Remix.run Logo
yodelshady 4 days ago

I've received the same PIN from an entirely different gym chain, albeit one using the same door system.

As you say, a massive red flag indicating it's not using a lot of sources of entropy.

pyman 3 days ago | parent | next [-]

What worries me the most is that if the ACS can't issue new PINs, there's no way to replace them. If a single PIN is shared or compromised, anyone with it can walk in undetected until the whole system is replaced. And if the entire PIN list is exposed, all hell breaks loose.

thefreeman 4 days ago | parent | prev [-]

Or they just reactivated his previously canceled account and it still had a pin associated