If the attacker is able to read the encrypted password file from flash, a 4-digit PIN is likely to be trivial to brute-force. Storing the password on a SIM with lock-out is a decent solution, if you have a SIM card. I'm tapping this out on an Android phone with no SIM.