feat: make the basic photo check the default, no blink needed

This commit is contained in:
Felitendo committed 2026-09-23 22:20:04 +02:00
1 parent 8129215d06
commit 10b4d91eec
9 files changed
+29 -18

No files matched your search

+6 -4
View File
@@ -7,7 +7,7 @@
<h3 align="center">Face ID for KDE Plasma.</h3> <h3 align="center">Face ID for KDE Plasma.</h3>
<p align="center"> <p align="center">
Look at the screen and it unlocks: the lock screen, sudo and admin prompts. A photo of you is not enough. Look at the screen and it unlocks: the lock screen, sudo and admin prompts. A photo on a phone does not fool it.
</p> </p>
<h5 align="center"> <h5 align="center">
@@ -22,7 +22,7 @@
</p> </p>
<p align="center"> <p align="center">
<img src="res/screenshots/unlock.webp" alt="The bubble drops down over the lock screen, the face in it looks around, asks for a blink, and two green rings spin and land around a tick" width="480"> <img src="res/screenshots/unlock.webp" alt="The bubble drops down over the lock screen, the face in it looks around, and two green rings spin and land around a tick" width="480">
</p> </p>
<p align="center"> <p align="center">
@@ -100,8 +100,10 @@ Without the menu: `plasma-face-unlock enable`, `disable`, `setup [NAME]`, `faces
It is a convenience, not a security upgrade. Face ID on a phone sees your face in 3D. A webcam only It is a convenience, not a security upgrade. Face ID on a phone sees your face in 3D. A webcam only
sees a flat picture. sees a flat picture.
- A photo does not get in: the face has to blink or turn a little, and a photo can do neither. - You do not have to blink. A photo on a phone or tablet, or a glossy print, is still refused:
- A phone or tablet held up to the camera is caught by its reflection and its straight edges. it gives itself away by its reflection and its straight edges.
- A matte printed photo can get past that. Set the photo check to *strict* in the settings: then
the face has to blink or turn a little, and a photo can do neither.
- A video of you can still get in. - A video of you can still get in.
- Five failed tries in a row pause it for 15 minutes, or until you use your password. - Five failed tries in a row pause it for 15 minutes, or until you use your password.
- Only root can read your face data. Adding or deleting a face always needs your password. - Only root can read your face data. Adding or deleting a face always needs your password.
+8 -4
View File
@@ -12,8 +12,8 @@ plasma-face-unlock - face unlock for KDE Plasma
Look at the screen and it unlocks, the way a phone does. The lock screen, sudo Look at the screen and it unlocks, the way a phone does. The lock screen, sudo
in a terminal and the admin password prompts of Plasma can all take a face in a terminal and the admin password prompts of Plasma can all take a face
instead of a password. Before a face counts, it has to show a sign of life, so instead of a password. A photo of somebody on a phone or tablet does not get
holding up a photo of somebody is not enough. in, and with the strict photo check a printed one does not either.
A bubble at the top of the screen shows what is going on: it drops down when A bubble at the top of the screen shows what is going on: it drops down when
the camera starts looking, the face in it looks around, and when it recognises the camera starts looking, the face in it looks around, and when it recognises
@@ -128,14 +128,18 @@ Confirm cues are evidence of a real head. *strict* needs one of them:
real turn, measured without the nose's own jitter, and the face has to real turn, measured without the nose's own jitter, and the face has to
narrow no more than a head that turned that far would. narrow no more than a head that turned that far would.
*basic* uses the deny cues only. *off* checks nothing and is only for trying *basic*, the default, uses the deny cues only: nobody has to blink, and a
out a camera. phone, a tablet or a glossy print held up is still refused. A matte printed
photo is not, so *strict* is the one to pick when that matters. *off* checks
nothing and is only for trying out a camera.
# HOW SAFE IS THIS # HOW SAFE IS THIS
A webcam sees a flat picture. A phone's face unlock builds a depth map with a A webcam sees a flat picture. A phone's face unlock builds a depth map with a
projector and an infrared camera; this cannot. What the photo check does: projector and an infrared camera; this cannot. What the photo check does:
- a photo on a phone or tablet, or a glossy print, is refused by *basic*, the
default. A matte printed photo can get past *basic*;
- a photo, printed or on a screen, held up and turned any way, is refused by - a photo, printed or on a screen, held up and turned any way, is refused by
*strict*; *strict*;
- a photo curled strongly and turned a lot can pass the head turn cue some of - a photo curled strongly and turned a lot can pass the head turn cue some of
+6 -4
View File
@@ -13,10 +13,12 @@ Description: face unlock for KDE Plasma
instead of a password. A bubble at the top of the screen, above the lock instead of a password. A bubble at the top of the screen, above the lock
screen too, shows the face being looked for, recognised or refused. screen too, shows the face being looked for, recognised or refused.
. .
Before a face counts it has to show a sign of life (a blink, or the nose A photo on a phone, a tablet or a glossy print is refused by its
moving the way a real nose does when the head turns), so a photo held up to reflection and its straight edges. The strict photo check also wants a sign
the camera is not enough. It is a convenience, not a security upgrade: a of life (a blink, or the nose moving the way a real nose does when the head
webcam sees a flat picture, and a video of the person can get through. turns), which stops a printed photo too. It is a convenience, not a security
upgrade: a webcam sees a flat picture, and a video of the person can get
through.
. .
Everything runs on the machine. Faces are stored as numbers readable only by Everything runs on the machine. Faces are stored as numbers readable only by
root, never as pictures. Run "plasma-face-unlock disable" before removing root, never as pictures. Run "plasma-face-unlock disable" before removing
+4 -3
View File
@@ -53,9 +53,10 @@ in a terminal and the admin password prompts of Plasma can take a face instead
of a password. A bubble at the top of the screen, above the lock screen too, of a password. A bubble at the top of the screen, above the lock screen too,
shows the face being looked for, recognised or refused. shows the face being looked for, recognised or refused.
Before a face counts it has to show a sign of life (a blink, or the nose moving A photo on a phone, a tablet or a glossy print is refused by its reflection and
the way a real nose does when the head turns), so a photo held up to the camera its straight edges. The strict photo check also wants a sign of life (a blink,
is not enough. It is a convenience, not a security upgrade: a webcam sees a or the nose moving the way a real nose does when the head turns), which stops a
printed photo too. It is a convenience, not a security upgrade: a webcam sees a
flat picture, and a video of the person can get through. flat picture, and a video of the person can get through.
Run "plasma-face-unlock disable" before removing this package, so that sudo Run "plasma-face-unlock disable" before removing this package, so that sudo
Binary file not shown.

Before

Width:  |  Height:  |  Size: 224 KiB

After

Width:  |  Height:  |  Size: 223 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 275 KiB

After

Width:  |  Height:  |  Size: 222 KiB

+3 -1
View File
@@ -30,7 +30,9 @@ struct Settings {
// A /dev/video path, "auto", or for testing "file:<video>" and // A /dev/video path, "auto", or for testing "file:<video>" and
// "images:<directory>". // "images:<directory>".
QString camera = QStringLiteral("auto"); QString camera = QStringLiteral("auto");
LivenessMode liveness = LivenessMode::Heavy; // Basic by default: screens and phones are caught without asking for a
// blink. Strict adds the blink or head turn that stops a printed photo.
LivenessMode liveness = LivenessMode::Light;
Strictness strictness = Strictness::Normal; Strictness strictness = Strictness::Normal;
// Only a face that looks at the screen with its eyes open counts. // Only a face that looks at the screen with its eyes open counts.
bool attention = true; bool attention = true;
+1 -1
View File
@@ -126,7 +126,7 @@ pfu_config_load() {
_pfu_kv_lookup "$PFU_CONFIG" Sudo no; CFG_SUDO=no; pfu_is_true "$PFU_KV_VALUE" && CFG_SUDO=yes _pfu_kv_lookup "$PFU_CONFIG" Sudo no; CFG_SUDO=no; pfu_is_true "$PFU_KV_VALUE" && CFG_SUDO=yes
_pfu_kv_lookup "$PFU_CONFIG" Polkit no; CFG_POLKIT=no; pfu_is_true "$PFU_KV_VALUE" && CFG_POLKIT=yes _pfu_kv_lookup "$PFU_CONFIG" Polkit no; CFG_POLKIT=no; pfu_is_true "$PFU_KV_VALUE" && CFG_POLKIT=yes
_pfu_kv_lookup "$PFU_SYSCONFIG" Liveness heavy; CFG_LIVENESS="$PFU_KV_VALUE" _pfu_kv_lookup "$PFU_SYSCONFIG" Liveness light; CFG_LIVENESS="$PFU_KV_VALUE"
_pfu_kv_lookup "$PFU_SYSCONFIG" Camera auto; CFG_CAMERA="$PFU_KV_VALUE" _pfu_kv_lookup "$PFU_SYSCONFIG" Camera auto; CFG_CAMERA="$PFU_KV_VALUE"
return 0 return 0
} }
+1 -1
View File
@@ -260,7 +260,7 @@ PFU_SETTINGS=(
"user|ScanOnLock|bool|no|Look right after the screen locks" "user|ScanOnLock|bool|no|Look right after the screen locks"
"pam|sudo|bool|no|Use for sudo in a terminal" "pam|sudo|bool|no|Use for sudo in a terminal"
"pam|polkit-1|bool|no|Use for admin prompts" "pam|polkit-1|bool|no|Use for admin prompts"
"sys|Liveness|choice|heavy|Photo check|heavy,light,off" "sys|Liveness|choice|light|Photo check|light,heavy,off"
"sys|Strictness|choice|normal|How closely a face has to match|normal,strict,relaxed" "sys|Strictness|choice|normal|How closely a face has to match|normal,strict,relaxed"
"sys|Attention|bool|yes|Only while looking at the screen" "sys|Attention|bool|yes|Only while looking at the screen"
"sys|Camera|camera|auto|Camera" "sys|Camera|camera|auto|Camera"