Hacker News new | ask | show | jobs
by al_borland 112 days ago
But a 4 digit PIN with unlimited retries can be brute forced.

Replacing a password with a 4 digit PIN is less secure. If a user wanted a 4 character password, they’d make a 4 character password. Forcing the creation doesn’t make much sense on a desktop.