That response is quite amusing, to say the least; I certainly laughed. Can the PIN be different from the account password, and different on each Windows device they use? Yes. In practice, will the type of "idiot" (your word, not mine) for whom this
implementation of PIN was designed actually use a different PIN on each device, and set it to be different from their Microsoft Live account password?
No, they will not! You know as well as I do that the "standard idiot" computer user will set the PIN to be the password (because it isn't prevented), use the same one on all his devices (this also is not prevented), and go on with
life. Meanwhile, the keylogger has already gotten that PIN, and you know the first thing its owner will do is to try that PIN against the mark's Hotmail account...
and it'll work. PIN fail.
I recently updated Windows 10 on 2 new machines. Once they finished updating and it was time to create accounts, I was required to enter both a password and a PIN for the account; there was no functional way to bypass either one. I have certainly read this
whole thread (in fact, I've contributed several comments on it); you do have to enter both a PIN and a password when you create a user account.
I do not want the PIN to be required (and at the risk of repeating myself yet again, if it allows alphanumeric content,
it's a password, not a PIN). I use strong passwords on my Microsoft account, along with 2FA. I likewise have a strong local password. I want the alternate password to be optional. Windows forces me to create one, and
will not let me continue with setup until I do so. Windows does not make it user-friendly to switch the login entry from PIN to password, and it seemed to try to sneak itself back to PIN login at least once after a reboot. If I create a dummy PIN,
then go in later and try to remove it, Windows complains, like it's some guy named Guido "suggesting" that I use a PIN, while subtly fondling the club he's going to use on my kneecaps if I don't.
Yes, you don't have to connect the local account with the cloud account. Last time I tried, it took a few mouse clicks and a bit of hunting to find the path to get to that option. Again, the "standard idiot" is not going to go that route, because it won't
connect with his OneDrive store or anything else he has attached to his Microsoft account, and it's a PITA for him to find the other option.
All the way around, it's a marginally useful idea with extremely poor implementation. Is it theoretically more secure?
Maybe. In practice? Not really, no. On balance, it's a waste of time and a huge frustration, and isn't really more secure than a good password and 2FA. Forcing me to create a PIN (which isn't really a PIN), and displaying what
appears to be an option to bypass it but the bypass doesn't work, is a bug, and it needs to be fixed.
A few suggestions:
- Relabel it from PIN (which insinuates it's purely numerical) to something like "local password", "alternate password", etc. Because that's what it really is. A PIN is what you enter at the ATM or the credit card terminal, because those have only a numeric
keypad. If the PIN accepts letters and/or punctuation, it's a password, not a PIN. Label it accordingly.
- Use a single login box, not separate password and PIN boxes. The code can check whether the password entered was the main one (i.e. the same one as the linked Microsoft account) or the alternate.
- If the user is going to create an alternate password, enforce its "alternate-ness". Require it to be different from the cloud account password. Even figure out a way to enforce uniqueness across all the user's devices, if you still think that's necessary.
But it's totally useless if the alternate password can be the same as the Live account password.
- For the love of all that is holy, make the alternate password optional. And quit **** about it if the user decides not to use it. Offer it once, accept the decline, and move on, Windows!