		<pubDate>Wed, 19 Sep 2012 12:34:14 -0800</pubDate>
		<dc:creator>kjh</dc:creator>
	</item>	<item>
		<title>By: Malor</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574268</link>	
		<description>I just use what the bank assigns, on the theory that it will be truly random.   Although I should probably nudge them to make something longer, as four digits is awfully short.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574268</guid>
		<pubDate>Wed, 19 Sep 2012 12:35:11 -0800</pubDate>
		<dc:creator>Malor</dc:creator>
	</item>	<item>
		<title>By: GenjiandProust</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574269</link>	
		<description>&lt;em&gt;Note to hackers: I don&apos;t use that scheme anymore.&lt;/em&gt;

Who do you think you are fooling with &lt;em&gt;that&lt;/em&gt; disclaimer?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574269</guid>
		<pubDate>Wed, 19 Sep 2012 12:35:20 -0800</pubDate>
		<dc:creator>GenjiandProust</dc:creator>
	</item>	<item>
		<title>By: jaduncan</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574275</link>	
		<description>&lt;em&gt; Although I should probably nudge them to make something longer, as four digits is awfully short.&lt;/em&gt;

Good luck with that; it will only happen when an incredibly wide base of installed hardware and code assumptions finally die out. People get annoyed if their PIN suddenly doesn&apos;t work on their holiday in Fiji.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574275</guid>
		<pubDate>Wed, 19 Sep 2012 12:37:43 -0800</pubDate>
		<dc:creator>jaduncan</dc:creator>
	</item>	<item>
		<title>By: logicpunk</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574276</link>	
		<description>My PIN used to be the first word I&apos;d say when I realized I&apos;d forgotten my PIN.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574276</guid>
		<pubDate>Wed, 19 Sep 2012 12:37:44 -0800</pubDate>
		<dc:creator>logicpunk</dc:creator>
	</item>	<item>
		<title>By: Spatch</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574278</link>	
		<description>&lt;i&gt;That episode always bothered me. When did ATMs use alphas?&lt;/i&gt;

The bank my family used twenty-five years ago had ATMs with telephone-style number pads that had letters over the numbers and everything. We able to choose a five-digit PIN too, so our ATM passcode became 74337. We raised sheep, y&apos;see. 

&lt;small&gt;I feel perfectly safe giving out this information considering that today the bank account, family unit and indeed the bank itself do not exist in their 1987 configurations. Unless you&apos;re a stinking time-traveller in which case oh well, have fun, but please leave enough for us to go to Disney World in 1988 because that was really awesome.&lt;/small&gt;

At the time I remember being more impressed by the fact that we were able to choose our PIN, because before that we had to memorize the one the bank gave us and what fun was that?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574278</guid>
		<pubDate>Wed, 19 Sep 2012 12:38:12 -0800</pubDate>
		<dc:creator>Spatch</dc:creator>
	</item>	<item>
		<title>By: Holy Zarquon&apos;s Singing Fish</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574281</link>	
		<description>&lt;em&gt;My PIN used to be the first word I&apos;d say when I realized I&apos;d forgotten my PIN.&lt;/em&gt;

&quot;Ouch&quot;?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574281</guid>
		<pubDate>Wed, 19 Sep 2012 12:39:21 -0800</pubDate>
		<dc:creator>Holy Zarquon&apos;s Singing Fish</dc:creator>
	</item>	<item>
		<title>By: Jpfed</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574286</link>	
		<description>&lt;em&gt;because if we take a sample of all hacked passwords and then only select a subset of people with &apos;weak&apos; passwords, pre-selecting people with the habit of picking weak passwords.

&lt;strong&gt;The hacked passwords were leaked by having the master database compromised, not the individual passwords&lt;/strong&gt;.&lt;/em&gt;

I don&apos;t think muddgirl&apos;s point was about &quot;these people were dumb enough to have their password compromised&quot;; it was &quot;these people were dumb enough to have chosen a 4-digit password&quot;.  

People can have whatever they want for their password.  Some people, for whatever reason, choose 4-digit numbers for their passwords instead of &quot;correct horse battery staple&quot; or whatever.   Those people may be predisposed to picking weak PINs; after all, we already know that they chose a weak password.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574286</guid>
		<pubDate>Wed, 19 Sep 2012 12:40:02 -0800</pubDate>
		<dc:creator>Jpfed</dc:creator>
	</item>	<item>
		<title>By: wcfields</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574289</link>	
		<description>I found this tid-bit interesting that these ATM PINs may have come via Korea.
&lt;blockquote&gt;
&lt;a href=&quot;http://news.ycombinator.com/item?id=4536506&quot;&gt;kijin&lt;/a&gt; via the &lt;a href=&quot;http://news.ycombinator.com/item?id=4535417&quot;&gt;Hacker News post&lt;/a&gt;: 
&lt;blockquote&gt;If you&apos;re wondering why 1004, a seemingly random number, is so close to the top of the list -- something that the author does not investigate in any detail -- my guess is that the database he used contains some major leaks from Korea. 1004 is a fairly popular password there, because it is one of the few 4-digit numbers that sound like actual words in Korean. 1004 sounds like &quot;angel&quot; (&lt;em&gt;cheonsa&lt;/em&gt;).

So if you&apos;re actually trying to break into people&apos;s accounts, it would be advantageous to know your victims&apos; ethnicity. It&apos;s quite likely that cards stolen in Koreatown will have a different distribution of PIN numbers than those stolen in Chinatown.&lt;/blockquote&gt;&lt;/blockquote&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574289</guid>
		<pubDate>Wed, 19 Sep 2012 12:41:48 -0800</pubDate>
		<dc:creator>wcfields</dc:creator>
	</item>	<item>
		<title>By: theodolite</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574295</link>	
		<description>Why is &quot;1004&quot; so high on the list? The analysis doesn&apos;t make any special note of it, but it&apos;s the only one in the top 10 that isn&apos;t just a repeated number or &quot;1234&quot;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574295</guid>
		<pubDate>Wed, 19 Sep 2012 12:44:42 -0800</pubDate>
		<dc:creator>theodolite</dc:creator>
	</item>	<item>
		<title>By: theodolite</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574300</link>	
		<description>Thanks wcfields for answering my question while I was still typing it.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574300</guid>
		<pubDate>Wed, 19 Sep 2012 12:45:34 -0800</pubDate>
		<dc:creator>theodolite</dc:creator>
	</item>	<item>
		<title>By: nebulawindphone</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574302</link>	
		<description>When I got my first bank account, I used my boyfriend&apos;s birthday for the PIN.  Only it turns out I remembered his birthday wrong, so my PIN is actually &quot;That one date when I &lt;i&gt;thought&lt;/i&gt; my boyfriend was born.&quot;  And then we broke up shortly afterwards.

How about THAT for security!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574302</guid>
		<pubDate>Wed, 19 Sep 2012 12:45:52 -0800</pubDate>
		<dc:creator>nebulawindphone</dc:creator>
	</item>	<item>
		<title>By: Ad hominem</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574313</link>	
		<description>A actual criminal asked me this once. He was a guy who hung around my building, just kind of loafing.

He knew I was some kind of computer whiz and asked me, &quot;if you had a debit card you found in an envelope in a pile of mail, how could you get the pin&quot;. I told him he could never guess it at the ATM, search the rest of the mail for the second letter that contained the PIN.

A couple weeks later I heard my mom complaining on the phone about mysterious 500$ debits on her card.

I felt like a real dick. I had to confess I had told the guy how to steal her money.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574313</guid>
		<pubDate>Wed, 19 Sep 2012 12:48:27 -0800</pubDate>
		<dc:creator>Ad hominem</dc:creator>
	</item>	<item>
		<title>By: ColdChef</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574315</link>	
		<description>&lt;em&gt;Why is &quot;1004&quot; so high on the list?&lt;/em&gt;

That&apos;s a big 10-4, good buddy!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574315</guid>
		<pubDate>Wed, 19 Sep 2012 12:49:51 -0800</pubDate>
		<dc:creator>ColdChef</dc:creator>
	</item>	<item>
		<title>By: AugieAugustus</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574318</link>	
		<description>&lt;em&gt;I felt like a real dick.
posted by Ad hominem at 2:48 PM on September 19 [+] [!]&lt;/em&gt;

Eponysterical!

On topic: I find it intriguing that on average the least common 4-digiters are significantly larger numbers than the most common 4-digiters.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574318</guid>
		<pubDate>Wed, 19 Sep 2012 12:51:52 -0800</pubDate>
		<dc:creator>AugieAugustus</dc:creator>
	</item>	<item>
		<title>By: muddgirl</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574322</link>	
		<description>&lt;i&gt;it was &quot;these people were dumb enough to have chosen a 4-digit password&quot;&lt;/i&gt;

I hesitate to use the word &quot;dumb&quot; (because if I need a password for a site that cares &lt;i&gt;so much&lt;/i&gt; about security that they&apos;re storing passwords in clear text, there&apos;s no reason to waste my time on a super-strong password, as long as it&apos;s unique) - but essentially, yes. I don&apos;t think it&apos;s axiomatic that a sample of weak passwords is representative of all PIN numbers.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574322</guid>
		<pubDate>Wed, 19 Sep 2012 12:53:40 -0800</pubDate>
		<dc:creator>muddgirl</dc:creator>
	</item>	<item>
		<title>By: whuppy</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574326</link>	
		<description>See also Benford&apos;s Law.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574326</guid>
		<pubDate>Wed, 19 Sep 2012 12:56:00 -0800</pubDate>
		<dc:creator>whuppy</dc:creator>
	</item>	<item>
		<title>By: Sys Rq</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574329</link>	
		<description>Blah blah blah &lt;em&gt;luggage!&lt;/em&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574329</guid>
		<pubDate>Wed, 19 Sep 2012 12:57:46 -0800</pubDate>
		<dc:creator>Sys Rq</dc:creator>
	</item>	<item>
		<title>By: WaylandSmith</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574332</link>	
		<description>I happily used 8 digit PINs for by bank card for years, thinking I was clever, until I travelled overseas and had no way to access my money, nor any way to change the PIN remotely.  Anybody know how pervasive &amp;gt;4 digit PINs are overseas these days?  I figure Europe&apos;s fine, but what about Asia?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574332</guid>
		<pubDate>Wed, 19 Sep 2012 12:59:31 -0800</pubDate>
		<dc:creator>WaylandSmith</dc:creator>
	</item>	<item>
		<title>By: ceribus peribus</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574338</link>	
		<description>It&apos;s hard for me to remember the actual digits in my PIN; I just push the same twisty line of buttons each time and rely on the fact that the number keys are always in the same configuration.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574338</guid>
		<pubDate>Wed, 19 Sep 2012 13:01:59 -0800</pubDate>
		<dc:creator>ceribus peribus</dc:creator>
	</item>	<item>
		<title>By: blue_beetle</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574341</link>	
		<description>I do all my PINs in hex.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574341</guid>
		<pubDate>Wed, 19 Sep 2012 13:03:20 -0800</pubDate>
		<dc:creator>blue_beetle</dc:creator>
	</item>	<item>
		<title>By: Sys Rq</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574344</link>	
		<description>Oh, and just FYI:  Using a PIN made up of numbers, or by the position of the keys, is a great idea until you inevitably run into that machine with the letters on different numbers, or the keys in a different order, and then you&apos;re fucked.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574344</guid>
		<pubDate>Wed, 19 Sep 2012 13:04:21 -0800</pubDate>
		<dc:creator>Sys Rq</dc:creator>
	</item>	<item>
		<title>By: inigo2</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574346</link>	
		<description>&lt;i&gt;I created my PIN using two related math facts: first using the first two-digit number to be surrounded by primes, then following those two digits with the smallest number to be surrounded by numbers with the same number of divisors as it has. Guaranteed unguessable! Foolproof!&lt;/i&gt;

I see what you did there.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574346</guid>
		<pubDate>Wed, 19 Sep 2012 13:04:26 -0800</pubDate>
		<dc:creator>inigo2</dc:creator>
	</item>	<item>
		<title>By: Sys Rq</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574347</link>	
		<description>Ugh. Made up of LETTERS.  D&apos;doy.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574347</guid>
		<pubDate>Wed, 19 Sep 2012 13:04:47 -0800</pubDate>
		<dc:creator>Sys Rq</dc:creator>
	</item>	<item>
		<title>By: MtDewd</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574352</link>	
		<description>&lt;em&gt;Oh, and just FYI: Using a PIN made up of numbers, or by the position of the keys, is a great idea until you inevitably run into that machine with the letters on different numbers, or the keys in a different order, and then you&apos;re fucked.&lt;/em&gt;
This happened to me decades ago when I had a phone number memorized by the keypress positions, and I was faced with a rotary phone dial.
My solution- I drew out a picture of a phone keyboard, and then watched as my muscle memory took over.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574352</guid>
		<pubDate>Wed, 19 Sep 2012 13:07:56 -0800</pubDate>
		<dc:creator>MtDewd</dc:creator>
	</item>	<item>
		<title>By: scruss</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574354</link>	
		<description>It pleases me that this shows the statistical insignificance of Canada, as every Canadian male over the age of 36 has the PIN &apos;2112&apos;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574354</guid>
		<pubDate>Wed, 19 Sep 2012 13:09:32 -0800</pubDate>
		<dc:creator>scruss</dc:creator>
	</item>	<item>
		<title>By: Sys Rq</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574367</link>	
		<description>&lt;em&gt;My solution- I drew out a picture of a phone keyboard, and then watched as my muscle memory took over.&lt;/em&gt;

My solution was to stubbornly keep trying the same wrong thing until I hit my maximum tries (there is such a thing, apparently) and had to go to the bank and reset my code.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574367</guid>
		<pubDate>Wed, 19 Sep 2012 13:14:30 -0800</pubDate>
		<dc:creator>Sys Rq</dc:creator>
	</item>	<item>
		<title>By: Karmakaze</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574372</link>	
		<description>&lt;blockquote&gt;&lt;i&gt;This happened to me decades ago when I had a phone number memorized by the keypress positions, and I was faced with a rotary phone dial.&lt;/i&gt;&lt;/blockquote&gt;
I used to have that problem with BBS phone numbers.  I knew them by typing them on the numbers at the top of my keyboard.  But if someone asked me for a BBS number, I&apos;d have to pretend-type to recreate them.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574372</guid>
		<pubDate>Wed, 19 Sep 2012 13:15:47 -0800</pubDate>
		<dc:creator>Karmakaze</dc:creator>
	</item>	<item>
		<title>By: Harpocrates</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574402</link>	
		<description>I find that pins I set using a phone or at a bank are different than numerical pins on a pc due to the different keypad configurations.   (Why do keyboard number pads have a orientation anyway? )</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574402</guid>
		<pubDate>Wed, 19 Sep 2012 13:23:11 -0800</pubDate>
		<dc:creator>Harpocrates</dc:creator>
	</item>	<item>
		<title>By: Tell Me No Lies</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574409</link>	
		<description>&lt;em&gt;I don&apos;t think muddgirl&apos;s point was about &quot;these people were dumb enough to have their password compromised&quot;; it was &quot;these people were dumb enough to have chosen a 4-digit password&quot;. 

People can have whatever they want for their password.&lt;/em&gt; 

Ah, I see the confusion.  Unfortunately your second statement is untrue.  Many ATM machines around the world require a four digit pin.  I found that out the hard way when I went on an extended multi-country trip and was frequently unable to access funds due to my 6 digit pin.

If as has been suggested this sample was obtained from Korea the users likely had no say in the pin length.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574409</guid>
		<pubDate>Wed, 19 Sep 2012 13:24:10 -0800</pubDate>
		<dc:creator>Tell Me No Lies</dc:creator>
	</item>	<item>
		<title>By: Jpfed</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574421</link>	
		<description>&lt;em&gt;Ah, I see the confusion. Unfortunately your second statement is untrue. Many ATM machines around the world require a four digit pin. I found that out the hard way when I went on an extended multi-country trip and was frequently unable to access funds due to my 6 digit pin.&lt;/em&gt;

The article did not use actual PINs for its analysis though.  Of course PINs are often restricted to four digits.  But this used compromised &lt;em&gt;passwords&lt;/em&gt;, not compromised PINs.

From the article, my emphasis:

&lt;blockquote&gt;Obviously, I don&apos;t have access to a credit card PIN number database. &lt;strong&gt;Instead I&apos;m going to use a proxy&lt;/strong&gt;. I&apos;m going to use data condensed from released/exposed/discovered password tables and security breaches.&lt;/blockquote&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574421</guid>
		<pubDate>Wed, 19 Sep 2012 13:27:22 -0800</pubDate>
		<dc:creator>Jpfed</dc:creator>
	</item>	<item>
		<title>By: klangklangston</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574476</link>	
		<description>Heh. My ATM card&apos;s pin is one of the five least used pins. Guess I&apos;ll change it to 1235.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574476</guid>
		<pubDate>Wed, 19 Sep 2012 13:47:41 -0800</pubDate>
		<dc:creator>klangklangston</dc:creator>
	</item>	<item>
		<title>By: _paegan_</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574506</link>	
		<description>I&apos;m relieved my PIN was on none of the lists.  I use the day of my two favorite holidays... one of my fav holidays is obscure.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574506</guid>
		<pubDate>Wed, 19 Sep 2012 13:57:15 -0800</pubDate>
		<dc:creator>_paegan_</dc:creator>
	</item>	<item>
		<title>By: adamdschneider</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574519</link>	
		<description>I&apos;m not telling any of you a goddamned thing about my PIN.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574519</guid>
		<pubDate>Wed, 19 Sep 2012 14:03:15 -0800</pubDate>
		<dc:creator>adamdschneider</dc:creator>
	</item>	<item>
		<title>By: Tell Me No Lies</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574582</link>	
		<description>&lt;em&gt;Obviously, I don&apos;t have access to a credit card PIN number database. Instead I&apos;m going to use a proxy. I&apos;m going to use data condensed from released/exposed/discovered password tables and security breaches.&lt;/em&gt;

Ah, missed that.  I retract my earlier statements.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574582</guid>
		<pubDate>Wed, 19 Sep 2012 14:35:08 -0800</pubDate>
		<dc:creator>Tell Me No Lies</dc:creator>
	</item>	<item>
		<title>By: deborah</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574603</link>	
		<description>I recently changed both PINS to the &lt;em&gt;same thing&lt;/em&gt;. I laugh at danger!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574603</guid>
		<pubDate>Wed, 19 Sep 2012 14:43:55 -0800</pubDate>
		<dc:creator>deborah</dc:creator>
	</item>	<item>
		<title>By: nebulawindphone</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574609</link>	
		<description>&lt;i&gt;I&apos;m not telling any of you a goddamned thing about my PIN.&lt;/i&gt;

Too late &amp;mdash; you just did!

&lt;small&gt;Quick, scan his comment history!  Figure out which four-digit numbers he hasn&apos;t told us anything about!&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574609</guid>
		<pubDate>Wed, 19 Sep 2012 14:47:56 -0800</pubDate>
		<dc:creator>nebulawindphone</dc:creator>
	</item>	<item>
		<title>By: kurumi</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574630</link>	
		<description>&lt;em&gt;Why is &quot;1004&quot; so high on the list?&lt;/em&gt;

A lot of people are fans of comb jellies?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574630</guid>
		<pubDate>Wed, 19 Sep 2012 14:56:12 -0800</pubDate>
		<dc:creator>kurumi</dc:creator>
	</item>	<item>
		<title>By: mathowie</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574657</link>	
		<description>I have one rule: every 4-digit PIN I have to share with family/coworkers is set to 5150. 

&lt;small&gt;Because everyone remembers when Van Halen started to suck, and it was &lt;em&gt;5150&lt;/em&gt;.&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574657</guid>
		<pubDate>Wed, 19 Sep 2012 15:10:23 -0800</pubDate>
		<dc:creator>mathowie</dc:creator>
	</item>	<item>
		<title>By: percor</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574661</link>	
		<description>&lt;i&gt;I have one rule: every 4-digit PIN I have to share with family/coworkers is set to 5150. &lt;/i&gt;

...and with that one foolish slip, admin privileges are MINE!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574661</guid>
		<pubDate>Wed, 19 Sep 2012 15:14:50 -0800</pubDate>
		<dc:creator>percor</dc:creator>
	</item>	<item>
		<title>By: Holy Zarquon&apos;s Singing Fish</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574662</link>	
		<description>Not so fast - his MeFi password is an unhackable &lt;em&gt;three&lt;/em&gt; digits!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574662</guid>
		<pubDate>Wed, 19 Sep 2012 15:16:55 -0800</pubDate>
		<dc:creator>Holy Zarquon&apos;s Singing Fish</dc:creator>
	</item>	<item>
		<title>By: carbide</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574673</link>	
		<description>Stay gold, the 0.154% of five-digit grown-ups using 42069.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574673</guid>
		<pubDate>Wed, 19 Sep 2012 15:27:15 -0800</pubDate>
		<dc:creator>carbide</dc:creator>
	</item>	<item>
		<title>By: nebulawindphone</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574679</link>	
		<description>You mean the entire population of Melber, Kentucky?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574679</guid>
		<pubDate>Wed, 19 Sep 2012 15:31:05 -0800</pubDate>
		<dc:creator>nebulawindphone</dc:creator>
	</item>	<item>
		<title>By: garius</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574707</link>	
		<description>&lt;em&gt;Why do keyboard number pads have a orientation anyway?&lt;/em&gt;

As in why are they different? Because one was based on the layout of calculators and the other on rotary phones.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574707</guid>
		<pubDate>Wed, 19 Sep 2012 15:56:41 -0800</pubDate>
		<dc:creator>garius</dc:creator>
	</item>	<item>
		<title>By: Xoebe</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574717</link>	
		<description>As the only thing closest to an IT guy we had, I was The Administrator to our modest network.

Then one day I was sick, and you guessed it - the server went kerflooey and nobody could do a thing about it.  The boss called me at home, and asked for my password, but I had no idea what it was.  I used a pattern of jagged lines on the keyboard.  I had to climb out of bed and find a keyboard before I could tell him what the password was.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574717</guid>
		<pubDate>Wed, 19 Sep 2012 16:05:08 -0800</pubDate>
		<dc:creator>Xoebe</dc:creator>
	</item>	<item>
		<title>By: Ike_Arumba</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574741</link>	
		<description>&lt;em&gt;Bosco

That episode always bothered me. When did ATMs use alphas?&lt;/em&gt;

That, plus: what ATMs have 5-digit PINs? Aren&apos;t they nearly all 4-digit? Or should I say, back in &apos;91-ish when that Seinfeld episode aired?? This has always bothered me tremendously... makes no sense.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574741</guid>
		<pubDate>Wed, 19 Sep 2012 16:31:01 -0800</pubDate>
		<dc:creator>Ike_Arumba</dc:creator>
	</item>	<item>
		<title>By: limeonaire</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574768</link>	
		<description>Agh, I wish he would edit that thing to replace every instance of &quot;PIN number&quot; with &quot;PIN.&quot; &apos;Cause otherwise, this is a great piece.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574768</guid>
		<pubDate>Wed, 19 Sep 2012 16:54:41 -0800</pubDate>
		<dc:creator>limeonaire</dc:creator>
	</item>	<item>
		<title>By: benito.strauss</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574774</link>	
		<description>&lt;cite&gt;I have one rule: every 4-digit PIN I have to share with family/coworkers is set to 5150. &lt;/cite&gt;

I&apos;m glad you&apos;re not from California, where a 5150 is a &lt;a href=&quot;http://en.wikipedia.org/wiki/5150_%28Involuntary_psychiatric_hold%29&quot;&gt;72-hour involuntary psychiatric hold&lt;/a&gt;. (I spent a summer in college doing data entry at a state hospital. I must have typed that number many thousand times.)</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574774</guid>
		<pubDate>Wed, 19 Sep 2012 16:59:41 -0800</pubDate>
		<dc:creator>benito.strauss</dc:creator>
	</item>	<item>
		<title>By: ob1quixote</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574814</link>	
		<description>Wait, wait. It took until the 24th comment, nearly five hours after it was posted &lt;em&gt;on MetaFilter&lt;/em&gt;, for anyone to say anything about the &quot;PIN Number&quot; thing? How is this possible?

&lt;small&gt;&amp;lt;soapbox&amp;gt;Remember kids, it&apos;s &apos;PIN&apos;, not &apos;PIN Number&apos;. You wouldn&apos;t say &apos;Personal Identification Number Number&apos;, &lt;em&gt;so for the love of Christ don&apos;t say &apos;PIN Number&apos;.&lt;/em&gt; Same deal with &apos;ATM Machine&apos;, &apos;NIC Card&apos;, &lt;i&gt;etc&lt;/i&gt;.&amp;lt;/soapbox&amp;gt;&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574814</guid>
		<pubDate>Wed, 19 Sep 2012 17:39:25 -0800</pubDate>
		<dc:creator>ob1quixote</dc:creator>
	</item>	<item>
		<title>By: Rodrigo Lamaitre</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574817</link>	
		<description>&lt;em&gt;That, plus: what ATMs have 5-digit PINs? Aren&apos;t they nearly all 4-digit? Or should I say, back in &apos;91-ish when that Seinfeld episode aired?? This has always bothered me tremendously... makes no sense.&lt;/em&gt;

And what&apos;s the deal with sitcoms that don&apos;t adhere to reality? I mean, their writers are human. I know they&apos;ve seen an ATM. Who &lt;em&gt;are&lt;/em&gt; these people?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574817</guid>
		<pubDate>Wed, 19 Sep 2012 17:41:41 -0800</pubDate>
		<dc:creator>Rodrigo Lamaitre</dc:creator>
	</item>	<item>
		<title>By: sourwookie</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574832</link>	
		<description>I ctl+f&apos;d the article for my PIN. It did not appear.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574832</guid>
		<pubDate>Wed, 19 Sep 2012 17:49:15 -0800</pubDate>
		<dc:creator>sourwookie</dc:creator>
	</item>	<item>
		<title>By: Shepherd</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574863</link>	
		<description>[steals mathowie&apos;s bank card, panics, spends 15 minutes trying to type OU812 into an ATM]</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574863</guid>
		<pubDate>Wed, 19 Sep 2012 18:05:38 -0800</pubDate>
		<dc:creator>Shepherd</dc:creator>
	</item>	<item>
		<title>By: lungtaworld</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574885</link>	
		<description>Not a PIN, but I suppose that &quot;E=MC2&quot; would not be a good password?</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574885</guid>
		<pubDate>Wed, 19 Sep 2012 18:18:47 -0800</pubDate>
		<dc:creator>lungtaworld</dc:creator>
	</item>	<item>
		<title>By: benito.strauss</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574893</link>	
		<description>&lt;small&gt;&lt;cite&gt;Remember kids, it&apos;s &apos;PIN&apos;, not &apos;PIN Number&apos;. You wouldn&apos;t say &apos;Personal Identification Number Number&apos;, .... &lt;/cite&gt;

&amp;lt;steals_soapbox&amp;gt;
But I would definitely say &quot;PIN number&quot;. As do millions of others, and we are all perfectly well understood. The goal of language is communication and clarity; efficiency is way down on the scale of what&apos;s important. In fact we throw in tons of redundancy to ensure the robustness of our language &amp;mdash; each letter conveys &lt;a href=&quot;http://en.wikipedia.org/wiki/Entropy_%28information_theory%29&quot;&gt;about 1 bit of information&lt;/a&gt;, which we wastefully encode with log&lt;sub&gt;2&lt;/sub&gt; 26 &#8776; 4.7 bits.
&amp;lt;/steals_soapbox&amp;gt;
&lt;/small&gt;</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574893</guid>
		<pubDate>Wed, 19 Sep 2012 18:21:35 -0800</pubDate>
		<dc:creator>benito.strauss</dc:creator>
	</item>	<item>
		<title>By: acb</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574895</link>	
		<description>&lt;i&gt;Don&apos;t forget people with Credit Union-issued cards that use those networked standalone ATMs. Some of those cards are issued with a set PIN and it&apos;s a real hassle to get them changed.&lt;/i&gt;

I recall reading once (I think it may have been in The Register) that, for a while in the 1980s, all bank cards issued in the UK were factory-set to one of three PINs. When this was discovered, the powers that be had to quickly scrap and reissue all the cards before anyone realised exactly the reason for the recall and the financial system collapsed.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574895</guid>
		<pubDate>Wed, 19 Sep 2012 18:24:01 -0800</pubDate>
		<dc:creator>acb</dc:creator>
	</item>	<item>
		<title>By: Lentrohamsanin</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574896</link>	
		<description>&lt;em&gt;Am I the only one disappointed that there&apos;s no link to the full list?&lt;/em&gt;

Oh I&apos;ve got a copy. Shoot me your PIN and I&apos;ll look it up for you.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574896</guid>
		<pubDate>Wed, 19 Sep 2012 18:24:50 -0800</pubDate>
		<dc:creator>Lentrohamsanin</dc:creator>
	</item>	<item>
		<title>By: RobotHero</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574937</link>	
		<description>The price of a cheese pizza and a large soda at Panucci&apos;s Pizza.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574937</guid>
		<pubDate>Wed, 19 Sep 2012 18:57:18 -0800</pubDate>
		<dc:creator>RobotHero</dc:creator>
	</item>	<item>
		<title>By: googly</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574938</link>	
		<description>&lt;em&gt;My solution was to stubbornly keep trying the same wrong thing until I hit my maximum tries (there is such a thing, apparently) and had to go to the bank and reset my code.&lt;/em&gt;

Me too! Except this particular ATM was in a Barcelona train station, and my nearest bank branch was 6000 miles away.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574938</guid>
		<pubDate>Wed, 19 Sep 2012 18:57:57 -0800</pubDate>
		<dc:creator>googly</dc:creator>
	</item>	<item>
		<title>By: fings</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574977</link>	
		<description>&lt;i&gt;I suppose that &quot;E=MC2&quot; would not be a good password?&lt;/i&gt;

It definitely would not be.  The RockYou password list includes: e=mc2, e=mc^2, e=mc2**, and e=mcsquared, and password crackers regularly check upper and lower case versions of passwords.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4574977</guid>
		<pubDate>Wed, 19 Sep 2012 19:21:10 -0800</pubDate>
		<dc:creator>fings</dc:creator>
	</item>	<item>
		<title>By: yaymukund</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575028</link>	
		<description>&lt;blockquote&gt;Hurrah for math! In position #17 of the ten digit password list we get 3141592654 (The first few digits of Pi)&lt;/blockquote&gt;

Math schmath&amp;mdash; those aren&apos;t even the correct digits!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575028</guid>
		<pubDate>Wed, 19 Sep 2012 20:06:35 -0800</pubDate>
		<dc:creator>yaymukund</dc:creator>
	</item>	<item>
		<title>By: muddgirl</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575051</link>	
		<description>&lt;i&gt;Math schmath&#8212; those aren&apos;t even the correct digits!&lt;/i&gt;

That&apos;s the beauty of it - no one things to check the &lt;i&gt;wrong&lt;/i&gt; digits of pi!</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575051</guid>
		<pubDate>Wed, 19 Sep 2012 20:32:15 -0800</pubDate>
		<dc:creator>muddgirl</dc:creator>
	</item>	<item>
		<title>By: Popular Ethics</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575094</link>	
		<description>&lt;em&gt;&lt;strong&gt;Vorteks:&lt;/strong&gt; Plus you have to remember that most debit cards/ATM cards are automatically deactivated after 3 or so incorrect PIN entries. So even if every card in the world had one of those 20 combinations, the chances of correctly guessing the pin before the card was locked down would only be 3 in 20, or 15%.
&lt;/em&gt;
Right, but 15% is a really high number!  Given that bank cards are relatively easy to steal  (you can pickpocket wallets or install skimmers on ATMs or at restaurants),  you only need to get twenty or so before you could be 90% confident that you&apos;d be able to access one of them by guessing its PIN.   That seems like a pretty low barrier to me.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575094</guid>
		<pubDate>Wed, 19 Sep 2012 21:22:22 -0800</pubDate>
		<dc:creator>Popular Ethics</dc:creator>
	</item>	<item>
		<title>By: symbioid</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575095</link>	
		<description>Oh man, I remember thinking about using O, D, Q and 0 on a license plate like the xkcd cartoon.  Of course, his point never occurred to, but I guess that&apos;s why he&apos;s the genius that makes XKCD and I&apos;m the shchlub who makes comments on metafilter.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575095</guid>
		<pubDate>Wed, 19 Sep 2012 21:22:42 -0800</pubDate>
		<dc:creator>symbioid</dc:creator>
	</item>	<item>
		<title>By: nebulawindphone</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575097</link>	
		<description>It sort of irks my inner nerdy 12-year-old too, since it&apos;s not the particular sequence of digits I went and memorized, but actually yeah if you needed ten significant figures for some real application you&apos;d round it instead of just truncating.  

I know.  The world is a terrible, ugly place.  It&apos;ll be okay.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575097</guid>
		<pubDate>Wed, 19 Sep 2012 21:23:57 -0800</pubDate>
		<dc:creator>nebulawindphone</dc:creator>
	</item>	<item>
		<title>By: Mitheral</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575150</link>	
		<description>This research is nonsense mostly because of this:&lt;blockquote&gt;By combining the exposed password databases I&apos;ve encountered, and filtering the results to just those rows that are exactly four digits long [0-9] the output is a database of all the four digit character combinations that people have used as their account passwords.

Given that users have a free choice for their password, if users select a four digit password to their online account, it&apos;s not a stretch to use this as a proxy for four digit PIN codes.&lt;/blockquote&gt;The second statement doesn&apos;t follow from the first.  I must have used passwords like 1234 and 6666 hundreds of times in the last fifteen years on sites that either required a password for no reason or on sites I had zip, zero, nada intention of ever visiting again.   So if the some newspaper in Wastewater Idaho wants me to register to read an article I&apos;m more than happy to let them know I&apos;m Elvis Presely at 123 Anywhere Street, Yourtown USA 90210 and give them a password of 1234.  And these are just the sort of backwaters that are likely to a) store passwords in plain text and b) have have poor security of that plain text file.  

That doesn&apos;t apply to my bank pin in any way though I don&apos;t doubt there are lots of 1234 sorts of ATM pins floating around. 

&lt;b&gt;Harpocrates&lt;/b&gt; &lt;a href=&apos;http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574402&apos;&gt;writes&lt;/a&gt;  &lt;em&gt;&quot;I find that pins I set using a phone or at a bank are different than numerical pins on a pc due to the different keypad configurations. (Why do keyboard number pads have a orientation anyway? )&quot;&lt;/em&gt;

Because IBM made business machines IE: calculators and not phones.  I&apos;ve often wondered why AT&amp;amp;T didn&apos;t make the touch tone phone pad with the same layout as calculator pads. Probably an epic &lt;a href=&quot;http://en.wikipedia.org/wiki/Endianness&quot;&gt;Big Endian/Little Endian&lt;/a&gt; story in the choice.

&lt;b&gt;Ike_Arumba&lt;/b&gt; &lt;a href=&apos;http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4574741&apos;&gt;writes&lt;/a&gt;  &lt;em&gt;&quot;That, plus: what ATMs have 5-digit PINs? Aren&apos;t they nearly all 4-digit? Or should I say, back in &apos;91-ish when that Seinfeld episode aired?? This has always bothered me tremendously... makes no sense.&quot;&lt;/em&gt;

I&apos;ve had a six digit pin (not the same one all the time) since my first debit card way back in 1987.  At the time I remember thinking have a non standard length in and of itself would be a stumbling block so I asked what the max was (6) and have been using that ever since.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575150</guid>
		<pubDate>Wed, 19 Sep 2012 22:32:45 -0800</pubDate>
		<dc:creator>Mitheral</dc:creator>
	</item>	<item>
		<title>By: IndigoRain</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575340</link>	
		<description>If you&apos;re using a 4-digit PIN to lock your iPhone (which likely contains social networking data, financial data, private photos, etc) you should know &lt;a href=&quot;http://lifehacker.com/5914602/this-is-how-you-should-secure-your-iphone&quot;&gt;there&apos;s a way you can use an alphanumeric password instead&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575340</guid>
		<pubDate>Thu, 20 Sep 2012 05:13:06 -0800</pubDate>
		<dc:creator>IndigoRain</dc:creator>
	</item>	<item>
		<title>By: Beardman</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575512</link>	
		<description>Everybody with 8068 is really choked right now.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575512</guid>
		<pubDate>Thu, 20 Sep 2012 06:51:45 -0800</pubDate>
		<dc:creator>Beardman</dc:creator>
	</item>	<item>
		<title>By: Hactar</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575785</link>	
		<description>Hardest PIN to guess: the last 4 digits of Pi.

I&apos;m surprised that more people don&apos;t use the last 4 of their phone numbers.  We had to ban that where I worked for an app the requires a PIN and not a password.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575785</guid>
		<pubDate>Thu, 20 Sep 2012 08:28:30 -0800</pubDate>
		<dc:creator>Hactar</dc:creator>
	</item>	<item>
		<title>By: jaduncan</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4575965</link>	
		<description>&lt;em&gt;I&apos;m surprised that more people don&apos;t use the last 4 of their phone numbers. We had to ban that where I worked for an app the requires a PIN and not a password.&lt;/em&gt;

They almost certainly do, but that&apos;s a social engineering attack that depends on knowing the person. Because those source numbers are relatively random they aren&apos;t going to show up on a table of the most used codes.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4575965</guid>
		<pubDate>Thu, 20 Sep 2012 09:37:28 -0800</pubDate>
		<dc:creator>jaduncan</dc:creator>
	</item>	<item>
		<title>By: desjardins</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4576055</link>	
		<description>&lt;em&gt;I&apos;m glad you&apos;re not from California, where a 5150 is a 72-hour involuntary psychiatric hold. &lt;/em&gt;

Um, that&apos;s why they named the album 5150.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4576055</guid>
		<pubDate>Thu, 20 Sep 2012 10:07:42 -0800</pubDate>
		<dc:creator>desjardins</dc:creator>
	</item>	<item>
		<title>By: benito.strauss</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4576111</link>	
		<description>Learn something new every day.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4576111</guid>
		<pubDate>Thu, 20 Sep 2012 10:34:48 -0800</pubDate>
		<dc:creator>benito.strauss</dc:creator>
	</item>	<item>
		<title>By: delmoi</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4576144</link>	
		<description>&lt;blockquote&gt;&lt;i&gt;As in why are they different? Because one was based on the layout of calculators and the other on rotary phones.&lt;/i&gt;&lt;/blockquote&gt;
There&apos;s a common urban legend that ATT made phone pads &quot;upside down&quot; to slow people who were good at 10-key entry so they wouldn&apos;t overload the system or whatever.  But apparently what actually happened is that they tested a bunch of different designs and it turned out that the current configuration was easiest for people to learn.

They also asked some calculator people why they did the numbers the other way around, and apparently there wasn&apos;t actually any particular reason.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4576144</guid>
		<pubDate>Thu, 20 Sep 2012 10:50:17 -0800</pubDate>
		<dc:creator>delmoi</dc:creator>
	</item>	<item>
		<title>By: eotvos</title>
		<link>http://www.metafilter.com/120076/And-change-the-combination-on-my-luggage#4576956</link>	
		<description>&quot;e=mc2**&quot; is on a password list? Huh?  Some sort of strange RPN exponentiation?  That seems like mighty obscure syntax, compared to, say, e=mc**2, which isn&apos;t on the list.

Interesting article, if one ignores the bogus logic relating this to ATM PINs and reads it as a study of numeric passwords on a low-stakes website.

Also, Hactar, who&apos;s to say there aren&apos;t many phone numbers in the list?  The set of phone number suffixes isn&apos;t too different from the set of four digit numbers - you&apos;d be hard pressed to see that in the data, without having correlated lists.</description>
		<guid isPermaLink="false">comment:www.metafilter.com,2012:site.120076-4576956</guid>
		<pubDate>Thu, 20 Sep 2012 17:32:16 -0800</pubDate>
		<dc:creator>eotvos</dc:creator>
	</item>
	</channel>
</rss>
