Facial authentication with Howdy
Security
As with all biometric applications, it is possible to fool Howdy. Figure 1 shows that a well-made image can pass as a face even if the size does not really fit. In the example, however, several attempts were required, and we had to permanently move the book cover used as a fake slightly in order to successfully record a profile. OpenCV's network is particularly sensitive to nodding.
On the Howdy homepage, developer Lem Severein points out the danger of manipulation and emphasizes the need to use a good IR video camera. But even a good IR camera could be fooled with some additional effort, just as fingerprint sensors can be fooled. The German Chaos Computer Club (CCC) has demonstrated problems with biometric authentication several times.
Severein came up with a useful extension to improve security known as rubber stamps [5]. Whenever Howdy recognizes a face – and only then – you can call predefined additional routines. These routines can then add additional tests, such as whether the user has pressed a certain key. If the additional condition is met, the software evaluates the authentication as correct. The mechanism is still missing in the current stable Howdy v2.6.1, but it is already available in the Git repository.
A separate tutorial shows how to implement appropriate rules (stamp rules). Howdy uses the possibilities of the OpenCV library. You can, for example, use a nod or a shake of the head as confirmation or negation. You are even allowed to define a minimum number of nods to confirm the authentication.
Severein has been working on Howdy 3.0 for more than a year, but a release date has not been set yet. In addition to the rubber stamps, version 3.0 will probably include a graphical user interface (GUI). A preview is available in the form of the developer version (Figure 3). To start the interface, you need the Python elevate
module from the python-elevate package. Then change to the src/
directory and call ./.init.py
.
Conclusion
Howdy shows where the world is headed: Self-learning systems and biometric data for authentication will probably play an important role in the future. So far, however, the special hardware requirements mean that Howdy is more of a proof of concept than an actual authentication solution suitable for industrial use. Having said this, you can use rubber stamps to increase security in practice.
Infos
- Howdy: https://github.com/boltgolt/howdy
- OpenCV: https://opencv.org
- Switching on IR lamps: https://github.com/EmixamPP/linux-enable-ir-emitter/wiki/Semi-automatic-configuration
- Howdy in the AUR: https://wiki.archlinux.org/title/Howdy
- Rubber stamps: https://github.com/boltgolt/howdy/wiki/Rubber-Stamp-Guide
« Previous 1 2 3
Buy this article as PDF
(incl. VAT)
Buy Linux Magazine
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters
Support Our Work
Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.
News
-
Armbian 24.11 Released with Expanded Hardware Support
If you've been waiting for Armbian to support OrangePi 5 Max and Radxa ROCK 5B+, the wait is over.
-
SUSE Renames Several Products for Better Name Recognition
SUSE has been a very powerful player in the European market, but it knows it must branch out to gain serious traction. Will a name change do the trick?
-
ESET Discovers New Linux Malware
WolfsBane is an all-in-one malware that has hit the Linux operating system and includes a dropper, a launcher, and a backdoor.
-
New Linux Kernel Patch Allows Forcing a CPU Mitigation
Even when CPU mitigations can consume precious CPU cycles, it might not be a bad idea to allow users to enable them, even if your machine isn't vulnerable.
-
Red Hat Enterprise Linux 9.5 Released
Notify your friends, loved ones, and colleagues that the latest version of RHEL is available with plenty of enhancements.
-
Linux Sees Massive Performance Increase from a Single Line of Code
With one line of code, Intel was able to increase the performance of the Linux kernel by 4,000 percent.
-
Fedora KDE Approved as an Official Spin
If you prefer the Plasma desktop environment and the Fedora distribution, you're in luck because there's now an official spin that is listed on the same level as the Fedora Workstation edition.
-
New Steam Client Ups the Ante for Linux
The latest release from Steam has some pretty cool tricks up its sleeve.
-
Gnome OS Transitioning Toward a General-Purpose Distro
If you're looking for the perfectly vanilla take on the Gnome desktop, Gnome OS might be for you.
-
Fedora 41 Released with New Features
If you're a Fedora fan or just looking for a Linux distribution to help you migrate from Windows, Fedora 41 might be just the ticket.