Shoulder Surfing
Jump to:
Summary
Shoulder Surfing is a social engineering attack where an attacker observes a victim’s private information by looking over their shoulder or through other direct visual means. This technique targets sensitive data such as passwords, PINs, or confidential information during input on devices or paper documents.
Key Characteristics
- Involves direct visual observation of sensitive information.
- Often occurs in public or semi-public spaces like ATMs, offices, or cafes.
- Can be performed physically or through video recording devices.
- Targets user input on keyboards, touchscreens, or handwritten notes.
- Does not require technical hacking skills, relying on opportunistic observation.
Defensive Controls
- Use privacy screens or shields on devices to limit visibility.
- Be aware of surroundings when entering sensitive information.
- Implement multi-factor authentication to reduce reliance on visible credentials.
- Educate users about the risks of shoulder surfing and safe input practices.
- Design user interfaces that mask input, such as password fields displaying asterisks.
Related Security Solutions
Privacy filters, biometric authentication, multi-factor authentication systems, secure input methods, and user awareness training programs are key solutions to mitigate shoulder surfing risks.
More in Physical & Hybrid Attacks