← Back to context

Comment by yodelshady

3 months ago

I've received the same PIN from an entirely different gym chain, albeit one using the same door system.

As you say, a massive red flag indicating it's not using a lot of sources of entropy.

What worries me the most is that if the ACS can't issue new PINs, there's no way to replace them. If a single PIN is shared or compromised, anyone with it can walk in undetected until the whole system is replaced. And if the entire PIN list is exposed, all hell breaks loose.