Most of us carry a handful of PINs and never think about them until a keypad asks. The phone lock screen, the bank card, the garage door, the alarm panel by the front door, the little combination on a gym locker. Each one is a short number standing between a stranger and something you care about, and most were chosen in about four seconds, by typing whatever came to mind first.
Why a short number is weak on its own
A four-digit PIN has exactly 10,000 possible values. That sounds like a lot until you picture someone working through them one after another. With nothing to stop them, a patient person gets through 10,000 codes in a day or two. Six digits gives you a million possibilities. Eight gives you a hundred million. Every digit you add makes the job ten times longer.
But the length is only half the story. The other half is how many wrong guesses the system allows before it shuts the door.
Where the guess limit protects you, and where it doesn't
Your phone and your bank card punish wrong guesses. Delays grow, cards get blocked, and nobody can sit there trying ten thousand codes. In that setting a 4 or 6 digit PIN is a fair trade for convenience, because the lock does most of the work. Plenty of other devices are far less forgiving:
- Alarm panels and door keypads. Some lock out, some don't. If you can't confirm it, assume they don't and use 6 to 8 digits.
- Safes and lockboxes. Anyone with physical access and time can keep trying. Go long.
- Router or camera admin PINs. These sit on your network all day. If you're setting up a router, the WiFi password generator covers the network key and where to enter it.
What people pick when nobody's watching
Analyses of leaked PIN lists keep finding the same thing: a small set of codes, led by 1234, covers a startling share of everything people choose. Then come repeats like 0000 and 1111, the keypad line 2580, and years. Birthdays are the worst of the lot. A date written as month and day has at most 366 values, and it's printed on half the documents in your wallet.
So this generator does two small things. It skips any PIN made of one repeated digit, like 0000 or 7777, and any straight run like 1234 or 4321. On a four-digit PIN that removes just 24 of the 10,000 possible codes, so it barely touches the strength. It only keeps the very first guesses off your list. Everything else is random. A code like 2580 or 1971 can still appear, purely by chance, and no more often than any other.
The keypad gives more away than you'd think
A keypad that's used every day wears unevenly. Greasy or faded keys show which digits get pressed, and sometimes a thermal camera can show it for a moment after. If your PIN uses four different digits and someone can see which four, only 24 orders are left to try. A longer PIN gives that trick a lot more to work through. Wiping the pad now and then doesn't hurt either.
One PIN per lock
It's tempting to use the same number for the phone, the alarm and the safe. Don't. Each one lives in a different place with different people around it, and a code the cleaner has seen on the alarm panel shouldn't also open your phone. Generating a fresh PIN for each takes a few seconds. If one gets seen or shared, you change that one and nothing else.
Remembering a random number
Random codes feel impossible to hold in your head, until you use them a few times. Say the digits in pairs, type the PIN a handful of times over the first few days, and it sticks. For something you touch once a year, like a safe, it's fine to write the code down as long as the note lives somewhere separate from the thing it opens. A note taped to the safe defeats the point. A note in your password manager, or in a sealed envelope elsewhere, does not.
If you already use a manager, protect that with something you can type from memory, and a passphrase is usually the better fit than any number.
When a PIN is the wrong tool
Numbers are for keypads and lock screens with a guess limit. They aren't for anything reachable over the internet, where an attacker can try codes as fast as a computer allows. For online accounts you want a proper password. The main password generator builds one in a click, and the strong password guide explains what length and randomness actually buy you. If a site insists on exactly 12 or 15 characters, the 12 and 15 character generator has that covered.
A few examples where people get this wrong:
- Using a PIN as the only protection on an email account, which is the recovery path for everything else you own.
- Treating the app-lock PIN on a social app as a substitute for a real login. A Facebook or social media password still needs to be long and unique.
- Sharing a home PIN with guests. A guest WiFi password is easier to hand over as a QR code than a number read aloud.
- Using a PIN as an API key or a coupon code. For anything a machine will check, the random string generator is built for it.
Using this generator
Drag the slider to pick 4 to 8 digits and a PIN appears straight away. Press Generate for another, or Copy to send it to your clipboard. The digits come from your browser's built-in secure random source and are picked one at a time, so nothing about the last PIN affects the next. Choose the length by what you're protecting: 4 or 6 where the device limits guesses, 6 to 8 where it doesn't. Then keep it apart from your other codes and let it be a number you never had to think up.