- The study analyzed the security of 4-digit and 6-digit PINs used for smartphone unlocking against a throttled attacker with up to 100 guesses.
- It found that 6-digit PINs provided little to no increase in security compared to 4-digit PINs against such an attacker. Despite having more possible combinations, user-chosen 6-digit PINs were also highly predictable.
- The presence of blocklists, which warn users about easy-to-guess PINs, increased the security of 4-digit PIN distributions but had limited effectiveness against a throttled attacker, even when the blocklist was enforced.