In the News
Simplicity in PIN security can only be a negative. In Comcast set Xfinity Mobile PINs to ‘0000’ by default, leaving customers vulnerable to hacks, Shannon Liao at The Verge discusses the repercussions of having default pins set to simple ‘0000’. Liao explains that by setting default PINS on XFINITY Mobile accounts, individuals have reported that their phone number and attached credit card information has been ported. Liao elaborates that Comcast has addressed the issue, but has yet to explain why unique PINs were not immediately assigned as a default instead of a universal ‘0000’ PIN.
Our Take
Account security is a prominent concern regarding maintaining the general privacy of user information. For many types of accounts, enabling multi-factor authentication and creating unique passwords are two of the most effective ways to protect your account and its contents from exposure. However, PINs have become an increasing popular method for account access. Such PINs are typically a short combination of numbers, yet the complexity of the number arrangement provides the necessary security defense for your account. When default PINs such as ‘0000’ are universally enabled, user’s accounts are left vulnerable until the PIN is manually changed. If these PINs were assigned randomly, giving users a unique default PIN, this gap of account protection would be eliminated. Eliminating such a vulnerability gap is crucial mainly because many individuals fail to alter the default PIN or password provided to them once an account is created.
Recommendations
How can you protect your personal and financial information from theft?
- Immediately change a default PIN to a more unique and confidential one
- Use safe password practices, and take advantage of Multi-factor Authentication where possible
- Limit the number of accounts and platforms that store your financial payment information
- Check your email, financial accounts, and credit reports regularly for abnormal activities
- Stay up to date on the news regarding recent fraud and phishing attacks to see if you may have been affected