Kiosk · Buying

Android kiosk mode: the four things it has to do

A checklist for evaluating any kiosk software, and the questions that separate a real lockdown from a full-screen app.

3 min read UniKiosk

"Kiosk mode" is a phrase covering everything from a full-screen browser to device-owner enrolment. If you are evaluating, these four capabilities are the whole test.

1. It holds the system out of the way — and keeps holding it

Hiding the status and navigation bars is easy. Keeping them hidden is the part that separates products.

Android re-shows the bars when somebody swipes from an edge. A real kiosk app pushes them back immediately, which on Android requires the overlay permission. If the product does not ask for that permission, one swipe and your device is browsable.

The test: deploy it, then swipe up from the bottom edge ten times quickly. If you ever see a persistent bar, it is not a lockdown.

2. It swallows the keys

Home, recents and back must be swallowed, not intercepted-and-ignored. The difference is visible: a product that intercepts shows a flicker of the launcher as it bounces back, which tells any curious person exactly what to keep pressing.

The test: press home repeatedly. You should see nothing at all.

3. It recovers on its own

A public screen must come back from a reboot and a power cut without a site visit. That means starting on boot, re-engaging the lockdown, and resuming the board — in that order and without a prompt.

The test: pull the power out of the wall while it is running. Plug it back in. Walk away for five minutes. Come back. If the board is not up, you have bought a maintenance contract with yourself.

This is the test people skip and the one that predicts almost all future call-outs.

4. There is a deliberate way back in

Somebody authorised has to get out, without a laptop and without a cable.

The design constraints pull against each other: discoverable enough to describe over the phone, obscure enough that the public never finds it, and memorable enough that staff who do it twice a year still can.

Our answer is five taps in the bottom-left corner, then a PIN. A visible button is a button members of the public will press. A gesture is a thing staff forget. A corner tap count is describable in one sentence.

The test: ask somebody who has never seen it to get back in, using only a sentence you say to them down a phone.

What none of it does

Physical access beats software, always:

  • The power button turns the device off. Nothing prevents that.
  • Safe mode disables third-party apps. Only device-owner provisioning prevents that.
  • adb over USB opens the device, if debugging is on and the port is reachable.

Any product claiming otherwise without device-owner enrolment is overselling. The mitigations are an enclosure, USB debugging off, and a covered port.

The evaluation checklist

Print this and run it on the actual device:

  • Swipe from every edge, ten times. Bars stay hidden?
  • Press home and recents repeatedly. Nothing flickers?
  • Reboot. Board comes back unattended?
  • Pull the mains. Board comes back unattended?
  • Can a colleague get back in from a one-sentence instruction?
  • With USB debugging off, is anything else reachable?

Six checks, ten minutes, on one device, before you buy fifty. Our lockdown documentation walks through each of these on the shipped build, including what it does not do.

Free, and there is nothing to cancel.

One APK, no account, no per-screen fee.