diff --git a/README.md b/README.md index 6a59caa..9ba671c 100644 --- a/README.md +++ b/README.md @@ -7,7 +7,7 @@
- Look at the screen and it unlocks: the lock screen, sudo and admin prompts. A photo of you is not enough. + Look at the screen and it unlocks: the lock screen, sudo and admin prompts. A photo on a phone does not fool it.
-
+
@@ -100,8 +100,10 @@ Without the menu: `plasma-face-unlock enable`, `disable`, `setup [NAME]`, `faces It is a convenience, not a security upgrade. Face ID on a phone sees your face in 3D. A webcam only sees a flat picture. -- A photo does not get in: the face has to blink or turn a little, and a photo can do neither. -- A phone or tablet held up to the camera is caught by its reflection and its straight edges. +- You do not have to blink. A photo on a phone or tablet, or a glossy print, is still refused: + it gives itself away by its reflection and its straight edges. +- A matte printed photo can get past that. Set the photo check to *strict* in the settings: then + the face has to blink or turn a little, and a photo can do neither. - A video of you can still get in. - Five failed tries in a row pause it for 15 minutes, or until you use your password. - Only root can read your face data. Adding or deleting a face always needs your password. diff --git a/doc/plasma-face-unlock.1.scd b/doc/plasma-face-unlock.1.scd index 9db7eb0..ba71e58 100644 --- a/doc/plasma-face-unlock.1.scd +++ b/doc/plasma-face-unlock.1.scd @@ -12,8 +12,8 @@ plasma-face-unlock - face unlock for KDE Plasma Look at the screen and it unlocks, the way a phone does. The lock screen, sudo in a terminal and the admin password prompts of Plasma can all take a face -instead of a password. Before a face counts, it has to show a sign of life, so -holding up a photo of somebody is not enough. +instead of a password. A photo of somebody on a phone or tablet does not get +in, and with the strict photo check a printed one does not either. A bubble at the top of the screen shows what is going on: it drops down when the camera starts looking, the face in it looks around, and when it recognises @@ -128,14 +128,18 @@ Confirm cues are evidence of a real head. *strict* needs one of them: real turn, measured without the nose's own jitter, and the face has to narrow no more than a head that turned that far would. -*basic* uses the deny cues only. *off* checks nothing and is only for trying -out a camera. +*basic*, the default, uses the deny cues only: nobody has to blink, and a +phone, a tablet or a glossy print held up is still refused. A matte printed +photo is not, so *strict* is the one to pick when that matters. *off* checks +nothing and is only for trying out a camera. # HOW SAFE IS THIS A webcam sees a flat picture. A phone's face unlock builds a depth map with a projector and an infrared camera; this cannot. What the photo check does: +- a photo on a phone or tablet, or a glossy print, is refused by *basic*, the + default. A matte printed photo can get past *basic*; - a photo, printed or on a screen, held up and turned any way, is refused by *strict*; - a photo curled strongly and turned a lot can pass the head turn cue some of diff --git a/packaging/deb/control b/packaging/deb/control index b0fb9ef..c4d05b8 100644 --- a/packaging/deb/control +++ b/packaging/deb/control @@ -13,10 +13,12 @@ Description: face unlock for KDE Plasma instead of a password. A bubble at the top of the screen, above the lock screen too, shows the face being looked for, recognised or refused. . - Before a face counts it has to show a sign of life (a blink, or the nose - moving the way a real nose does when the head turns), so a photo held up to - the camera is not enough. It is a convenience, not a security upgrade: a - webcam sees a flat picture, and a video of the person can get through. + A photo on a phone, a tablet or a glossy print is refused by its + reflection and its straight edges. The strict photo check also wants a sign + of life (a blink, or the nose moving the way a real nose does when the head + turns), which stops a printed photo too. It is a convenience, not a security + upgrade: a webcam sees a flat picture, and a video of the person can get + through. . Everything runs on the machine. Faces are stored as numbers readable only by root, never as pictures. Run "plasma-face-unlock disable" before removing diff --git a/packaging/rpm/plasma-face-unlock.spec b/packaging/rpm/plasma-face-unlock.spec index 3e12757..1f7b573 100644 --- a/packaging/rpm/plasma-face-unlock.spec +++ b/packaging/rpm/plasma-face-unlock.spec @@ -53,9 +53,10 @@ in a terminal and the admin password prompts of Plasma can take a face instead of a password. A bubble at the top of the screen, above the lock screen too, shows the face being looked for, recognised or refused. -Before a face counts it has to show a sign of life (a blink, or the nose moving -the way a real nose does when the head turns), so a photo held up to the camera -is not enough. It is a convenience, not a security upgrade: a webcam sees a +A photo on a phone, a tablet or a glossy print is refused by its reflection and +its straight edges. The strict photo check also wants a sign of life (a blink, +or the nose moving the way a real nose does when the head turns), which stops a +printed photo too. It is a convenience, not a security upgrade: a webcam sees a flat picture, and a video of the person can get through. Run "plasma-face-unlock disable" before removing this package, so that sudo diff --git a/res/screenshots/bubble.png b/res/screenshots/bubble.png index 892a7be..7fc24a0 100644 Binary files a/res/screenshots/bubble.png and b/res/screenshots/bubble.png differ diff --git a/res/screenshots/unlock.webp b/res/screenshots/unlock.webp index 3f580c5..91a0f1a 100644 Binary files a/res/screenshots/unlock.webp and b/res/screenshots/unlock.webp differ diff --git a/src/core/settings.h b/src/core/settings.h index 54394b8..148e91f 100644 --- a/src/core/settings.h +++ b/src/core/settings.h @@ -30,7 +30,9 @@ struct Settings { // A /dev/video path, "auto", or for testing "file: