Kiosk lockdown
The admin PIN
Setting the PIN, the five-tap corner gesture, and what to do when somebody has forgotten it.
Setting it
On the device, before you enable the lockdown, open the admin area and set a PIN. Do this first. Enabling the lockdown on a device with no PIN set is how you end up reinstalling.
The PIN protects physical access to the device. The console has its own separate password protecting network access. They are deliberately not the same credential, because the people who need each are usually different people.
The gesture
Five taps in the bottom-left corner of the screen, then the PIN.
- It is in a corner because corners are the least likely place for a passer-by to touch.
- It is five taps because one or two happen by accident.
- It is in the bottom-left specifically so it can be described over the phone without ambiguity.
The taps must land in the corner region and in reasonably quick succession. On a very large screen, aim for the corner rather than "the bottom-left area".
Choosing one
- Not
1234, and not the shop's door code. - Written down somewhere that is not the device and not a sticker on its back.
- Known by at least two people. A single holder who leaves is a reinstall waiting to happen.
If it is forgotten
There is no recovery code and no reset link, because there is no account system to send one from. The options are:
- From the console, if you can still reach it on the network: change the PIN there.
- From adb, if debugging was left on: clear the app data. This removes layouts and media on that device.
- Reinstall the app. Same effect as above.
This is the trade for having no cloud: nobody can reset your device, including us. Keep the PIN somewhere sensible.
For a fleet
Layouts export and import as JSON, but the PIN is per device and set on the device. For a rollout, set it as part of the same pass in which you install the APK and turn the lockdown on, and record it in whatever your team already uses for door codes and switch passwords.