Home
A note on the Security Aspects of Alpha PIN Assignments

Alpha PINs may be of particular value when associated with self-selected PINs. The case for the use of alpha is that it helps users to remember longer PINs. The case against is that words involve less randomness in their use of the keys than is the case with numeric PINs, and also that a PIN remembered as a word will employ only eight of the ten available digits.

Hence issuers encouraging their cardholders to use alpha to help remember their self selected PINs, may wish to persuade them to think in terms of a mnemonic (using the first letters of the words in a sentence or phrase), rather than as a specific word. In addition it is recommended in ISO 9564-1 (2002), Section 7.1 that, for security reasons, a customerselected alpha PIN should be not less than six characters.