Feature Request: Facial Recognition for Login and Screen Unlock #461
siyamsec-lab
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Summary
Add optional, local facial-recognition authentication to AnduinOS for user login and screen unlocking.
Motivation
Modern operating systems increasingly provide biometric authentication as an alternative to entering a password. AnduinOS could provide a similar experience while keeping the implementation lightweight and privacy-focused.
This would be particularly useful for laptops and devices with an integrated or USB webcam.
Proposed Feature
Provide an optional facial-authentication mechanism that allows an enrolled user to authenticate using their face for:
The existing password/PIN authentication method should remain available as a fallback.
Technical Approach
The implementation should integrate with the Linux authentication infrastructure, preferably through PAM, rather than implementing authentication separately inside the desktop environment.
A possible architecture would be:
The implementation should be compatible with the existing AnduinOS login and lock-screen stack.
Privacy
Facial authentication should be designed with privacy as a primary requirement.
The default implementation should:
Raw facial images should not be retained unnecessarily.
Security
Facial recognition should be treated as an authentication mechanism rather than merely a convenience feature.
The implementation should consider:
For higher-security operations, the system could require the user's password or another authentication factor rather than relying exclusively on facial recognition.
User Experience
A user could enroll their face through a simple settings interface:
During login or unlock:
If recognition fails:
Optional Configuration
Users should be able to configure:
Compatibility
The feature should degrade gracefully on systems without a compatible webcam or hardware.
Users without a supported camera should continue to use the existing authentication methods without additional configuration.
Initial Scope
A reasonable first implementation would support:
More advanced liveness detection and hardware-backed biometric storage could be considered in later releases.
Expected Benefit
This would provide AnduinOS users with a convenient biometric login/unlock option while maintaining the project's lightweight and privacy-oriented approach.
All reactions