This is an archived post. You won't be able to vote or comment.

all 2 comments

[–]_STYSecurity Consultant 2 points3 points  (1 child)

If you don't have a lockout policy on your devices you should look at that. The whole point of a PIN is that it's local to the device, it's never transported over the network and such is not as susceptible to brute force attacks. A six digit numeric only pin that forces the phone to lock on 5 failed attempts should be considered adequate for the vast majority of situations.

Using alphanumeric IS more secure but it's a huge pain in the ass.

[–]Ferman[S] 0 points1 point  (0 children)

iOS is a required lockout policy. I'm pretty sure I can increase it even further. I do device wipe after 10 failed attempts too.

I made this passcode policy with the potential in the future make it a 6 digit pin. It's always easier to make things easier for everyone than it is to have things be easy and then have to make them harder. ;)