Some operating systems and apps offer “nearby” or “proximity” logins that approve a new device when it’s physically close to one you already use. It feels convenient—hold your phone near a laptop, tap approve, and you’re in. But convenience can blur the lines of strong multi-factor authentication (MFA). If a nearby handshake skips, softens, or replaces a second factor, a new device could be added to your account with less verification than you expect. This guide explains what these handshakes are, the risks, how to disable them, and safer alternatives you can use instead.
What Is a “Nearby Login” Handshake?
A nearby login handshake is a short-range device approval flow—often over Bluetooth, NFC, Wi‑Fi Direct, or ultra-wideband—where an already trusted device helps sign in or add a new device. Examples include approving a sign-in prompt that pops up because two devices are close, tapping to transfer credentials, or scanning a setup animation that swaps keys wirelessly.
Done correctly, proximity can supplement MFA (something you have + something nearby). Done poorly, it can become a single point of failure: a tap on a locked screen, a misleading prompt, or an approval that bypasses a real second factor (like a one‑time code or a hardware security key).
Why It Can Be Risky
- MFA dilution: If the proximity prompt doubles as both “prove possession” and “approve login,” it can reduce MFA to a single gesture.
- Prompt bombing nearby: Attackers in shared spaces (coffee shops, conferences, transit) can trigger repeated nearby approval prompts, relying on confusion or mis-taps.
- Shoulder-surfing and social engineering: A convincing pop-up like “Finish setting up your device” can look legitimate enough to approve under pressure.
- Hidden pairing: Some flows add trust relationships in the background, making it easier for the attacker’s device to request future approvals.
- Mixed ecosystems: Third-party apps may implement proximity logins inconsistently, weakening the overall security model.
How to Decide: Disable or Restrict?
If you travel, work in crowded environments, share living spaces, or manage sensitive accounts, it’s safer to disable nearby logins entirely and rely on stronger MFA (authenticator apps or hardware security keys). If you keep proximity features, lock them down so they never replace the second factor—at most, they should add friction, not remove it.
How to Disable or Tighten Nearby Logins by Platform
The goal is to turn off any feature that lets a nearby device approve sign-ins, add devices, or transfer credentials without a full MFA step. Specific setting names vary by version; when in doubt, search your settings for “nearby,” “proximity,” “hand off,” “sign-in,” “pairing,” “tap to sign in,” or “quick start.”
Apple: iPhone, iPad, and Mac
- Turn off device-to-device setup helpers when adding new devices: During new iPhone/iPad/Mac setup, avoid “Quick Start” or “Set Up with iPhone.” Choose manual sign-in and complete full MFA using your Apple ID, password, and code from a trusted device.
- Disable AirDrop to Contacts Only or Off: Settings > General > AirDrop > set to Contacts Only or Receiving Off to reduce unsolicited nearby interactions.
- Disable Handoff (if you don’t use it): iOS/iPadOS: Settings > General > AirPlay & Handoff > Handoff > Off. macOS: System Settings > General > AirDrop & Handoff > Handoff > Off. This cuts down on cross-device prompts.
- Require stronger MFA for Apple ID: Keep Two-Factor Authentication on, and under Password & Security, review Trusted Phone Numbers and remove any you no longer use. Do not approve Apple ID login prompts unless you initiated the action.
- Bluetooth hygiene: Turn off Bluetooth when not needed or set it to be non-discoverable. iOS is non-discoverable by default, but toggling Bluetooth off in Settings (not just Control Center) reduces ambient pairing attempts.
- Review trusted devices: Settings > [Your Name] > scroll to devices. Remove any device you don’t recognize.
Android and ChromeOS (Google Account)
- Disable Nearby Share for credentials: Settings > Google > Devices & sharing > Nearby Share. Set to Off or restrict to Your devices only, and do not share credentials or QR-based logins via Nearby Share.
- Disable Fast Pair permissions you don’t need: Settings > Connected devices > Connection preferences > Fast Pair. Turn off scanning or revoke permissions that enable auto-pairing prompts.
- Google Prompts and passkeys: Visit myaccount.google.com > Security. If you use Google Prompts, ensure they are tied to your device only and consider replacing with physical security keys. Manage Passkeys and delete any you don’t recognize.
- Smart Lock tightening: Settings > Security > Advanced settings > Smart Lock. Disable On-body detection and Trusted devices (Bluetooth) so a nearby device can’t keep your phone unlocked.
- ChromeOS Smart Lock: On your Chromebook: Settings > Connected devices > Android phone. Turn off Smart Lock (unlock Chromebook with your phone) if you don’t need it.
- Review your Google Account devices: myaccount.google.com > Security > Your devices. Sign out any device you don’t recognize and change your password if you see suspicious activity.
Windows and Microsoft Accounts
- Turn off Dynamic Lock and proximity unlocks you don’t need: Settings > Accounts > Sign-in options > Dynamic Lock. Uncheck “Allow Windows to automatically lock your device when you’re away,” and avoid enabling any third-party proximity unlock add-ons.
- Windows Hello security baseline: Require PIN with TPM, fingerprint, or camera—but do not approve new device sign-ins through proximity gadgets. Stick to direct MFA with your Microsoft account.
- Disable Bluetooth discovery: Settings > Bluetooth & devices. Remove unknown devices and toggle Bluetooth off when not in use.
- Microsoft Account security: account.microsoft.com > Security. Review Advanced security options, disable any “one-tap” approvals you don’t use, and prefer authenticator-app or security-key based MFA. Remove unrecognized sign-in methods.
Browsers and Passkeys
- Passkeys can be safe—if scoped correctly: Passkeys stored on-device or in a hardware key are strong. The risk is when websites or apps allow “nearby device” approvals that transfer a passkey without rigorous confirmation.
- Review and prune passkeys: Chrome: Settings > Autofill & passwords > Passkeys. Edge: Settings > Profiles > Passwords > Passkeys. Safari (macOS): System Settings > Passwords. Delete passkeys for accounts you don’t recognize or don’t want stored on that device.
- Disable cross-device sharing where possible: Turn off automatic sync of credentials across devices you do not fully control. Use browser profiles that don’t sync sensitive accounts.
Safer Alternatives to Nearby Logins
- Hardware security keys (FIDO2/WebAuthn): Use a primary and backup key. They require a deliberate, physical touch, stop push-bombing, and can’t be silently transferred by proximity features.
- Authenticator apps: Use time-based one-time codes (TOTP) or app-based prompts with number matching or location details. Do not approve any prompt you did not initiate.
- Independent device enrollment: When adding a new phone or laptop, sign in manually, then complete MFA directly on that device. Avoid “copy your account from a nearby device” wizards.
- Limited Bluetooth usage: Keep Bluetooth off in public if you don’t need it, and set devices to non-discoverable to reduce drive-by prompts.
How to Spot and Stop a Suspicious Nearby Prompt
- Check context: Did you just try to sign in? If not, deny the prompt.
- Verify details: Legit prompts often show location, browser/OS, or a number to match. If anything looks off, reject.
- Look for repetition: Multiple prompts in a row can be push-bombing. Deny all and change your password.
- Move away or disable radios: Turn off Bluetooth and Wi‑Fi and step away from crowds if prompts keep reappearing.
- Audit devices and sessions: Visit your account’s security page (Apple, Google, Microsoft, etc.) to sign out unfamiliar sessions and remove unknown devices.
Checklist: Lock Down Proximity and Device Enrollment
- Turn off “nearby,” “proximity,” “tap to sign in,” and auto-pairing features you don’t need.
- Require strong MFA using an authenticator app or hardware security keys.
- Disable Bluetooth discovery and remove unknown paired devices.
- Avoid quick-setup flows that copy credentials from another device.
- Review trusted devices, passkeys, and sign-in methods monthly.
- Reject any approval prompt you didn’t initiate and change your password immediately if they persist.
When This Matters Most
Proximity features amplify risk in hotels, coworking spaces, conferences, campuses, airports, and public transit—anywhere an attacker can get physically close. They also matter for shared households, where family devices may accidentally approve prompts for the wrong account.
Identity Protection Tip
Even with proximity features disabled, attackers may still try account takeovers through phishing, SIM swapping, or credential stuffing. Pair strong MFA with ongoing monitoring of your financial identity. If you want a single place to keep an eye on changes that could indicate identity misuse—like unexpected credit pulls, new accounts, or fraud alerts—consider a dedicated monitoring tool. For an option that combines privacy-minded credit and identity monitoring, see SmartCredit for privacy, credit monitoring, and identity protection.
Frequently Asked Questions
Does turning off nearby logins break other features?
Usually not. You can keep everyday Bluetooth accessories and still disable proximity-based account approvals, quick-setup wizards, and Smart Lock features. Test your workflow after changes.
Are passkeys vulnerable to nearby attacks?
Passkeys themselves are strong. The risk lies in permissive device-to-device transfers or approvals that add a passkey to a new device without full confirmation. Manage where your passkeys live and require a hands-on step (like a hardware key touch).
What if my organization enforces proximity unlocks?
Talk to IT about requiring additional factors (e.g., Windows Hello with security keys) and disabling auto-approval for new devices. Enterprise policies can scope proximity to unlocking only, not account enrollment.
How often should I review trusted devices?
Monthly is a good cadence, and any time you notice unusual prompts, travel, or change your phone number.
Conclusion
Nearby login handshakes blur convenience with security—and when they sidestep a true second factor, they open a door for attackers within radio range. Disable or strictly limit proximity-based approvals, enroll new devices with full MFA, and manage where your credentials and passkeys reside. Combine those habits with regular device and session reviews, and you’ll keep convenience from quietly undercutting your account security—and your identity.
Good to Know
If you ever see a surprise “Is this you?” or “Add this device?” prompt, deny it, change your password, and review recent logins. Unexpected proximity prompts can be a sign someone nearby is trying to piggyback onto your account.