Skip to main content

Here’s why you should not type in a PIN while wearing a wearable

Apple Watch Wrist
Giuseppe Costantino/Shutterstock
Smartwatches and wearables may be great for alerting you to get on your feet and exercise, but you may not want to wear them when inputting secure PINs, like the one you punch in at the ATM.

A new paper, titled “Friend or Foe?: Your Wearable Devices Reveal Your Personal PIN,” shows that deciphering someone’s PIN isn’t that hard, though the paper doesn’t dive into the specific wearables that were used.

Related Videos

Written by researchers at the Stevens Institute of Technology and Binghamton University, the paper reveals that attackers can track the millimeter-level distances and directions of hand movements thanks to embedded sensors like accelerometers, gyroscopes, and magnetometers, in the wearable device. By tracking your exact movements, researchers were able to “derive the moving distance” of a person’s hand between key entries on key-based systems like a keyboard or ATM.

They successfully reverse-engineered the wearable’s sensors to track a person’s hand movements to see the PIN that was entered — that method is called the “Backward PIN-Sequence Inference algorithm.” The group tested more than 5,000 key-entry traces from 20 adults with different kinds of wearables. The technique provided an accuracy of 80 percent on one try, and that jumped to 90 percent with three tries.

Attackers can use this method in two ways — by installing malware directly onto the device, or by grabbing the data via the Bluetooth connection that bridges the wearable to the smartphone, according to

It all sounds awfully simple, but researchers do offer a solution to manufacturers and developers — insert some “noise data” to obscure the sensitive data. This solution sounds incredibly similar to differential privacy — a tool Apple is using in iOS 10 to make data-gathering more secure and anonymous. Google has also been using this technique in its Chrome browser for years.

We have reached out to the group to check which devices they tested with, but in the meantime, perhaps you should take off your wearable before you enter your secure PINs.

Updated on 07-07-2016 by Julian Chokkattu: Clarified that attackers use tracking data from the wearable to decipher PINs typed on physical key-based systems.

[amz_nsa_keyword keyword=”Portable VPN”]

Editors' Recommendations

Does the Samsung Galaxy A54 have a headphone jack?
The top edge of the Galaxy A54.

The Samsung Galaxy A54 is Samsung's budget flagship that's a solid pick for anyone looking to get the best the company has to offer without breaking the bank. Every time a new smartphone like the Galaxy A54 launches, it can feel like questions about the phone's technical specs take up the majority of the conversation. The hardware features are equally as important since they're the things that prospective buyers will be physically interacting with when using the phone.

When it comes to frequently asked hardware questions, questions about 3.5mm headphone jacks are usually the ones asked most often. Although much of the world has moved on to relying primarily on wireless headphones, there are still those who use wired headphones as their main way of consuming audio content. Most major flagships have dropped headphone jacks entirely, but there's a devoted group of budget devices that still feature them for headphone users who prefer wired connections. Here's what you need to know about the Galaxy A54's audio options and if it has a headphone jack.
The Samsung Galaxy A54 doesn't have a headphone jack

Read more
The Huawei Watch Ultimate looks like the perfect Apple Watch Ultra rival
The Huawei Watch Ultimate in Voyage Blue and Expedition Black themes.

See if you can guess which smartwatch Huawei wants to take on with its latest release. It’s called the Huawei Watch Ultimate, and it’s made to appeal to outdoorsy types, complete with comprehensive diving and expedition modes.

It has a really big screen and a big battery too. That’s right, the Huawei Watch Ultimate is an Apple Watch Ultra competitor — but don’t pass it by just yet, because it’s worth your attention.

Read more
Samsung Galaxy Watch 6: the 6 things that would make it amazing
The Galaxy Watch 5 Pro showing a colorful watch face.

Samsung’s 2023 product lineup has turned out pretty impressive so far, but the more promising devices are scheduled for the latter half of the year. Among them is the Galaxy Watch 6 series. Now, the Galaxy Watch 5 line-up isn’t bad by any stretch of the imagination, but it also wasn’t really an appealing upgrade over the Galaxy Watch 4 portfolio.

With the Galaxy Watch 6 series, we’re already hearing some promising chatter in the leak land. Here’s a wish list of changes that would make the Galaxy Watch 6 series a truly tantalizing and potent alternative to the venerable Apple Watch.
Bring back the rotating bezel
Galaxy Watch 4 Andy Boxall/Digital Trends

Read more