TechNewsReel
Live

Android 17 adds biometric lock to 'Mark as lost' to stop shoulder-surfing thieves

Google is upgrading its anti-theft suite to require fingerprints or face scans, closing a critical security gap for stolen devices.

TechNewsReel Newsroom · September 9, 2026

Google is tightening the security of its Android 17 Find Hub by requiring biometric authentication to regain access to a device marked as lost. The update aims to neutralize a common theft tactic where criminals observe a user's passcode before stealing the hardware.

Under the new system, the 'Mark as lost' feature now mandates biometric verification—such as a fingerprint or face unlock—in addition to the standard PIN or passcode. To further prevent thieves from disabling tracking or bypassing security, activating 'Mark as lost' now automatically hides the Quick Settings menu and blocks the device from joining any new Wi-Fi or Bluetooth networks.

The shoulder-surfing gap

Historically, Android's anti-theft tools relied primarily on the device PIN. This created a significant vulnerability known as "shoulder-surfing," where thieves watch a victim enter their code in a public space and then steal the phone. Once in possession of the PIN, the thief could often bypass existing locks to access the device or disable tracking features.

By shifting the trust from a knowable code to an immutable biometric identifier, Android 17 closes this gap. While a passcode can be observed, a fingerprint or face cannot be "watched" into, ensuring that the PIN alone is no longer a skeleton key for a stolen device.

Impact on device security

This shift transforms the lock screen from a simple barrier into a robust identity verification tool. By requiring a biometric match alongside the PIN, Google significantly increases the difficulty for thieves to access sensitive data, banking applications, and password managers.

Moreover, the restriction of Quick Settings and network connectivity prevents a thief from quickly putting the device into airplane mode or connecting to a rogue hotspot to manipulate the device's state. This ensures that the owner maintains a higher probability of tracking the hardware via Find My Device even after the phone has been stolen.

What to watch

While the core biometric requirements and connectivity blocks are confirmed for Android 17, users should monitor their specific device updates for the rollout of these Find Hub enhancements. The move signals a broader trend in mobile OS design where static passcodes are no longer considered sufficient for high-stakes security events like device theft. As mobile criminals evolve their tactics, the integration of multi-factor authentication at the hardware level becomes essential for protecting user privacy and recovering lost assets.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.