PHP Client PIN Security

I am currently developing a system that has functionality where customers can view information about their purchases / renewals / etc by supplying a PIN code "number".

Instead of the login data, a PIN is used due to the type of customers we are targeting. The PIN is printed on documents sent to them.

The view displayed when submitting the PIN code does not display highly sensitive information, such as a credit card, etc., but less sensitive, such as the name of the product, type, price, barcode, repair, etc.

This question is about PIN. I decided to use a random 5-character PIN (0-9, az AZ) - case sensitive. I will delete some homoglyphs ('I', '1', 'l', '0', 'O', 'rn', 'vv'), so the actual number of combinations is actually lower.

I have a few questions about this:

  • Is this practice acceptable?
  • Do I have to write a blocking mechanism to “block” traffic from IP addresses with a lot of failed attempts? *
  • Do I have to write an error checking system (similar to Luhn algo in credit card numbers)?
  • * Should I use captcha?
+5
source share
6 answers

, PIN-, - , , , , ZIP-. , - " ".

, , , "" . , IP - IP-.

- "tar-", , , . . PIN-.

+1

CAPTCHA - CAPTCHA 1) , CAPTCHA 2) : , sleep 1 , 2 , 4s , 8 . , . , , - .

- 6- , .

, - - , " lolcats" - , ( , , , : " , - ?" ).

+1

PIN- - , . PIN- , .

, , . , , . , ? , PIN-, openID (LightOpenID). Google OpenID, "". , . Google captcha ( "" ).

?

, , .

"" IP- ? *

, , , PIN- - . , IP, , . , - . HashCash stackoverflow.com, . , , .

? ( Luhn algo in )?

.

captcha?

- CAPTCHA, , . Google/Twitter/ .. CAPTCHA, , . PIN- OpenID Google, , Google .

+1

1) , . 2) , - , , IP-. 3) ? , ? 4) captcha.

0
  • , , , , - , .
  • , , , , , , NAT, ip (, , , fastweb, ip ), ip (15-30 3-5 enoght, , , ) , , , .
  • , , ,
  • , - : " 2 =" " ?", , .

mt_rand() ( , , php ),

 AXV2-X342-3420

, , .

, , , , .

0

" , , .

5- [0-9, AZ, az] 8,27 ( 64 310= 2 ^ n), []

(1000 /, ), . ? , , .

"" IP- ?

IP- .

( Luhn algo )?

, .

captcha?

, . Captchas , .

Update

, , - (?) . , : ", - ... , ", .

. , . , .

- . :

  • ( ) ( )
  • : ? Visa? , . Bob Bicycle Shop , , .

, , "". , ? *, .

* , , .

0

All Articles