Every other unit in this series describes threats arriving over the network. This one describes the only category where whoever acts is physically near you.
It is a difference that changes everything: there are no filters to cross, no connections to intercept, nothing to guess. There is only a distance of a few metres and a window of time.
It expands on the recommendation screen lock timeout.
The common principle
Every technique in this family shares one characteristic: they exploit an already authenticated session.
They do not attack the password, they do not attack the encryption, they do not attack the second factor. They wait for the moment when all those protections have already been passed — by you, legitimately — and use that window.
It is why a defence built only on strong credentials does not cover this scenario: credentials are not the target here.
1. Opportunistic looking
It is by far the most frequent, and it is rarely called an “attack”.
How it works. Somebody in the same space notices an open device and looks at it. They plan nothing: they take an opportunity that presented itself.
Who does it. A curious colleague, somebody you live with, somebody passing through. In the great majority of cases there is no plan and no financial motive: there is curiosity.
What they get. What is visible: messages, calendar, open documents, notifications.
Why it counts anyway. Information seen cannot be unseen, and in a professional setting it can concern people who are not in the room.
2. Reading over the shoulder
How it works. The device does not have to be touched: being in a position where the screen is readable is enough. A train, a plane, a waiting room, a cafe table, an adjacent desk.
What they get. The content of messages and emails, verification codes when they appear as a notification, and — in the worst cases — a password observed as it is typed.
The specific defence. A privacy filter on a laptop screen, the habit of angling the device, and turning off message previews in notifications on the locked screen. That last one matters particularly: a verification code visible without unlocking the phone undoes the second factor for anyone standing in front of the device.
3. Persistent configuration
It is the most serious, and it is what justifies all the checks described in the post on signals.
How it works. Whoever has access to the open device is not looking for information: they install something that keeps working afterwards. A forwarding rule on the mail, an application, a browser extension, a linked account, a recovery method added.
Why it is different. The first two techniques end when the window ends. This one starts when the window ends: from that moment the access is remote, silent, and it survives the device being locked and even a password change.
The time needed. Less than a minute for a forwarding rule; a few minutes for the rest.
The specific defence. It is the only technique in this family where the defence is not preventive but a matter of checking: forwarding rules, linked devices and recovery methods.
4. A device connected physically
How it works. A device plugged into a port on the open computer. Some present themselves to the system as a keyboard and type a sequence of commands in seconds; others copy data.
How realistic it is. Far less than the previous ones in an ordinary setting: it takes preparation and a specific objective. It is a scenario relevant to people in sensitive roles, not to most people.
The specific defence. Locking the screen neutralises it almost entirely, because on a locked system new input devices are ignored or require explicit authorisation.
5. Taking a device with the screen open
How it works. The device is taken while it is unlocked — at a cafe table, on the underground, on a bench.
Why it is the worst variant of theft. A stolen device that is locked is an object: the data is encrypted and unreachable. A stolen device that is open is your digital identity, with the sessions active and no barriers at all.
The specific defence. Manual locking every time you put the device down, and — on phones — the setting that locks instantly when you press the side button.
The overall picture
| Technique | Frequency | Severity | Does it survive the window? |
|---|---|---|---|
| Opportunistic looking | Very high | Low-medium | No |
| Reading over the shoulder | High | Medium | No |
| Persistent configuration | Medium | Very high | Yes |
| A connected device | Low | High | Yes |
| Taken with the screen open | Medium | Very high | Yes |
The right-hand column is what sets the priorities: the techniques that survive the window are the ones worth building a check against, not only prevention.
What does not belong to this family
Worth clarifying, because the word “proximity” gets used for other things too.
- Attacks over Bluetooth or wireless networks exploit radio closeness, not physical access to an open device. They are a different family, covered in another unit.
- The theft of a locked device is a question of encryption and account recovery, not of an open session.
- Spy software installed remotely requires no proximity: it arrives by other routes.
The contexts where these techniques work best
The techniques above are not all equally likely everywhere. Recognising the favourable contexts is more useful than memorising the techniques.
Shared workspaces and coworking. Many people, little mutual acquaintance, frequent and predictable absences. It is the context where all five techniques are possible.
Offices open to the public. Counters, professional practices, reception desks. People who are not part of the organisation pass through, and are often left alone for a moment while whoever received them goes to fetch a document.
Meeting rooms. A computer left connected to the projector during a break is open, in a space anybody can walk into.
The common areas of hotels and conferences. Waiting rooms, lounges, shared tables. People passing through, no oversight, and the custom of asking a stranger to “keep an eye on” a laptop for two minutes — which is exactly the wrong thing to entrust.
Public transport. It does not allow the device to be touched, but it is the ideal context for reading over the shoulder: short distances, plenty of time, a gaze that draws no attention.
Domestic spaces with people coming through. Moving house, work on the house, parties, your children’s friends. No bad faith required: just an open device and people who do not live there.
The common denominator is not how dangerous the place is — none of these is a risky place. It is the combination of an open device and an uncontrolled presence, which is a far more ordinary condition than the word “attack” suggests.
Why the defence is so simple
There is an interesting symmetry in this family of threats: they are among the easiest to carry out and among the easiest to prevent.
Easy to carry out because they take no technical skill at all: anybody can look at an open screen.
Easy to prevent because one single measure neutralises nearly all of them: a device that locks in thirty seconds reduces the window to an interval in which, realistically, nothing gets done.
That is not true of every category of risk. Against phishing you need continuous attention and recognition skills; against malware you need updates, care and tools. Here a number in a settings menu is enough — and that is perhaps why this recommendation gets underestimated: it seems too simple to be important.
The defences, in order of effectiveness
Lined up, because they do not all carry the same weight and it helps to know where to start.
| Defence | What it covers | Effort |
|---|---|---|
| A short timeout + immediate lock | Nearly every technique | A minute, once |
| Manual locking when you get up | The same, without waiting for the timer | Two days of habit |
| Notification previews turned off | Reading codes over the shoulder | Thirty seconds |
| A password vault with its own lock | Looking, and persistent configuration | One setting in the app |
| Periodic checks of forwarding and sessions | Persistent configuration only, but afterwards | Five minutes a month |
| A privacy filter on the screen | Reading on a train and in open-plan offices | A physical accessory |
The first two rows cover most of the scenario on their own. The fifth is the only one acting afterwards rather than beforehand, which is why the others cannot replace it: no preventive measure removes a forwarding rule already created.
The profile of whoever acts
It is worth being honest about one point, because it changes how to think about this.
In the other units of the series, whoever attacks is typically an organisation, remote and anonymous, operating at scale. Here, in the great majority of cases, there is no criminal. There is a person in the same space, who saw an opportunity and took it.
That does not make the problem less real, but it changes two things:
On prevention: you do not need to defend against a skilled adversary. You need to close a door that was left open.
On the response: when it happens, the subject is not only technical. It is a relationship inside which something happened, and that is the hardest part — covered in the post on consequences.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that here the adversary is near, not remote |
| Skills | Telling the techniques that end from those that persist |
| Secure Behaviour | Locking when you get up; checking the configurations afterwards |
Reference level: FL3 — Autonomous.
Summary
- Proximity attacks do not attack credentials: they exploit an already authenticated session.
- Persistent configuration is the most serious variant: it starts when the window ends.
- Message previews on the locked screen expose verification codes to anyone standing in front of the phone.
- It is a family that is easy to carry out and easy to prevent: a short timeout covers nearly all of it.
One thing to do today. Check whether your phone shows message content on the lock screen. If it does, set previews to “only when unlocked”: it is the difference between a second factor that protects and one readable by anybody walking past.
Related content
- Screen lock timeout — the recommendation this expands on
- Signs someone used your device — how to notice a persistent configuration
- How to set up automatic locking — the measure covering nearly the whole family
- Consequences of an unattended device — what stays afterwards, on the human side
Related resources
Short reads from the Resources section, for anyone who wants to stop on a single aspect:
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



