I read the article. Basically a shoulder surfing thief can watch you type in a passcode, grab your phone, and use the passcode to get access to your entire phone including all of your accounts. Except…
- My bank accounts want to use FaceID or type in their account and password. In theory, the thief might be able to reset the password, but my banks wants my ATM card’s last four digits and my account.
- All my passwords are stored in 1Password and I need my FaceID or 1Password password. If you use Apple’s Password database, your passcode can get into that.
- And this is not exclusively an Apple problem. This is also a problem with Android phones too. It is more likely that iPhone users will use their phone for banking, email, etc. But, if they do, Android phones are just as vulnerable. Pasting Apple like they did all over the place is just plain clickbait.
The solution is to always use TouchID or FaceID when you’re out and about. They both work so seamlessly, you can almost forget your phone is locked. So, set them up.
Since you’ll FaceID and TouchID use 95% of the time, using more complex passcodes is much easier. Apple defaults to six digits which is barely acceptable. It’ll be hard for a shoulder surfer to get all six digits. However, older users have four digit passcodes which is unacceptable.
The iPhone has four options:
- Four Digit Passcode
- Six Digit Passcode
- Digital Passcode up to 19 digits long
- Alphanumeric passcodes
The idea is to prevent the shoulder surfer from picking up the entire passcode. If the thief gets only four digits of a six digit passcode, they’ll have to guess the last two, they really can’t do any damage. After five attempts, the iPhone will take longer and longer to allow the next guess.
The idea is speed and length. Thus, option #3, an extra long digital passcode is the best option. You can type it pretty fast, and a shoulder surfer might not be able to pick up the code. Note that if you choose option #3 and your passcode is just six digits long, Apple will treat it as a six digit passcode. That means it’ll prompt you that the passcode is six digits. That will make it easy for. Shoulder surfer to pick up.
Option #4, Alpha numeric passcodes might be too slow for you to type, and if your passcode is a word, the shoulder surfer could pick that up.
I’ve noticed that Android still defaults to four digit passcodes. Even worse are the swipe pattern locks. I’m glad Apple never implemented them. I’ve been able to shoulder read swipe patterns without even trying. Heck, most people use the same swipe pattern — around the perimeter then diagonally from bottom right to top left. It’s like leaving your car keys in the toe of your shoe when you go swimming at the beach.
So setup TouchID and FaceID and use them. If you suddenly find yourself out and about and must use your passcode, check around you for shoulder surfers. Use either the extra long numeric passcode or an alphanumeric passcode that is not a simple word. Make sure you can type it fast without hunting and pecking.
If you speak a foreign language that uses a Non l-Latin alphabet, you can use your non-Latin keyboard for the passcode. Unless the thief is familiar with the language, they’ll probably never figure out your passcode.