Invisible input and output modalities, such as haptics and audio, are a potentially effective defense against observation-based attacks on PIN entry systems. However, the successful implementation of such systems calls for some general design guidelines.