face-unlock

face-unlock

Face ID for Linux.

Unlock the lock screen, sudo and admin prompts with your face.
On KDE Plasma, GNOME, Hyprland and Niri.

Install | How to use | Is it safe? | Report a bug

Buy me a coffee on Ko-fi

The bubble drops down over the lock screen, the face in it looks around, and two green rings spin and land around a tick

The bubble above the Plasma lock screen: looking, recognised, not recognised

## Install
Arch, CachyOS, EndeavourOS, Manjaro ```bash yay -S face-unlock ```
Fedora ```bash sudo curl -fsSL -o /etc/yum.repos.d/face-unlock.repo \ https://loonixtools.github.io/face-unlock/face-unlock.repo sudo dnf install face-unlock ```
Debian, Ubuntu ```bash codename="$(sed -n 's/^VERSION_CODENAME=//p' /etc/os-release)" sudo install -d -m 0755 /etc/apt/keyrings curl -fsSL https://loonixtools.github.io/face-unlock/KEY.gpg \ | sudo gpg --dearmor -o /etc/apt/keyrings/face-unlock.gpg echo "deb [signed-by=/etc/apt/keyrings/face-unlock.gpg] https://loonixtools.github.io/face-unlock/deb/$codename ./" \ | sudo tee /etc/apt/sources.list.d/face-unlock.list sudo apt update && sudo apt install face-unlock ```
- **KDE Plasma:** works out of the box. - **GNOME:** log out and back in once after installing. - **Hyprland and Niri:** the bubble only shows on face-unlock's own lock screen. hyprlock shows a line of text at the top instead. You also need a polkit agent. If none runs, the menu offers to install one.
Hyprland and Niri: which lock screen?

The window that asks which lock screen to use: face-unlock's with the bubble on the left, the user's own hyprlock with a line of text at the top on the right

When you turn face unlock on, a window asks which lock screen you want. You can change it later under **Settings**. - **face-unlock's own:** the bubble, the time and your wallpaper. You lock with `face-unlock lock`, and the menu shows where to put that. - **Yours** (hyprlock, swaylock, gtklock or waylock): press Enter on the empty password field to scan. hyprlock and swaylock also scan when you come back. Hyprland without uwsm needs a line in its config. The menu shows it.
## How to use ```bash face-unlock ```

The face-unlock menu in Konsole: face unlock on, one face, lock screen, sudo and admin prompts on

Press **1** and look at the camera. Then lock the screen and look at it.
Settings

The settings in Konsole, grouped into lock screen, password prompts, recognition and bubble, with the photo check explained at the bottom

## Is it safe? A convenience, not extra security. A webcam only sees a flat picture. | | | |---|---| | Photo or video on a phone, tablet or glossy screen | ✅ Stopped | | Matte printed photo | ⚠️ Only stopped with photo check *strict* | | Video of you on a big matte screen | ❌ Can get in | | Five failed tries | ⏸️ Paused for 15 minutes | | Your face data | 🔒 Numbers, no pictures. Root only. | | sudo over SSH | 🚫 Never unlocked by a face | ## More
How it works | | | |---|---| | `face-unlockd` | The root service. Owns the camera and the face data. | | `face-unlock-agent` | Runs in your session. Watches the lock screen, draws the bubble. | | `pam_face_unlock.so` | Lets sudo and admin prompts ask the service. | | `face-unlock` | The menu. | Two small networks from the OpenCV model zoo run on the CPU: YuNet finds the face, SFace turns it into numbers. All details: `man face-unlock`.
Build from source ```bash make models make make test sudo make install ``` Needs CMake, a C++20 compiler, Qt 6, LayerShellQt, KI18n, OpenCV 4.5.4+ (with DNN), Linux-PAM and libsystemd.
## Credits - [Glance](https://github.com/jonnyoo/glance) by Jonathan Zhou: the idea and the look of the bubble. - [YuNet](https://github.com/opencv/opencv_zoo/tree/main/models/face_detection_yunet) and [SFace](https://github.com/opencv/opencv_zoo/tree/main/models/face_recognition_sface) from the OpenCV model zoo. GPL-3.0-or-later.