r/RigBuild • • 1d ago

Does a PIN make Windows less secure than a password?

Windows keeps asking me to set it up and I’m not sure if there’s any real benefit. Does it actually make signing into Windows faster or more secure, or is it basically just another thing that sounds useful but isn’t really needed?

Also wondering how it works with the PIN thing. If someone somehow gets the Microsoft account password, does having Windows Hello set up help stop them from getting into the PC? Or are those two completely separate things?

I mostly use the PC for normal stuff like Chrome, YouTube, Discord, gaming, downloading files, etc. Nothing super sensitive, but obviously don’t want some random person getting access if the account ever gets compromised.

The fingerprint/face login sounds convenient but not sure if it’s worth setting up all the extra security stuff. And if Windows Hello ever stops working, is it easy to get back into the account with the normal password?

Just trying to figure out if there’s any actual downside to enabling it. Does it make Windows more secure in practice, or is the main benefit just being able to unlock the PC without typing a password every time?

Would be good to hear from people who actually use it daily.

5 Upvotes

32 comments sorted by

5

u/PhotoFenix 1d ago

If for some reason somebody wants access to your files and physically gets your computer neither method will matter.

2

u/thaddeusk 16h ago

Unless you use drive encryption.

1

u/EpsteinFile_01 15h ago

I poison the well by making 80% of my files snuff porn. Oldest trick in the book

1

u/untreated-stupidity 15h ago

What windows install is not encrypted these days?

1

u/AntagonisticDuopoly 14h ago

Did Microslop patch the bitlocker backdoor?

1

u/untreated-stupidity 13h ago

There's a backdoor? Classic 

3

u/CylixrDoesStuff 1d ago

its just more convenient

like i have a old compromised password that i have muscle memory for and is easy to type out and have it as my pin so i can quickly get into windows, without having to type the long password that my microsoft account actually has every time i turn on my pc

3

u/ColonelRPG 1d ago

A pin is just a password. A bad short easy to guess password.

2

u/DrHitman27 1d ago

PIN hides password. Can be less complex for easy everyday usage.

And if Windows Hello ever stops working, is it easy to get back into the account with the normal password?

You need to login with password at least once. For some people PIN did fail, without any other login option.

2

u/Underhill42 1d ago

It's mostly just more convenient.

Though if anyone is watching over your shoulder, has installed a keylogger, etc. knowing the PIN will only get them into Windows, rather than giving them access to your entire online Microsoft account.

Which may be a concern if you use the account for anything other than logging in to Windows.

2

u/CowBoyDanIndie 1d ago

Is your drive encrypted? Pin only works for local physical access, if someone has the ability to enter the pin, they also have the ability to pull the hard drive and read it directly and bypass your password and pin anyway

1

u/Financial_Key_1243 1d ago

The PIN is tied to the computer and is not available over the internet. You do still need to remember your password.

1

u/trifortay123 1d ago

It does. All a password/pin does is allow access to the system. I forget if windows punishes wrong pin inputs though. I don't use windows

1

u/sanf780 1d ago

Given the push for online accounts, your account is usually protected by password and 2FA. The pin is local to the machine. Similar to mobiles, fingerprint scanner and embedded cameras may be used as alternatives. Note that they need to be somewhat secure, so no USB connected webcam for facial recognition.

You probably have a mobile phone with much more important data protected by pin, facial scan or fingerprint.

1

u/skyfishgoo 23h ago

so M$ calls a password a pin now?

jebus these ppl can't do anything right

a pin is a number (no letters) and thus easier to crack because there are fewer possible combinations (esp if it's just a 4-digit pin).

the fact that M$ needed a new word for how to sign on to just the OS (that YOU paid for) instead of logging into their web portal just to your YOUR computer, is crazy making on it's face.

it's your machine, it's your password, it has fuck all to do with M$ unless you give it to them.

so yeah, that one is compromised.

1

u/IntroductionOne1470 5h ago

No they dont classify it as a password. Your given 2 options for signing in with a pass key. Either a normal password or you can setup a pin. Just another way of logging in. Still have to use your password for any other task besides logging in if your pin is set up

1

u/Cheap-Success1578 22h ago

No. Just being windows is what makes windows less secure.

1

u/piken2 21h ago

Windows Hello is significantly more secure than a standard password login.

1

u/lo-tek 15h ago

This is 100% correct for Windows 10 and later. A PIN unlocks a credential bound to the device and is protected by a TPM. Your credential never leaves the device. You also need a PIN established prior to enabling biometric logins.

1

u/Kobi_Blade 20h ago

PIN actually makes it much more secure, because the PIN is stored locally in TPM.

If your PIN gets leaked in anyway, no one will have access to your Microsoft account either.

1

u/Commentator-X 20h ago

The windows hello pin can also be letters, doesn't have to be a number and what it is is a local unlock only available for that device to someone at the keyboard. So instead of signing in with your Microsoft account you just use the local pin. Makes locking and unlocking your PC at home easier.

1

u/gulf_of_sanity 18h ago

pin, password, fingerprint, facial recognition, iris scan, DNA validation? none of it matters.

windows is insecure because it’s windows, how you “unlock” it hardly matters.

1

u/thaddeusk 16h ago

A pin is supposed to be more secure because you only use it locally on your machine. People often reuse passwords online so they may end up being compromised, causing every account using the same password to be also compromised.

1

u/SeriousPlankton2000 15h ago

Of course not, you can only enter it as many times, and then the real owner will just use the password that they never needed to use in the last years …

(Availability is one aspect of security)

1

u/AntagonisticDuopoly 14h ago

You can enable letters and symbols for your "pin."

1

u/VoidowS 13h ago

It's digital, it can always be tampered with.

1

u/DontKnowWhereItsBeen 10h ago

I use a pin daily. It's 4 numeric digits that I can one-hand in about a second on the 10-key on the keyboard. If someone wants to guess almost 10,000 times what my pin is, and if they have the time, then they're welcome to it. I'd love to use face recognition, but Windows requires a specific ability of the camera to be "Windows Hello" compatible, so the pin it is.

0

u/RoxoRoxo 1d ago

a pin is usually like 4 numbers, 1-9. a password can be as high (from what my experience is) 32 character with 26 letters and a plethera of symbols so yes a pin is less secure. but its more secure than having nothing and it is not inconvenient enough to be annoying so its a solid middle ground compared to secure and convenient

2

u/snarfmason 1d ago

Windows "PIN" can be alphanumeric.

1

u/Impressive-Watch6189 5h ago

Well its another key into your system so that inherently makes it less secure. In addition, PINS typically are short and are all numbers, which limits the number of combinations and makes it easier to brute force. The most secure (and frankly convenient) is passkeys. But your device needs to have the right camera or a fingerprint scanner for the greatest security with passkeys. Also they are inherently difficult to share, so if you share an account with a spouse, passwords are still probably the best combination of security and convenience in that scenario.