3 ms·
> Passcodes are vulnerable to shoulder surfers My home door lock has a pretty cool way to counteract this. Here's a picture of what it looks like https://www
by arcastroe 2y ago
> Passcodes are vulnerable to shoulder surfers
My home door lock has a pretty cool way to counteract this.
Here's a picture of what it looks like
https://www.digitaltrends.com/wp-content/uploads/2021/07/lockly-duo-smart-lock-lifestyle-2.jpg https://www.digitaltrends.com/wp-content/uploads/2021/07/loc...
Every time you press a button, all the numbers shuffle around. Even if someone watches you enter the passcode, they can't be certain of what the password actually was.
They do gain some information (the first digit must be either a two, a six, or a nine), but they don't get the full information.
- swores 2y agoHaving had a bank that did something similar for logging onto their mobile app, annoyance at that feature was the main reason I moved to a different bank. Do you not have the problem I had that the moving around of numbers makes it impossible to use muscle memory and you always need to think about each digit, or do you just have more patience than me and not mind? Maybe the bank's version on my phone was particularly bad and the interface on your lock particularly good? (It was almost a decade ago, I can't actually remember exactly what it looked like / how it worked, just how frustrating it was.)
- rustcleaner 2y ago>or do you just have more patience than me and not mind? This is the case for me (GrapheneOS), and I wouldn't be surprised if it is the case for the GP too...
- exe34 2y agoI completely forgot the pin to a bank card I haven't used in a long while. It occurred to me that humans are mostly just next token predictors anyway, so I pretended I knew the pin, and just got the little machine out, went to my bank page, and started logging in, and when it came the time to type my pin into the machine to get the one time code, I simply remembered the pin while my fingers typed them in.
- cykros 2y agoStandard practice from Old School Runescape as well as Ragnarok Online for pin entry. Always was annoying to have a relatively unimportant account like those more protected than bank accounts were at the time.
- extraduder_ire 2y agoOSRS also encourages everyone to enable 2fa by tying it to a quest that gives you 10k ingame currency. I assume they are so serious about security because it would generate a lot of work for support, and people are constantly trying to scam each other and hack accounts. Plus, they don't have the luxury of locking the whole account until you go into your bank in person.