Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Corporate email profiles on BYOD phones often enforce a long passcode requirement, so you've got a lot of Fortune 500 sales guys to screen out if you're stopping and searching anybody with a suspiciously long password.


I'm at a loss as to how alphabet agency can determine a weak passcode vs strong passcode was used. how does a pin get stored on the phone? surely, not plain text of a 4 digit pin. if they do any encryption to the 4 digit pin, how would it appear any different than a significantly stronger passcode?


The grandparent post was about determining the complexity of a PIN/Passcode by watching it being entered - more screen interaction = more complex.


It uses a different screen. If you have a 4 digit pin, the entry screen looks a lot like the phone dialer, with the numbers 0-9.

If you have a stronger passcode, you see a full keyboard instead.


The prompt is different based on the type of code you use.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: