C.W.K.
Stream
Lesson 01 of 05 · published

The Math — Why 4-Digit PINs Are Defensible

~15 min · bcrypt, math, pin-length

Level 0Greenhorn
0 XP0/53 lessons0/14 achievements
0/100 XP to next level100 XP to go0% complete

A 4-digit PIN has 10,000 combinations. On paper that's trivially breakable. In practice, with two compounding defenses, it becomes one of the most cost-effective auth choices for solo apps. The math is worth doing once.

Three brute-force modes

ModeHow fastHow to defeat
Offline (hash leak)SHA256: ~10⁹ guesses/sec/GPU → 4 digits in microsecondsBcrypt at cost 12: ~6 guesses/sec/core → 4 digits in ~30 minutes
Online, no lockoutHTTP request rate — maybe 100/sec over Tailscale → 4 digits in ~2 minutesRate limit + lockout (this track)
Online, lockout-after-55 attempts then blacklist → effectively unbreakable for an opportunistic attackerThis is the goal

What 5-digit buys you

PIN lengthCombinationsUX costMarginal security gain (with lockout)
410,000Baseline (fast)Baseline
5100,000+1 keystroke10x better online; insignificant offline at bcrypt cost 12
61,000,000+2 keystrokes100x better; only matters if lockout fails
8100,000,000+4 keystrokes; people start fumblingDiminishing returns at this point

External links

Exercise

On your dev machine, time python -c "import bcrypt; bcrypt.hashpw(b'1234', bcrypt.gensalt(rounds=12))". The wall-clock time is your per-guess cost. Multiply by 10,000 — that's roughly the offline crack time for a 4-digit PIN if a hash leaks. Decide whether your cost factor is right for your hardware.

Progress

Progress is local-only — sign in to sync across devices.
Spotted a bug or have feedback on this page?Report an Issue

Comments 0

🔔 Reply notifications (sign in)
Sign inPlease sign in to comment.

No comments yet — be the first.