A 4-digit PIN has 10,000 combinations. On paper that's trivially breakable. In practice, with two compounding defenses, it becomes one of the most cost-effective auth choices for solo apps. The math is worth doing once.
Three brute-force modes
| Mode | How fast | How to defeat |
|---|---|---|
| Offline (hash leak) | SHA256: ~10⁹ guesses/sec/GPU → 4 digits in microseconds | Bcrypt at cost 12: ~6 guesses/sec/core → 4 digits in ~30 minutes |
| Online, no lockout | HTTP request rate — maybe 100/sec over Tailscale → 4 digits in ~2 minutes | Rate limit + lockout (this track) |
| Online, lockout-after-5 | 5 attempts then blacklist → effectively unbreakable for an opportunistic attacker | This is the goal |
What 5-digit buys you
| PIN length | Combinations | UX cost | Marginal security gain (with lockout) |
|---|---|---|---|
| 4 | 10,000 | Baseline (fast) | Baseline |
| 5 | 100,000 | +1 keystroke | 10x better online; insignificant offline at bcrypt cost 12 |
| 6 | 1,000,000 | +2 keystrokes | 100x better; only matters if lockout fails |
| 8 | 100,000,000 | +4 keystrokes; people start fumbling | Diminishing returns at this point |