CYBER WELFARE

Protect your Digital Privacy

Shoulder Surfing: Protecting Your Phone as You Unlock It

Additional resource for the lesson “Shoulder Surfing: Where You Unlock Your Phone” — Online Security course

A good passcode stops being good the moment somebody watches you type it. Shoulder surfing is the oldest attack there is, it needs no equipment, and it happens in the places you unlock your phone twenty times a day without thinking.

A. Why this matters

The companion resources cover which unlock method to choose and how quickly the phone should lock itself. This one is about the third variable, and the one people never consider: where you are standing when you type the code.

A code that has been observed is not a code any more. And the observation costs nothing — no software, no skill, just proximity and a few seconds of attention.

The key idea: this is the one attack where the defence is entirely behavioural. No setting protects you from being watched; only noticing does.

It matters more than it used to, because phones are now unlocked in public constantly — and because a stolen phone that someone has seen you unlock is a very different loss from one they have not.

B. Key concepts

Six ideas about the moment of entry.

Shoulder surfing

Observing someone enter a code, a password or a PIN, directly or from a distance.

Why it matters to you: It requires nothing but position. This is why it survives every technical improvement: there is nothing to break.

Why patterns are the most exposed

A drawn shape is large, slow, and visible as a movement rather than as individual key presses.

Why it matters to you: It can be read from several metres away, and remembered easily because it is a shape rather than a sequence of digits.

Numeric versus alphanumeric

A six-digit PIN involves six taps on a large keypad. An alphanumeric passcode involves more characters on a smaller keyboard.

Why it matters to you: Longer and more varied is genuinely harder to capture accurately at a glance — a second reason to prefer it beyond raw strength.

The risk context

Public transport, queues, cafés, airports, shared offices, lifts — anywhere someone is close and stationary behind or beside you.

Why it matters to you: Recognising the situation is the whole skill. In most of your day the risk is nil; in a few recurring moments it is not.

Cameras and reflections

Security cameras in shops and stations, and reflective surfaces such as windows and glasses.

Why it matters to you: Worth knowing without becoming preoccupied: it is a reason to angle the screen away in a queue, not a reason to feel watched everywhere.

Privacy screen filters

A film that narrows the viewing angle so the screen is only readable from directly in front.

Why it matters to you: Inexpensive and effective for people who work on trains or in open offices. Not necessary for everyone, and useful for some.

C. A practical example: two stops on a train

You unlock your phone on a crowded train. Someone standing behind you sees the pattern you draw — a large L shape, done the same way every time.

Nothing happens for the rest of the journey. Two stops later, the phone is taken from your hand as the doors close.

  • Without the observed code, the thief has a locked, encrypted device. It is worth reselling and nothing more.
  • With it, they have your email, your messages, your banking app and, if your authenticator is on the phone, your second factors too.

The theft was opportunistic. The reason it became serious was the two seconds of watching that came first.

What would have changed it

  • A PIN or alphanumeric code instead of a pattern: harder to read at a glance, and no shape to remember.
  • The phone angled towards you, or unlocked with a fingerprint in that setting.
  • Simply noticing that a crowded train is one of the places worth being deliberate.

This is the one case where biometrics are clearly the better choice: a fingerprint or face unlock reveals nothing to an observer.

D. Try it yourself: notice the moments

This one is observation rather than configuration. Give it a day.

Step 1 — Count where you unlock

  • For one day, notice where you enter your code: at home, at a desk, on transport, in queues, in meetings.
  • You are looking for the recurring public moments, not a complete count.

Step 2 — Identify your two riskiest habits

  • Most people find one or two: the daily commute, or the queue at the same shop.
  • Those are the moments worth changing. The rest do not need attention.

Step 3 — Choose the countermeasure that fits

  • Use biometrics in public and reserve the typed code for private settings.
  • Angle the screen towards you, or shield it with your other hand.
  • Move away from patterns if you still use one.
  • Consider a privacy filter if you regularly work on transport.

The aim is not vigilance all day. It is recognising the two or three recurring situations where a small adjustment removes the exposure entirely.

E. Videos, articles and further resources

Independent and institutional sources in English.

NCSC (UK) — Cyber security advice for you and your family
General device protection advice for individuals, including access habits.
https://www.ncsc.gov.uk/section/advice-guidance/you-your-family

FTC — How to protect your phone from hackers
What to do to protect the phone, and what to do if it is taken.
https://consumer.ftc.gov/articles/how-protect-your-phone-hackers

CISA — Secure Our World
The US cyber security agency’s public programme: four basic actions, explained for people who are not IT professionals.
https://www.cisa.gov/secure-our-world

NCSC (UK) — Top tips for staying secure online
Six short pieces of advice from the UK’s national cyber security authority. A good starting point if you want the essentials without the jargon.
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online

NCSC (UK) — What to do if your account is hacked
The steps that matter in the first hour after a device with your accounts on it is lost.
https://www.ncsc.gov.uk/section/respond-recover/hacked-accounts

EFF — Keeping your data safe
Encryption and device protection explained for people who do not want to become experts.
https://ssd.eff.org/module/keeping-your-data-safe

Links checked in August 2026.

F. The Cyber Welfare Framework: Skills, Awareness, Secure Behavior

This lesson sits on the Secure Behavior pillar at level FL2. Unusually for this course, there is no setting to change — only a habit.

Skills

  • Recognising the situations where entering a code is exposed.
  • Using biometrics in public and the typed code in private.
  • Shielding the screen naturally, without it becoming a performance.

For professionals and organizations

  • Considering privacy filters for staff who routinely work on transport or in open spaces.

Awareness

  • Understanding that an observed code is no longer a code.
  • Recognising that patterns are the most readable option from a distance.
  • Seeing the link between observation and theft: the second is much worse after the first.

For future instructors and ambassadors

  • Keeping this proportionate. The goal is awareness of two or three recurring moments, not permanent suspicion of everyone nearby.

Secure Behavior

  • Being deliberate about unlocking in crowded or public settings.
  • Preferring biometrics where people are close.
  • Not using a pattern on a device carried in public.

For organizations

  • Including this in awareness training, where it is usually missing entirely.

G. Questions to sit with

  1. Where do you unlock your phone most often outside your home?
  2. Would someone standing behind you be able to read your code, or follow the shape you draw?
  3. Do you use biometrics in public, or type the code regardless of who is nearby?
  4. If your phone were taken from your hand right now, would the person holding it already know how to open it?

H. What to do now

The recommendations (R) and security measures (MS) from the Cyber Welfare database that apply to the moment of entry.

The unlock method

  • MS3 — Prefer a passcode over a pattern: a drawn shape is the easiest thing to read from a distance.
  • R5 — A six-digit PIN as a minimum.
  • MS4 — An alphanumeric passcode of 8 characters or more, which is also harder to capture at a glance.

The context

  • R7 — Keep the screen lock timeout short, so a phone put down is not left open.
  • R10 — Avoid handling sensitive services on public networks and in public settings generally.

Minimum commitment: Biometrics in public, typed code in private, is the simplest rule that covers most of this.

Three small adjustments

  1. If you use a pattern on a phone you carry in public, change it to a PIN or passcode.
  2. Turn on biometrics and use them when people are close.
  3. Identify your two most exposed recurring moments — usually a commute or a queue — and be deliberate in those.

That is the whole lesson. It costs nothing and it closes the one gap that no setting can.

In short

  • An observed code is no longer a code, and observing costs nothing.
  • Patterns are the most readable option; a passcode is the hardest to capture.
  • Biometrics are the right choice in public precisely because they reveal nothing.
  • The goal is noticing two or three recurring moments, not being watchful all day.

Related resources in this course

The rest of the device cluster:

Discover more companion resources from the online courses of the Protect Your Digital Privacy programme.

If you would like to follow the whole path, the Cyber Welfare Program is free and open to everyone.

→ Join the Cyber Welfare Program