“…Users are often unaware of bystanders [10], especially whilst being immersed in VR [14,27], who were shown to be able to infer the VR user's input (e.g., PINs) [14,16,40]. As researchers and practitioners in VR are very keen in creating immersive and mature technologies to increase users' experience and embed such novel technologies into our mundane life [18,36], research to protect actual users against attacks (e.g., observation attacks, guessing attacks, or video attacks where attackers record and play back user's authentication [8,15]) is still limited. RubikBiom protects users from such attacks even if attackers have access to the correct secret as it provides users with an additional security layer.…”