CYBER WELFARE

Protect your Digital Privacy

Proximity attacks: when the threat is in the same room

Every other unit in this series describes threats arriving over the network. This one describes the only category where whoever acts is physically near you.

It is a difference that changes everything: there are no filters to cross, no connections to intercept, nothing to guess. There is only a distance of a few metres and a window of time.

It expands on the recommendation screen lock timeout.

The common principle

Every technique in this family shares one characteristic: they exploit an already authenticated session.

They do not attack the password, they do not attack the encryption, they do not attack the second factor. They wait for the moment when all those protections have already been passed — by you, legitimately — and use that window.

It is why a defence built only on strong credentials does not cover this scenario: credentials are not the target here.

1. Opportunistic looking

It is by far the most frequent, and it is rarely called an “attack”.

How it works. Somebody in the same space notices an open device and looks at it. They plan nothing: they take an opportunity that presented itself.

Who does it. A curious colleague, somebody you live with, somebody passing through. In the great majority of cases there is no plan and no financial motive: there is curiosity.

What they get. What is visible: messages, calendar, open documents, notifications.

Why it counts anyway. Information seen cannot be unseen, and in a professional setting it can concern people who are not in the room.

2. Reading over the shoulder

How it works. The device does not have to be touched: being in a position where the screen is readable is enough. A train, a plane, a waiting room, a cafe table, an adjacent desk.

What they get. The content of messages and emails, verification codes when they appear as a notification, and — in the worst cases — a password observed as it is typed.

The specific defence. A privacy filter on a laptop screen, the habit of angling the device, and turning off message previews in notifications on the locked screen. That last one matters particularly: a verification code visible without unlocking the phone undoes the second factor for anyone standing in front of the device.

3. Persistent configuration

It is the most serious, and it is what justifies all the checks described in the post on signals.

How it works. Whoever has access to the open device is not looking for information: they install something that keeps working afterwards. A forwarding rule on the mail, an application, a browser extension, a linked account, a recovery method added.

Why it is different. The first two techniques end when the window ends. This one starts when the window ends: from that moment the access is remote, silent, and it survives the device being locked and even a password change.

The time needed. Less than a minute for a forwarding rule; a few minutes for the rest.

The specific defence. It is the only technique in this family where the defence is not preventive but a matter of checking: forwarding rules, linked devices and recovery methods.

4. A device connected physically

How it works. A device plugged into a port on the open computer. Some present themselves to the system as a keyboard and type a sequence of commands in seconds; others copy data.

How realistic it is. Far less than the previous ones in an ordinary setting: it takes preparation and a specific objective. It is a scenario relevant to people in sensitive roles, not to most people.

The specific defence. Locking the screen neutralises it almost entirely, because on a locked system new input devices are ignored or require explicit authorisation.

5. Taking a device with the screen open

How it works. The device is taken while it is unlocked — at a cafe table, on the underground, on a bench.

Why it is the worst variant of theft. A stolen device that is locked is an object: the data is encrypted and unreachable. A stolen device that is open is your digital identity, with the sessions active and no barriers at all.

The specific defence. Manual locking every time you put the device down, and — on phones — the setting that locks instantly when you press the side button.

The overall picture

TechniqueFrequencySeverityDoes it survive the window?
Opportunistic lookingVery highLow-mediumNo
Reading over the shoulderHighMediumNo
Persistent configurationMediumVery highYes
A connected deviceLowHighYes
Taken with the screen openMediumVery highYes

The right-hand column is what sets the priorities: the techniques that survive the window are the ones worth building a check against, not only prevention.

What does not belong to this family

Worth clarifying, because the word “proximity” gets used for other things too.

  • Attacks over Bluetooth or wireless networks exploit radio closeness, not physical access to an open device. They are a different family, covered in another unit.
  • The theft of a locked device is a question of encryption and account recovery, not of an open session.
  • Spy software installed remotely requires no proximity: it arrives by other routes.

The contexts where these techniques work best

The techniques above are not all equally likely everywhere. Recognising the favourable contexts is more useful than memorising the techniques.

Shared workspaces and coworking. Many people, little mutual acquaintance, frequent and predictable absences. It is the context where all five techniques are possible.

Offices open to the public. Counters, professional practices, reception desks. People who are not part of the organisation pass through, and are often left alone for a moment while whoever received them goes to fetch a document.

Meeting rooms. A computer left connected to the projector during a break is open, in a space anybody can walk into.

The common areas of hotels and conferences. Waiting rooms, lounges, shared tables. People passing through, no oversight, and the custom of asking a stranger to “keep an eye on” a laptop for two minutes — which is exactly the wrong thing to entrust.

Public transport. It does not allow the device to be touched, but it is the ideal context for reading over the shoulder: short distances, plenty of time, a gaze that draws no attention.

Domestic spaces with people coming through. Moving house, work on the house, parties, your children’s friends. No bad faith required: just an open device and people who do not live there.

The common denominator is not how dangerous the place is — none of these is a risky place. It is the combination of an open device and an uncontrolled presence, which is a far more ordinary condition than the word “attack” suggests.

Why the defence is so simple

There is an interesting symmetry in this family of threats: they are among the easiest to carry out and among the easiest to prevent.

Easy to carry out because they take no technical skill at all: anybody can look at an open screen.

Easy to prevent because one single measure neutralises nearly all of them: a device that locks in thirty seconds reduces the window to an interval in which, realistically, nothing gets done.

That is not true of every category of risk. Against phishing you need continuous attention and recognition skills; against malware you need updates, care and tools. Here a number in a settings menu is enough — and that is perhaps why this recommendation gets underestimated: it seems too simple to be important.

The defences, in order of effectiveness

Lined up, because they do not all carry the same weight and it helps to know where to start.

DefenceWhat it coversEffort
A short timeout + immediate lockNearly every techniqueA minute, once
Manual locking when you get upThe same, without waiting for the timerTwo days of habit
Notification previews turned offReading codes over the shoulderThirty seconds
A password vault with its own lockLooking, and persistent configurationOne setting in the app
Periodic checks of forwarding and sessionsPersistent configuration only, but afterwardsFive minutes a month
A privacy filter on the screenReading on a train and in open-plan officesA physical accessory

The first two rows cover most of the scenario on their own. The fifth is the only one acting afterwards rather than beforehand, which is why the others cannot replace it: no preventive measure removes a forwarding rule already created.

The profile of whoever acts

It is worth being honest about one point, because it changes how to think about this.

In the other units of the series, whoever attacks is typically an organisation, remote and anonymous, operating at scale. Here, in the great majority of cases, there is no criminal. There is a person in the same space, who saw an opportunity and took it.

That does not make the problem less real, but it changes two things:

On prevention: you do not need to defend against a skilled adversary. You need to close a door that was left open.

On the response: when it happens, the subject is not only technical. It is a relationship inside which something happened, and that is the hardest part — covered in the post on consequences.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that here the adversary is near, not remote
SkillsTelling the techniques that end from those that persist
Secure BehaviourLocking when you get up; checking the configurations afterwards

Reference level: FL3 — Autonomous.

Summary

  • Proximity attacks do not attack credentials: they exploit an already authenticated session.
  • Persistent configuration is the most serious variant: it starts when the window ends.
  • Message previews on the locked screen expose verification codes to anyone standing in front of the phone.
  • It is a family that is easy to carry out and easy to prevent: a short timeout covers nearly all of it.

One thing to do today. Check whether your phone shows message content on the lock screen. If it does, set previews to “only when unlocked”: it is the difference between a second factor that protects and one readable by anybody walking past.

Related content

Related resources

Short reads from the Resources section, for anyone who wants to stop on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.