0%
BACK TO OVERVIEW

Shoulder Surfing 2.0: How Thermal Cameras, Telephoto Lenses, and Smartphone Photos Bypass Your Access Control

Shoulder Surfing 2.0: How Thermal Cameras, Telephoto Lenses, and Smartphone Photos Bypass Your Access Control

Eight minutes after entry, your PIN code is still glowing

A security researcher stands in front of a PIN pad at an office building with a commercial thermal camera. The last entry was eight minutes ago. Despite this, four keys are significantly warmer than the others—the residual heat from fingertips still clearly shows which digits were pressed. Two of them glow brighter: the ones pressed last. This narrows down a four-digit code to just two or three possible combinations. Total effort: a budget thermal imaging attachment for a smartphone and thirty seconds of patience.

This isn't a lab experiment. Thermal attacks on PIN pads were systematically documented in 2017 by researchers at UC San Diego and work reliably on plastic keyboards even at normal room temperatures. But thermal imaging is just one tool in a broader spectrum of visual exploitation—starting with binoculars and ending with a smartphone photo of an ID badge.

Shoulder Surfing 2.0 is not an attack that requires proximity. It requires a clear line of sight and the right tools. Anything visible to the human eye is potentially readable—from distances no one expects, using devices anyone can buy.

8 min
Residual heat readable on PIN pads after entry
10–15m
Effective distance for thermal attack
3 Clicks
From badge photo to print-ready copy
<200 EUR
Cost of thermal smartphone attachment

Visual Exposure: The Underestimated Attack Vector

Most security concepts focus on access control: Who has a badge, who knows the code, who has authorization. Visual attacks bypass these questions entirely. They don't ask for authorization—they observe it. The goal is not the access itself, but the information that enables it.

Visual exposure occurs wherever security-relevant information exists in a visible medium: on a display, a keypad, an ID badge, a screen in an open-plan office, or even a Post-it note under a keyboard. The attack surface is the entire visual environment of an employee—and it is rarely fully addressed in any security concept.

Technical access control ends the moment a human enters their code or wears their badge visibly. What the eye can see, an attacker can document—using tools available at any electronics store.

The Four Attack Vectors of Visual Exposure

Vector 01 // Critical
Thermal Attack on PIN Pads
Residual fingertip heat on plastic keypads remains detectable in thermal images for up to 8 minutes. Brighter = most recently pressed. This allows for partial reconstruction of the entry sequence.
FLIR One · InfiRay · Seek Thermal · Android/iOS attachment · from ~150 EUR
Vector 02 // High
Optical Recon: Badge Data from Afar
High-resolution cameras or telephoto lenses can capture badge numbers, company logos, employee photos, departments, and access levels from 10–30 meters away. Visibility equals documentation.
DSLR Telephoto · Smartphone Zoom · Binoculars with camera adapter
Vector 03 // High
Badge Photo and Print Copy
A single clear photo of a visible badge is enough for an optically convincing printed copy. No RFID clone needed—visual imitation suffices for tailgating and pretext attacks.
Smartphone Photo · Canva / Image Editing · Color Printer + Laminator
Vector 04 // Medium
Screen Shoulder Surfing
Passwords, confidential data, and internal systems visible on screens in public areas, trains, or open offices. Risks include hotel lobby meetings and coworking spaces.
Direct Sight · Window reflections · Remote camera recording

Thermal Attack in Detail: Physics and Practice

Thermal attacks work because plastic is a poor thermal conductor. Body heat from a fingertip (~34°C contact temperature) stays on the key surface significantly longer than on metal. A thermal camera with a 160×120 resolution—found in cheap smartphone attachments—is sufficient to detect this difference.

0 – 30s
All pressed keys clearly visible. Temperature difference is sharp; entry sequence partially reconstructible via brightness levels.
Complete
30s – 3 min
Pressed keys still clearly recognizable. Sequence is harder to determine, but the specific digits entered are unmistakable.
Partial
3 – 8 min
Still detectable on plastic keypads, already faded on metal pads. The digit group used can often still be identified.
Limited
> 8 min
Signal too weak for reliable analysis at room temperature. Hot weather or heated surfaces may reduce this window.
None

Metallic keypad surfaces dissipate heat faster and are significantly more resistant to thermal attacks. PIN pads with metal keys, active thermal mixing (randomly heating all keys), or randomized key layouts are technical countermeasures—not just a PIN policy.

The Badge Photo: Three Clicks to a Print Copy

A badge serves two functions: it is a technical access credential (RFID/NFC chip) and a visual identification tool (print, photo, color, logo). Most security concepts protect the technical function—using cryptography, mutual authentication, or Wiegand replacements. The visual function is almost never addressed.

What a badge photo reveals to an attacker
Logo & Design Basis for a convincing print copy. Logos are publicly available; color schemes and layouts are visible in the photo. Sufficient for tailgating and pretext attacks.
Employee Photo Individual identification for social engineering, impersonation, and targeted phishing attacks with personalized context.
Name & Department Direct OSINT value: Name + Company + Dept = complete LinkedIn profile in one step. Starting point for spear-phishing and pretext development.
Access Level / Color Code Many companies indicate access levels via badge colors. The attacker knows which areas the employee is authorized to enter—and which copy they need.
Badge Serial Number Visible serial numbers allow for direct replication onto writable RFID emulators (T5577, MIFARE) in systems without mutual authentication.

A printed badge look-alike doesn't need to work to be useful. In a pretext attack, an optically convincing copy is enough to appear legitimate at receptions, during tailgating, or when conversing with staff. RFID function is optional; visual persuasion is the real tool.

Full Attack Chain: From Observation to Entry

Step 01
Visual Recon
Observation of the entrance area: map PIN pad types, badge designs, employee behavior, camera angles, and blind spots.
Step 02
Data Collection
Thermal imaging after PIN entry, telephoto lenses for badge photos, direct observation of codes, or reflections for screen content.
Step 03
Preparation
Narrow down PIN combinations, create badge print copies, copy serial numbers to emulators, and refine pretexts with gained context.
Step 04
Access
PIN entry with reconstructed code, tailgating with convincing badge copy, or a combination of both vectors.

Why Technical Measures Alone Aren't Enough—And Which Policies Make the Difference

Visual attack vectors cannot be fully closed by technology. Thermal-resistant PIN pads and cryptographically secured badges solve part of the problem—but not the part rooted in human behavior. Wearing a badge outside a jacket, exposing a screen on a train, or entering a PIN without cover creates an attack surface no technical system can shield.

Policy 01 // Mandatory
Concealed Badge Wear
Badges must be kept in protected carriers or worn concealed, only shown actively. Never visible outside on a jacket, hanging freely on a lanyard, or left on desks. Applies to break areas and leaving the building.
Policy 02 // Mandatory
Shield PIN Entry
Active hand-covering during every PIN entry as a mandatory behavioral rule—not just a recommendation. Applies to PIN pads, ATMs, and access systems. This significantly reduces the thermal attack vector.
Policy 03 // Recommended
Clean Desk & Clear Screen
Lock screens when leaving the workstation (Windows + L / Cmd + Ctrl + Q). Do not leave password notes or badges on the desk. Use privacy filters for laptops in public areas or while traveling.
Policy 04 // Recommended
Minimize Badge Design
Do not communicate access levels via front-facing colors or text. Do not print serial numbers on the exterior. Keep employee photos and names on the back or in digital form on the chip.

Badge policies only work when lived—not just when written in a handbook. The most effective measure is a corporate culture where shielding your PIN and concealing your badge is as natural as buckling a seatbelt. This is built through regular simulation, not training slides.

Visual Attack Vectors: Effort, Cost, and Impact

Attack Vector Required Tool Cost Countermeasure Risk
Thermal Attack PIN Pad (Plastic) Thermal camera attachment from ~150 EUR Metal keypad, thermal mix, hand shielding CRITICAL
Badge Photo for Print Copy Smartphone camera 0 EUR Concealed wear, minimal design CRITICAL
Optical Badge SN Capture Telephoto lens / Zoom camera from ~100 EUR Serial number interior / chip-only HIGH
Direct PIN Observation Direct sight / Reflection 0 EUR Visual shield, hand covering, camera angles HIGH
Photographing Screen Content Smartphone 0 EUR Privacy filters, Clean Screen policy MEDIUM
Thermal Attack PIN Pad (Metal) High-end thermal camera from ~800 EUR Inherently more resistant via conductivity MEDIUM

Hardening Against Visual Attacks

  • PIN Pads with Metal Surfaces or Active Thermal Mixing: Metal keypads dissipate heat much faster than plastic. Systems with active thermal mixing—where all keys are slightly heated—completely neutralize thermal attacks. This should be a selection criterion for new installations.
  • Randomized Key Layouts: Some ACS manufacturers offer pads with layouts that change with each entry. Even if keys are thermally identifiable, their position changes every time, making the attack ineffective.
  • Mandatory Badge Holders with Privacy Shields: Use holders that are opaque on the front or have a flip mechanism, showing the badge only when actively presented. These cost very little and close the badge photo vector entirely.
  • Harden Badge Design against Info Exposure: Do not encode access levels with front-facing colors. Keep serial numbers in the chip only. Place employee photos and names on the back or in digital credentials.
  • Analyze Camera Angles for PIN Pad Areas: Check if your own surveillance cameras capture PIN entry areas. If so, adjust angles. This also reveals positions an attacker might use—showing where visual shields are necessary.
  • Privacy Filters for Mobile Devices: Mandatory for all employees who travel regularly or work in public. Privacy filters reduce the viewing angle to ~60 degrees, making screens unreadable to side observers.
  • Explicitly Test Visual Vectors in Pentests: A physical security audit should include thermal PIN pad capture, badge photo simulation, and screen shoulder surfing as explicit test cases. What we find in a test, an attacker will find too.

Visual security costs almost nothing – a shielded badge holder, a privacy filter, and a practiced PIN covering routine close the most common vectors. The investment in policy and habit is orders of magnitude smaller than the potential damage of a successful badge clone or PIN theft.

Conclusion: What the Eye Sees, an Attacker Can Use

Shoulder surfing hasn't disappeared; it has become high-tech. The core question remains: What can an attacker see given the right moment and location? The answer has expanded dramatically through affordable thermal cameras, high-res smartphone lenses, and trivial image editing.

The badge hanging on a jacket. The plastic PIN pad without a shield. The laptop on a train without a filter. Each of these is a complete attack vector—not hypothetical, but regularly exploited in audits. And each can be closed with simple, cost-effective measures.

Security doesn't end at technical access control. It ends at the limit of the visible.

Do you know what an attacker sees with a thermal camera at your entrance?

We test visual attack vectors—thermal imaging, badge exposure, screen visibility—and provide concrete policy recommendations per location.

Request Visual Security Audit →
```
Tags // #PhysicalPentest #RedTeam #ShoulderSufring #ThermalAttack #BadgePolicy

© AccessGranted X GmbH