British financial services firm Intelligent Environments caused a stir last week when it announced that it would let its customers use emoji passcodes to log into their accounts. The company launched the system after their study found that emoji passwords are both simpler and more secure than numbered ones. IE says their research shows that a third of Britons have forgotten their bank PIN numbers in the past, and one in four use the same password for all their accounts—it would in theory be easier to remember different combinations of emoji.
The conventional 10-digit number code is also vulnerable to security threats— it only allows for 7,290 possible combinations. But IE’s emoji passwords, which make users choose four emoji out of a possible 44, allow for 3,498,308 unique permutations.
IE’s system is tailored to the changing tastes of twentysomethings—64 percent of them routinely use emoji, according to Tech Times.
“If anything, it’s a marketing move catered to millennials,” Erik Cabetas, managing partner at Include Security, a Brooklyn consulting firm, told the Observer in an email.
Mr. Cabetas outlined several other reasons why U.S. banks should not start converting their 360,000 ATMs to emoji just yet. There are three main issues with the system:
- You can guard a PIN number from view when entering it into a physical ATM, but if you’re selecting emojis from a touch screen then that isn’t as easy.
- With a PIN number you can verify over the phone.
- Both emoji and PIN numbers will fall into the same pattern of use—”1234″ will become “top row of emojis left to right.”
While Mr. Cabetas admitted that an emoji system would provide more options, he said that did not mean that the system was more secure.