Howdy – Windows Hello style facial authentication for Linux
github.com
github.com
- Implements a popular feature other OS's have
- A cute knock off name, making it self-explanatory (this is actually fairly important for adoption!)
- Integrates well with cli junky workflows
> Using the central authentication system (PAM), this works everywhere you would otherwise need your password: Login, lock screen, sudo, su, etc.
- A nearly perfect readme in the repo. 2 sentence summary of the project, concise instructions for building/installation, where the error log lives, etc. without being too long.
There are a lot of repos I've seen with horrible readmes that don't even have a sentence of what the purpose of it is.
Which is reasonable if the repo is just for development, but most of the time a link to the repo is the main download link/project landing page. The added friction leads to less adoption and usage of something otherwise useful.
If you're making a project simmilair to this, I recommend taking notes :^)
I can kind of get why "Windows Hello" camera-based face id isn't exactly great but do you also think the same of Apple's "actually modeling your face" style? Because I was really apprehensive about it compared to a fingerprint reader but I've pretty much flipped 180.
I use finger print scanners at home because it's less keystrokes.
But not on my phone. Both because my (trusted) friends sometimes need to borrow a phone, and also for the very rare chance police detain me and try to break into my phone without a warrant.
Legally, you don't have to tell a cop your password, but they can physically force you to use your finger/face to unlock your phone.
That said, the traditional fingerprint readers are more secure and just as easy to use. I don't understand why Apple shifted focus for mobile security onto facial recognition, especially with the development of under-screen fingerprint scanners in smartphones.
Even medical latex-type gloves make keyboard typing near impossible for me (granted that might be because I'm right between sm and md size gloves so I have to wear slightly baggy mediums...)
> "(Quoting Stratechery) TouchID made it far easier to have effective security for the vast majority of situations, and FaceID makes it invisible. [...] the first time I saw notifications be hidden and then revealed (as in the GIF above) through simply a glance produced the sort of surprise-and-delight that has traditionally characterized Apple’s best products" - https://daringfireball.net/linked/2017/11/08/apple-at-its-be...
> "(Quoting Tom's Guide) I’ve been using Face ID on the iPhone X for more than 24 hours, and I don’t need a stopwatch to tell you that it unlocks my phone slower than when I was using Touch ID on my older iPhone 7 Plus". This is not a “workaround”. This is how you’re supposed to unlock iPhone X. Starting with a tap of the side button is not how you’re supposed to do it — you’re creating a two-step process where you only need one. [...] The best way to use Face ID is to pretend it isn’t even there, and just swipe up from the home indicator." - https://daringfireball.net/linked/2017/11/01/face-id-extra-s...
> "(Quoting Michael Tsai) However, Face ID also has advantages. It works with gloves on, with wet fingers, and with dry/cracked skin. It’s more convenient when the phone is in a dock or car mount where it would be hard to get my hand under it to put my thumb on the sensor." - https://daringfireball.net/linked/2019/03/01/tsai-iphone-se-...
With under-screen fingerprint scanners, or the power button fingerprint scanners on some phones, that "two step process" turns back into a single step. My unlock process is to put my finger on my screen (where the fingerprint scanner is) and pull it out of my pocket. It's honestly no different from the swipe up that you need to do on iOS. Because the scanner is on the front, it also works pretty flawlessly when it's attached to a mount of some sort.
Wet hands are one place where improvements can be made, but modern fingeprint scanners are doing quite well in that space as well.
I've used Google's facial recognition system for ages before I had a phone with a fingeprint scanner and it was always pretty snappy for me, but I didn't set it up with this phone and I haven't missed it so far.
I have little basis for this assumption, but I imagine apple would compromise a bit of security to keep the feature people payed for working and just chop off half the face.
Now what you really want to be doing is printing QR code masks to make up for the missing half of the face! /s
This is absolutely wrong. I've bypassed it with only a picture (off of a phone, no less). It is bad technology (for securing sensitive information). In terms of convenience of course, it is unmatched.
Apple's face modeling is miles better than a webcam for sure, and I'll admit I've never used a system like that before.
On iOS at least, it gains affirmative consent by you double clicking a button on the side. It also refuses to recognise your face if your eyes are closed.
And if someone has full physical control over you such that they can open your eyes without consent, do you really care if they can unlock your phone? Your life is in their hands at that point anyway.
You have to assume a persistent attacker with physical access will be able to crack the device regardless.
It only works if you're close, alive, your eyes are both open, and looking right at it. I doubt that degree of specific physical attack is in most people's threat model. It's only backing a 4/6 digit pin for most people anyway. Realistically, it's not the weakest link.
Computer: "Transaction confirmed" (secretly runs dd if=/dev/random of=/dev/sda)
FaceID only works if your eyes are open for this reason.
I remember being impressed by the quality and honesty of the project and began my search for similar projects for fingerprint authentication.
I sadly couldn't find anything that works. I use LM 20.3 on an ASUS Vivobook and apparently PAM doesn't support my in-built fingerprint scanner.
Congrats to the author(s) for shipping a library, and having done so for some time now it seems (which is more than I've ever done).
Can I ask if there's much of a point, though? Like why bother with the trouble of setting this up if I can just print a photo and have it unlock? At that point you're better off with a very weak and easy-to-remember password, no?
As models evolve, they could be integrated without changing the other components.
Also, I'd be curious to see how it compares to, say, Windows Hello. The nice thing about it being open source is you can change the confidence threshold for matching a face, and see the impact.
> Use your built-in IR emitters and camera in combination with facial recognition to prove who you are.
I wonder if the "could be enough to do it" is kind of pessimistic. That is, it is open source software -- you can install it on whatever computer you want, including one without an advanced IR camera. Or, the user could have some obscure IR camera, which might not be detected properly/might not have Linux drivers. It seems hard to make guarantees for arbitrary hardware.
My professional laptop could be different if I was working on something of any importance. That is not the case, but there the risk reward is different, and I would probably keep it to password + sec key or something in these lines
For instance, only face-unlock my screen if it locked for inactivity, and less than 15 minutes ago. If I manually locked it, require password. If I've been gone too long, require password. For sudo and bootup, always require password.
That would make the level of (in)security acceptable to me. In its present state, I don't think it's appropriate.
And for anything PAM doesn't handle, since Howdy is just a Python lib/app, it's almost trivial to modify it to do anything else. You could just add your modifications into https://github.com/boltgolt/howdy/blob/beta/howdy/src/compar... (eg, make it autofail if a env/memory flag hasn't been set after first login, same with storing an inactivity flag, etc. Looks like the author is responsive taking pull requests, so you could even do it properly and get it upstreamed even: https://github.com/boltgolt/howdy/pulls?q=is%3Apr+is%3Aclose...
As for appropriateness, it's fine if it's not your cup of tea, but with 3.6K stars and 220 forks, obviously it works great/is useful for a lot of people so I'm glad that the author released and maintains it, even if it's not for everyone.
Okay, thank you, I had not found that page in a brief glance. Which admittedly was probably not enough of a glance to give it a fair shot.
That's pretty awesome, I will have to poke at it. I also have fingerprint login so I'm sure I can get up to some silly hijinks...
I've wanted that for some time with sssd (e.g., unlock with a single factor if my TGT is still valid) but never got around to filing the right RFEs.
FWIW, Windows Hello does try to defend against this attack by requiring special cameras that operate in the infrared band.
The question is - who are you trying to protect against?
Like, personally I'm worried about someone stealing my laptop. In that case, it's extremely unlikely the thief would have a photo of me to use to unlock the laptop. Yes my wife or my friends would have access to pictures of me in high enough resolution to print and use to unlock it - but I'm really not worried about them breaking in.
Unless you're being targeted by someone, of course. In that case you have way more problems to worry about than your laptop being unlocked...
To emphasize: Howdy is about convenience for people that are okay with a less secure installation. It can also be used as a second factor.
3.0.0 has been in the works for 2 years now and will introduce a GTK UI, native PAM module and many other changes. Let me know if you have any questions!
That would allow people using systemd-homed's encryption to unlock their home directories, which they otherwise cannot have done [as it requires the passphrase].
Both Windows Hello, and the Mac equivalent, can't be fooled by photos -- they require an IR camera, or camera which can measure depth.
Claiming this is "Windows Hello style", if it can be fooled by a photo, is a bit misleading in my opinion.
My 6 year old daughter was able to log into my admin account. They weren't even trying to do that, just opened the laptop and it's all like "Hello, Brian!" and logged into my account.
This is false, I've bypassed it on a very modern laptop using a phone picture.
in a US court of law, things like blood and biometrics are NOT protected by the fifth amendment. law enforcement can (and have) compelled submission of fingerprints and faces to unlock devices. this includes immigration and customs officers demanding credentials from foreign nationals.
complex passphrases however are protected under the fifth amendment, and are much more secure overall.
If the cops concerns you, I recommend practicing the lock sequence, and if they don't, perhaps we're not citizens of the same country.
Otherwise anyone can just boot the machine off a USB stick and take what they like.
1. if the device is turned off, I have to enter my passcode/password to enable biometrics authentication.
2. If after long enough of being on the biometrics are not used, it will require the passcode/password.
3. There is a quick shortcut to disable biometric authentication.
To my knowledge iOS is the only one that does all 3. Mac does the first 2 for TouchID and annoyingly there is not a shortcut for the third available.
Windows Hello seems like a half assed security measure since it is missing all 3. At quick glance this does the same.
However, I think the emergency disable functionality in Windows Hello isn't really necessary. You can quickly disable biometrics on your phone from your pocket, but disabling it on a desktop or laptop is a lot harder to do inconspicuously.
Because this is using PAM, you can configure it however you want. You can tell your system to allow user logins through biometrics but require a password for administrative tasks (doas/sudo) for example. You can also edit the source code and make it always fail if a certain file in a write-only directory is present and set up a keyboard shortcut that runs `touch /special/file/here`. You can even implement such a timer system by setting up a systemd timer that automatically creates such a file after a certain amount of time to make sure you need to reauthenticate.
Setting up a reliable face recognition system that hooks into the right APIs is the hard part. That's what this project does. Customising it to serve your exact use case is relatively easy.
"Windows Hello uses the two IR emitters to generate a 3D image of your face, and is much more secure. To do this Hello lights up your face with the left emitter on even frames, and uses the right emitter on odd frames. This lights up your face in slightly different angles, which is not possible to be faked by simply printing a 2D photo.
Unfortunately Howdy does not have control over these IR emitters and can't use this process"
Wasn't sure if "does not" means can't, so I did a search and discovered this interesting development: https://github.com/boltgolt/howdy/pull/611
I suppose it could be weak to a "mask" attack, but you could add something like drishti to make sure you can real eyes in addition to a face.
Note, even 3D sensors like Apple's FaceID can be broken with sufficient effort: https://www.wired.com/story/hackers-say-broke-face-id-securi...
Multi-spectral processing might help in that case, but honestly, if this sort of attack is a real security threat, then you probably shouldn't be running biometric logins in the first place (and you should probably actually be using MFA).
I probably should remove it, but it is already saving me so much time..