Table of Contents

← Return to the Personal Security Course

Every control in the previous eleven modules assumes the device stays in your hands. Physical access invalidates a great deal of it. An unlocked laptop is a complete account compromise, a stolen phone is a second-factor loss, and a seized device is a question about whether your encryption holds.

This final module covers device control, document disposal, observation, and the biometric question which depends on your legal situation rather than your preferences.

Budget about 25 minutes. The device and biometric decisions are the ones with lasting consequences.

What You Will Learn

  • Assess the difference between theft risk and seizure risk
  • Apply physical controls proportionate to where you carry devices
  • Dispose of documents and media without leaving recoverable data
  • Recognize observation techniques including shoulder surfing and card skimming
  • Evaluate biometrics against a PIN for your own legal circumstances
  • Produce a physical security record and a completed course summary
TermMeaning
SeizureLawful or unlawful taking of a device by another party
Shoulder surfingReading a screen or keypad from a position you did not notice
SkimmerA device attached to a card reader to capture card data
CoercionCompelling a device unlock rather than defeating encryption
PerimeterThe physical boundary around a space containing assets

Theft and Seizure Are Different Problems

They overlap, and they drive opposite design decisions.

TheftSeizure
Who actsOpportunistic criminalAuthority or a known party
Primary lossThe hardware and the data on itThe data and its contents
Best controlEncryption plus remote wipeEncryption plus what you chose not to store
What helpsNot leaving devices visible, cable locksDevice power state, and knowing your rights

Shutting down rather than suspending matters here. A device in standby often holds decryption keys in memory, while a powered-off device requires the passphrase to reach the data. The distinction is the practical reason Module 8 recommended full power-off over standby.

The most effective seizure control is deciding in advance what does not belong on the device. Data you never stored is data nobody recovers.

Devices in the Physical World

  • Use cable locks where a device is left in a semi-public place, such as an office or a library
  • Keep devices out of sight in vehicles, and treat a charging cable on a seat as a signal something is under it
  • Carry a privacy screen in transit, which defeats most shoulder surfing
  • Enable remote wipe and confirm it works before you need it
  • Do not charge from unknown USB ports, as Module 7 covered. Prefer your own adapter

A short idle lock timeout is the highest-yield setting in this section. Most physical compromises of a device happen while it is unattended and unlocked, not while it is encrypted and powered off.

Documents and Disposal

Physical documents carry data which no encryption protects.

ItemDisposal Approach
Financial statementsShred, cross-cut rather than strip-cut
Identity documentsShred, and treat replacement as the better option where available
Medical recordsShred, since they frequently carry identity numbers
Old storage mediaDestroy physically. Overwriting is not reliable on all media, and a failed drive often still holds data
Delivery labelsRemove or obscure before discarding packaging

Watermark documents you share, with the recipient and date. It costs nothing, and it traces a leak to a specific copy if one appears somewhere unexpected.

Cross-cut shredding matters. Strip-cut shredders produce strips which are straightforward to reassemble.

Observation, and the Biometric Question

Being observed is subtle, and the countermeasures are simple.

  • Shield the keypad when entering a PIN, and clean the screen afterwards on touch devices where smudges reveal digits
  • Inspect card readers and ATMs for attached skimming hardware, and prefer readers which look untouched
  • Notice who is positioned to see your screen, and reposition rather than assuming nobody is looking

The biometric decision depends on your legal exposure, not your convenience.

MethodStrengthConsideration
BiometricConvenient, and difficult to guessIn some jurisdictions, compelling a finger or face carries different protections than compelling a passphrase
PIN or passphraseKnowledge you holdSlower, and vulnerable to observation

If compelled disclosure is a realistic concern, use a PIN or passphrase rather than biometrics. The reasoning is jurisdictional rather than technical, so it is a decision to make with awareness of where you live and work. Some devices allow biometrics to be disabled temporarily through a specific key combination, which is worth knowing in advance.

A related note on biometrics: your face is already photographed in public, which is the argument against treating facial recognition as a secret. A passphrase is not in any photograph.

Reducing Ongoing Exposure

Two items deserve attention because they persist without your involvement.

Crowdsourced and commercial image collection continues regardless of your participation. Cameras capture your movements, and privacy options are limited. Practical reductions include choosing less-monitored routes where it matters to you, and recognizing a friend’s public post reveals your location even if you post nothing.

CCTV and facial recognition are expanding in many cities. Awareness of where coverage is dense around your home and workplace is more useful than attempting to defeat it.

Our sibling project mapping ALPR camera locations illustrates how much surveillance infrastructure is publicly inferable: Flock Finder . Knowing the density near you is a starting point for planning, not a complete solution.

Diagram grouping physical security controls into devices, documents, and observation, showing encryption and remote wipe for devices, shredding and watermarking for documents, and observation countermeasures

The Physical Record

PHYSICAL SECURITY RECORD
Devices:
  Idle lock timeout:      ______________________
  Remote wipe tested:     yes / no
  Cable lock in use:      yes / no / n/a
  Privacy screen:         yes / no
  Full power-off habit:   yes / no

Documents:
  Shredder type:          cross-cut / strip-cut / none
  Documents watermarked:  yes / no
  Media destruction plan: ______________________

Observation:
  Lock method:            PIN (length __) / passphrase / biometric
  Biometrics disabled when needed: how? __________
  ATM and reader checks:  habit / sometimes / never

Exposure:
  CCTV awareness near home/work: reviewed / not reviewed

Course Summary: All Twelve Modules

You have now covered the full sequence. This table is the compressed version of the course.

ModuleThe one action which matters most
1. AuthenticationMove email and finance accounts to a passkey or hardware key
2. Web BrowsingBlock third-party cookies and install one content blocker
3. EmailTurn off automatic remote content loading
4. MessagingEnable contact verification and disappearing messages
5. Social MediaRemove birthday, school, and employer from your profile
6. NetworksChange the router admin password and disable WPS and UPnP
7. Mobile DevicesSet a carrier PIN and port freeze
8. Personal ComputersConfirm disk encryption and restore one file from backup
9. Smart HomeMove IoT devices to a separate network segment
10. Personal FinanceFreeze credit at all three bureaus
11. Human AspectSave verified contact numbers and agree a signal with family
12. Physical SecurityShorten the idle lock timeout and shut devices down fully

Next Steps

  1. Return to the course hub and review your completed records: Personal Security Course
  2. Read the four-tier summary for the whole course on one page: Prioritized Personal Security Checklist
  3. Go deeper with a community checklist if you want several hundred items: Personal Security Checklist by Alicia Sykes
  4. Apply the organizational checklists if you also manage systems: Every Checklist
  5. Use the local tools for anything involving a secret: All Client-Side Tools
  6. Revisit your threat model annually, since circumstances and adversaries change: How to Form Your Own Personal Threat Model