• Monument@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    4
    ·
    1 day ago

    …. Oh!

    You just explained a question I had.
    I couldn’t figure out why a pin was considered more secure.

    In my reasoning: How is a PIN (potentially numeric only), changed 1x a year, safer than a password (3 of 4: Alpha, Mixed case, numeric, special chars), changed 4x a year.

    The answer, as you explained, is scope of trust. Machine only vs tenant-wide. That makes sense.

    • tux7350@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      24 hours ago

      Windows Hello ties the PIN to the TPM of the computer. It’s not just you having a pin, its the pin + the crypto secret loaded on the device. Thats why its more secure then just a complex password.

    • smh@slrpnk.net
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 day ago

      That makes sense. Something you have (that specific machine) + something you know (your pin).

      I used to work someplace where we all had a pin+a smart card that we’d insert into the machine, same idea except I could log into any machine with the card+pin combination.

      Loved not having to remember a long AF password. Didn’t like having to drive home if I forgot my card on the kitchen counter.