Skip to main navigation Skip to search Skip to main content

Shoulder Surfing through the Social Lens: A Longitudinal Investigation & Insights from an Exploratory Diary Study

Habiba Farzand*, Karola Marky*, Mohamed Khamis*

*Corresponding author for this work

Research output: Chapter in book/report/conference proceedingConference contributionResearchpeer review

Abstract

Shoulder surfing is a prevailing threat when accessing information on personal devices like smartphones. Adequate mitigation requires studying shoulder surfing occurrences in people's daily lives. In this paper, we confirm and extend previous research findings on shoulder surfing occurrences using a new method; a one-month diary study (N=23). Our results provide evidence of shoulder surfing in public and private environments. Content-based shoulder surfing happens more frequently than authentication-based shoulder surfing. Participants experienced shoulder surfing at least twice during the study period and considered the closeness of relationships with the shoulder surfers when deciding how to respond to shoulder surfing incidents. Participants preferred unobtrusive alerting mechanisms over mitigation mechanisms for protection against shoulder surfing. Our work advocates moving away from one-size-fits-all privacy solutions and supports the design of user-centred shoulder surfing mitigation methods that consider social aspects. We conclude with directions for future research to assist security researchers and practitioners.

Original languageEnglish
Title of host publicationProceedings - EuroUSEC 2022
Subtitle of host publication2022 European Symposium on Usable Security, EuroUSEC 2022
PublisherAssociation for Computing Machinery (ACM)
Pages85-97
Number of pages13
ISBN (Electronic)9781450397001
DOIs
Publication statusPublished - 29 Sept 2022
Event2nd European Symposium on Usable Security, EuroUSEC 2022 - Karlsruhe, Germany
Duration: 29 Sept 202230 Sept 2022

Publication series

NameACM International Conference Proceeding Series

Conference

Conference2nd European Symposium on Usable Security, EuroUSEC 2022
Country/TerritoryGermany
CityKarlsruhe
Period29 Sept 202230 Sept 2022

Keywords

  • privacy
  • security
  • shoulder surfing

ASJC Scopus subject areas

  • Human-Computer Interaction
  • Computer Networks and Communications
  • Computer Vision and Pattern Recognition
  • Software

Cite this