- Five distinct digits in a six-digit passcode maximizes possible combinations.
- Smudge attacks let thieves identify tapped digits from fingerprint residue.
- Repeating one digit hides which key repeated, multiplying an attacker's work.
Presh Talwalkar poses his best puzzles the way a magician palms a coin: you know there's a trick, but you still don't see it coming.
A Stanford-trained mathematician who runs the MindYourDecisions YouTube channel, Talwalkar recently turned his attention to a question most people never think to ask: is a smartphone passcode with a repeated digit actually more secure than one using all different numbers?
What is a smudge attack?
A smudge attack uses residual fingerprint oil on a touchscreen to identify which keys were tapped during passcode entry. Researchers at the University of Pennsylvania documented the technique in 2010 and found it could reveal the digits in a PIN from photographs taken under standard lighting conditions.
The Smudge Attack You've Probably Never Heard Of
The setup begins with a well-documented threat called a smudge attack.
When you tap a PIN, your fingers leave oily residue on the screen. Anyone with a decent camera and reasonable lighting can photograph those marks and identify which keys you pressed. They won't know the order, but they'll know the digits.
That information dramatically narrows the search. A six-digit passcode using six different numbers has 720 possible orderings. A thief who can read your smudges needs to check, at most, 720 combinations. With modern tools, that takes very little time.
Key figure
1,800 vs 720
Possible six-digit passcodes using five distinct digits vs six distinct digits
Why Fewer Digits Can Mean More Combinations
Here is where Talwalkar's puzzle becomes genuinely surprising.
If you use only five distinct digits in a six-digit passcode, one digit must repeat. The attacker can still read your smudges, but now faces an additional problem: they don't know which digit repeats.
That uncertainty multiplies the search space considerably. For each possible repeated digit, there are 360 distinct orderings (6 factorial divided by 2 factorial for the duplicate). Across all five candidate digits, that yields 1,800 possible combinations.
The attacker who read your smudges now has two-and-a-half times more work ahead of them.
Talwalkar generalizes the result using basic combinatorics. For any passcode of length n using n distinct digits, there are n factorial permutations. Using n minus one distinct digits produces roughly (n-1)/2 times as many. For n of four or greater, that ratio always exceeds one.
The Optimal Number Shifts With Passcode Length
The intuition does not extend indefinitely.
For a six-digit passcode, using five distinct digits is optimal. Dropping to four distinct digits yields 1,560 combinations, fewer than five-distinct but still more than six-distinct. Three distinct digits produces 540. At two distinct digits, you have just 62 options.
The curve peaks at five and falls sharply on either side.
More On Codes
Quantum Cryptography Gets a New Foundation Built on Useless Keys
Two cryptographers built quantum encryption on keys too slow to unlock anything. Their one-way puzzles could survive if all classical cryptography fails.
→For a seven-digit passcode, Talwalkar consulted the Online Encyclopedia of Integer Sequences and found the optimum shifts: five distinct digits still maximizes the combination count, though the absolute numbers change. The principle holds for longer passcodes too, with the sweet spot drifting as length increases.
The practical advice is simple.
On a six-digit iPhone or Android passcode, repeat exactly one digit. Your screen will still betray the keys you used. But anyone reading those smudges faces a meaningfully longer search.
Sources
- Primary Source: The Mathematical Reason Your Passcode Should Repeat A Digit (MindYourDecisions / YouTube)
- Additional Context:
- Smudge attack (Wikipedia)
Fact Check: Claim-by-Claim Verification Verified
All major claims in the article are factually accurate, including the smudge attack background, mathematical calculations, and combinatorial reasoning.
Commentary
- The article simplifies the context by focusing on smudge attacks as motivation. The mathematical insight about repeated digits is valid specifically when an attacker has successfully identified which digits are present but not their order—this contextual constraint is clearly explained in the article and is accurate.
- The article uses "5 distinct digits" language correctly. When the article states "repeating a digit" for a 6-digit passcode, it means using 5 distinct digits with one digit appearing twice, which is standard mathematical terminology.
- The principle that fewer distinct digits can yield more combinations is counterintuitive but mathematically sound, making this appropriate for popular science presentation as explained in the article.
Sources used for verification
Academic/Peer-reviewed:
- Smudge Attacks on Smartphone Touch Screens - USENIX
- Combinatorics Lecture Notes - Stanford University
Other reliable sources:
- The Mathematical Reason Your Passcode Should Repeat A Digit - MindYourDecisions/YouTube
- Smudge attack - Wikipedia
- Online Encyclopedia of Integer Sequences - OEIS.org
- MindYourDecisions Blog - MindYourDecisions
Fact-checked by Perplexity Sonar Pro on 2026-03-07
