IHG Finally Ditches PINs In Favor Of Passwords
ed Four Digit PINs Historically IHG Rewards Club has only allowed members to use four digit PINs to secure their accounts, and not longer passwords. It's one thing to give people the option of choosing four digit PINs (which is bad enough), but to not give people any other options is mind-boggling. IHG Rewards Club…
Continue reading: IHG Finally Ditches PINs In Favor Of Passwords
Share your questions, experiences, and thoughts below.
Great, I'm changing my PIN to a password right now.
Wait... I need my PIN for that, and I don't remember it. Need to find it in my mail. Never mind.
Good riddance, those PINs. Although passwords are better, these requirements are absolute BS - mostly security theatre. As always, xkcd explains it best: https://xkcd.com/936/
I had mine hacked a few years ago. Honestly didn’t mind it. They wiped out 100k plus miles, but it was a quick phone call and about 1 week to restore (granted, I didn’t have any travel scheduled for that time). The upside was that since I had the Chase card, I ended up getting the 10% bonus from their fraudulent redemption.
I totally appreciated the ease of IHG login. Here again we've lost because simpletons lost their way.
The fact IHG has kept 4-digit PINs until now makes me wonder what other parts of their IT systems are old and/or weak.
The most basic thing that will make a password more secure is length. The longer it is, the harder to crack. Four digits is child's play. Remember, this is the same company that used to ask you for your SSN to sign up and used it as your member number. I gave them a fake number but many people, I'm sure, handed over the real thing in the '90s.
Apparently they are slowly learning. However to @fortytwo's point, the requirements are stupid. Long, memorable but not easily guessable and not in the dictionary. That's what you need. Forget all the other BS. And 2FA is better. There are exploits that hackers can use, but it's harder than not using it. And it's better if you get the second factor from an app than to have it sent to your phone.
That’s good news. I have passwords across hundreds of accounts for various things. This was literally the only one my password manager yelled at me about. Immediately changed it to a random 20 character password.
You know Qantas still use pins??? To change it you get the following message ;Your new PIN must be four numbers only, not letters, and all four numbers cannot be the same (e.g. 1111). To be fair if you try to update your profile they do have 2FA. I would love to be proven wrong on the PIN but can not see an option to put in a decent password
pin and password are not much different these days. keyloggers and account data breaches make using pin and password pointless. Some level of 2FA is required these days, be it sms or authenticator or physical U2F keys (sms being the worst)
The new IHG app on Android no longer allows me to log in, from my PC at home everything works. Has anyone else had the same problem?
