Hacker News new | ask | show | jobs
by umsm 4140 days ago
> having the ability to verify a PIN and the ability to reset the ‘tries’ counter, one can trivially check every possible PIN automatically until the correct PIN is found.

This is the key part for me. Being able to brute-force a pin is a huge vulnerability.