A phone’s lock screen today offers at least five different ways to open it. They look like equivalent alternatives, and they are not: they protect against different things, they give way in different situations, and they stand in a hierarchy almost nobody knows about.
That is the most important point, and it is worth stating up front: fingerprint and face do not replace the code, they sit alongside it. The code stays underneath, and it remains the real protection.
This post explains how the different methods work and how to combine them. It is the technology side of the recommendation six digit passcode.
The hierarchy almost nobody knows about
On modern mobile systems the code — passcode or password — is not one method among others: it is the key on which the protection of the data on the device depends.
Fingerprint and face recognition are convenience shortcuts, authorised to unlock the device after the code has already been entered at least once. The system goes back to asking for the code in specific situations:
- after a restart or a shutdown;
- after a certain number of hours without unlocking;
- after several failed biometric attempts;
- before changing the security settings;
- on some systems, after an emergency mode has been triggered.
A practical consequence follows: a device with a fingerprint enabled and a four-digit passcode is protected, ultimately, by four digits. Biometrics do not raise that threshold — they only make it more comfortable not to use it.
1. Numeric passcode
A code made only of digits.
- How it works. The device limits attempts: after a few errors it introduces increasing delays, and in some configurations it can erase itself after many failed attempts.
- What it protects well. Manual attempts to guess it, if the code is not traceable to you. With six digits, the combinations go from ten thousand to a million.
- Where it is fragile. Being observed while typing, and codes derived from dates or known sequences.
- When to choose it. It is the right choice for most people: quick to type, sufficient if unpredictable and combined with the attempt limit.
- Complexity: basic.
2. Alphanumeric password
A code including letters and symbols.
- How it works. The same mechanism as the passcode, with a much wider set of characters for each position.
- What it protects well. Everything the passcode covers, with an extra margin against systematic attempts on a stolen device.
- Where it is fragile. The inconvenience: typing it dozens of times a day leads to shortening it or turning off the automatic lock, cancelling out the advantage.
- When to choose it. On devices holding particularly sensitive data, or in professional settings that require it. It is the refinement set out in the programme’s Security Measures.
- Complexity: intermediate, for daily use.
3. Fingerprint
The sensor recognises the fingerprint and unlocks.
- How it works. The fingerprint is not kept as an image: the system derives a mathematical representation of it, held in a protected portion of the processor that applications cannot reach.
- What it protects well. Daily use. It greatly reduces the number of times you type the code in public — and that is a real security advantage, not just a convenience.
- Where it is fragile. It does not work with wet or dirty fingers; it can be less reliable on some sensors; and it remains a shortcut above the code, which is what needs choosing well.
- When to choose it. Always, in addition to a strong code.
- Complexity: basic.
4. Face recognition
The camera recognises the face and unlocks.
- How it works. The more recent systems build a three-dimensional map of the face, hard to fool with a photograph. Simpler systems, based on a two-dimensional image alone, offer appreciably lower protection.
- What it protects well. Daily use, on the same logic as the fingerprint.
- Where it is fragile. The difference between the two kinds of implementation is substantial and not always obvious: it is worth knowing which one your device carries. And, like the fingerprint, it remains a shortcut above the code.
- When to choose it. Happily, if the device uses three-dimensional recognition.
- Complexity: basic.
5. Pattern
A path traced by joining dots on a grid.
- How it works. The system records the sequence of dots.
- What it protects well. Not much, compared with the alternatives. The patterns people actually use are far fewer than the theoretical combinations: most start from a corner and draw regular shapes.
- Where it is fragile. It is the method most exposed to observation: the finger’s movement is visible from a distance and can be reconstructed from memory, and it often leaves a trace on the screen.
- When to choose it. Better avoided where alternatives exist. It is the method the programme’s Security Measures explicitly advise against.
- Complexity: basic.
Comparison table
| Method | Resists repeated attempts | Resists observation | Daily convenience | Role |
|---|---|---|---|---|
| 4 digit passcode | Weak | Medium | High | Not advised |
| 6+ digit passcode | Good | Medium | High | Recommended baseline |
| Alphanumeric password | Very good | Medium | Low | Advanced refinement |
| Fingerprint | Not applicable | High | Very high | Shortcut above the code |
| Face (3D) | Not applicable | High | Very high | Shortcut above the code |
| Face (2D) | Not applicable | Medium | Very high | Weak shortcut |
| Pattern | Weak | Low | High | To avoid |
The “Role” column sums it all up: biometric methods do not compete with the code, they sit above it.
The recommended combination
For the great majority of people:
A passcode of six digits or more, not traceable to you + biometric recognition enabled + a short automatic lock.
Each element does something different:
- the passcode is the underlying protection, the one that holds in the moments where biometrics do not apply;
- biometrics reduce the occasions on which the passcode is typed in public, and make a very short automatic lock sustainable;
- the automatic lock shortens the window in which the device sits open on the table.
Without biometrics, a fifteen-second automatic lock becomes unbearable and gets lengthened. That is why biometrics increase overall security, even though taken alone they are the least robust part.
What happens to the data when the phone is locked
It is worth knowing, because it explains why the code counts for so much.
On modern mobile devices the data is encrypted, and the encryption key is tied to the unlock code. With the device switched off or freshly restarted, the content is not readable until the code has been entered for the first time.
After that first unlock, the system keeps the keys available so applications can work: from that moment the device is in a less protected state, even when the screen is locked.
Two practical consequences:
- Switching the phone off, in particular situations, increases protection more than simply locking the screen does.
- A weak code weakens the encryption, because the protection of the data depends on it. It is not just a question of “opening the screen”.
The attempt limit: the invisible protection
There is an element working alongside the code that almost nobody factors into the choice: the device limits attempts by itself.
The mechanism is progressive. After a few consecutive errors the system introduces a wait before the next attempt; the wait grows with each error, reaching minutes and then hours. In some configurations, after a high number of failed attempts, the device can erase its own data.
That changes the arithmetic considerably. On a stolen archive — the scenario for online account passwords — the attempts can be very many. On a phone, trying fifty combinations takes hours of enforced waiting.
A useful conclusion follows: on a mobile device the length of the code does not have to withstand millions of attempts, it has to withstand targeted ones. Six unpredictable digits are amply sufficient precisely because the system slows down anyone trying.
It is also why the real vulnerability is not the strength of the code, but the fact that it can be deduced: somebody who knows your date of birth does not need fifty attempts, they need two.
What to check. On devices holding particularly sensitive data, see whether the option to erase after repeated failed attempts is enabled — and, if you turn it on, make sure you have a copy of the content.
What no unlock method can do
- It does not protect an already unlocked device. That is by far the most frequent case, and it is why the automatic lock counts.
- It does not protect what is visible on a locked screen. Message previews and verification codes are a separate setting.
- It does not protect against access to your accounts from another device. That depends on your passwords and second factor.
- It does not prevent you being compelled to unlock. In some contexts, being able to switch the device off quickly counts for more than having a strong code.
- It does not replace remote lock, which is the only action available once the device is no longer yours.
How to choose, in practice
If you are an individual. A six digit passcode plus biometrics. It is the combination that covers the real scenarios without making the device inconvenient.
If you are a professional. Consider an alphanumeric code on the device holding client data, and check which kind of face recognition your phone carries.
If you set up devices for others — in the family, for people less at ease with them — the best choice is almost always a six digit passcode plus a fingerprint: the code is rarely needed, and meanwhile the protection is adequate.
A rule of thumb. The right method is the one that lets you keep the automatic lock on very short times without irritating you. If a configuration leads you to lengthen the lock time, you chose the wrong method.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Understanding the hierarchy between the code and the biometric methods |
| Awareness | Recognising that the convenience of biometrics is what makes security sustainable |
| Secure Behaviour | Choosing a combination that does not lead you to lengthen the automatic lock |
Reference level: FL4 — Skilled. This is the level at which you choose a method for how it works, rather than for how the device proposed it when first switched on.
Conclusion
Fingerprint and face do not protect the phone: they make it convenient to keep protected. The real protection remains the code, and it is the choice worth making well once.
What to do next. Check how many digits your phone’s code has. If it is four, taking it to six takes a minute — and it raises the number of possible combinations a hundredfold.
Related content
- Six digit passcode — the recommendation this belongs to
- How to secure your phone unlock — how to put these choices into practice
- Attacks on the lock screen — what each method is needed against
- Impact of an unlocked phone — what is at stake behind the lock screen
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



