Hacker News new | ask | show | jobs
by brennenHN 4919 days ago
Even in the best case, knowing what the four digits are, there are 24 possible options. We rate limit the PIN to 3 wrong attempts per day, so an attacker would need 8 days to be certain to gain access to an account. It is easy to remotely deactivate the phone from a computer, so the user's accounts will be protected.

That said, this is an area we want to make stronger. Using facial recognition and other, more secure, methods of user identification are on our roadmap as important improvements.

2 comments

Giving a facial imprint is very risky for the user. I think it's wrong to add this to the system and force users to give this information.

Good luck though

If I want to prevent you from accessing your account for at least 24 hours, couldn't I just try to log in as you and intentionally enter an incorrect PIN thrice?

Am I misunderstanding something?

Yes, you have to have the phone, but this is still possible.
Ah, OK. Better than a remote attack for sure.