Jump to content

Shoulder surfing (computer security)

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by Tim Q. Wells (talk | contribs) at 00:09, 11 August 2007 (grammar). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

In computer security, shoulder surfing refers to using direct observation techniques, such as looking over someone's shoulder, to get information. Shoulder surfing is particularly effective in crowded places because it's relatively easy to stand next to someone and watch as they fill out a form, enter their PIN at an automated teller machine, use a calling card at a public pay phone, or enter passwords at a cybercafe, public and university libraries, or airport kiosks. Shoulder surfing can also be done at a distance with the aid of binoculars or other vision-enhancing devices. Inexpensive, miniature closed-circuit television cameras can be concealed in ceilings, walls or fixtures to observe data entry. To prevent shoulder surfing, experts[who?] recommend shielding paperwork or the keypad from view by using one's body or cupping one's hand.

Recent automated teller machines now have a sophisticated display which discourages shoulder surfers. It grows darker beyond a certain viewing angle, and the only way to tell what is displayed on the screen is to stand directly in front of it.

Certain models of credit card readers have the keypad recessed, and employ a rubber shield that surrounds a significant part of the opening towards the keypad. This makes shoulder-surfing significantly harder, as seeing the keypad is limited to a much more direct angle than previous models. Taken further, some keypads alter the physical location of the keys after each keypress. For example the digit 1 may be the upper left on the first press, then moves to the bottom right for the second.