- A few webcam frames on every unlock
- Dashed: nobody it knows
- Six-digit code, or two face rescans
- Locks at least 90 s apart
- A few webcam frames on every unlock
- Dashed: nobody it knows
- Six-digit code, or two face rescans
- Locks at least 90 s apart
Work / Desktop tool
Who sat down at your PC while you were away? A Windows app that checks the face at the screen every time the session unlocks.
- Year
- 2026
- Status
- Built, not yet released
- Code
- Private repository
Whodis

Concept
When Windows unlocks, Whodis takes a few webcam frames and compares them with the faces you enrolled. If it’s nobody it knows, it tells you. Arm the lock and a fullscreen countdown asks for a face rescan or a six-digit authenticator code, and if neither works, Windows locks for real.
The problem
A photo held up to a webcam beats any face check. The hard part isn’t matching faces. It’s building something useful that never pretends to be more secure than it is.
It is a tripwire, not an authenticator.


How it works
Ambiguity favours you
A stranger verdict needs several frames that all hold a face, none of them close to anyone enrolled. A covered camera, an empty room or a too-close-to-call reading all resolve as "not a stranger".
Source: README, What it is, and is not
Tampering counts
Unplug the camera or revoke its access while the lock is armed and the same countdown starts, because pulling the cable would otherwise be the way past.
Source: README
The lock is confirmed, never assumed
After Whodis asks Windows to lock, it checks that the session really locked. Repeated locks are spaced out so a bad reading can’t trap you in a loop.
Source: main/platform/session-lock.ts, docs/HISTORY.md
Hard to kill, nothing to leak
Installed for all users, a SYSTEM watchdog service relaunches Whodis within seconds, and the installer refuses to put that service in a folder other users can change. Stored fields are AES-256-GCM, with the key wrapped by Windows DPAPI. No account, no server.
Source: README, service/, main/core/crypto.ts


Built with
- Electron
- TypeScript
- face-api
- better-sqlite3
- koffi (Win32)
- DPAPI + AES-256-GCM
- PowerShell service
Numbers
- 2
- face rescans before the lock winsREADME, The lock screen
- 6
- digits in the authenticator code, the real secretREADME
- 90 s
- minimum between locks, so a bad camera can’t loop youREADME
- 0
- servers. Nothing leaves the machineREADME