• A few webcam frames on every unlock
  • Dashed: nobody it knows
  • Six-digit code, or two face rescans
  • Locks at least 90 s apart
Whodis as a greybox: 13 blocks generated from the project’s own data.
  • A few webcam frames on every unlock
  • Dashed: nobody it knows
  • Six-digit code, or two face rescans
  • Locks at least 90 s apart

Work / Desktop tool

Who sat down at your PC while you were away? A Windows app that checks the face at the screen every time the session unlocks.

Year
2026
Status
Built, not yet released
Code
Private repository

Whodis

Whodis lock screen: Access Denied with a 29-second countdown, a six-digit authenticator field and a Scan again button.
The lock: 29 seconds to scan your face again or type the authenticator code, then Windows locks for real.

Concept

When Windows unlocks, Whodis takes a few webcam frames and compares them with the faces you enrolled. If it’s nobody it knows, it tells you. Arm the lock and a fullscreen countdown asks for a face rescan or a six-digit authenticator code, and if neither works, Windows locks for real.

The problem

A photo held up to a webcam beats any face check. The hard part isn’t matching faces. It’s building something useful that never pretends to be more secure than it is.

It is a tripwire, not an authenticator.

From the whodis README

How it works

  1. Ambiguity favours you

    A stranger verdict needs several frames that all hold a face, none of them close to anyone enrolled. A covered camera, an empty room or a too-close-to-call reading all resolve as "not a stranger".

    Source: README, What it is, and is not

  2. Tampering counts

    Unplug the camera or revoke its access while the lock is armed and the same countdown starts, because pulling the cable would otherwise be the way past.

    Source: README

  3. The lock is confirmed, never assumed

    After Whodis asks Windows to lock, it checks that the session really locked. Repeated locks are spaced out so a bad reading can’t trap you in a loop.

    Source: main/platform/session-lock.ts, docs/HISTORY.md

  4. Hard to kill, nothing to leak

    Installed for all users, a SYSTEM watchdog service relaunches Whodis within seconds, and the installer refuses to put that service in a folder other users can change. Stored fields are AES-256-GCM, with the key wrapped by Windows DPAPI. No account, no server.

    Source: README, service/, main/core/crypto.ts

Built with

  • Electron
  • TypeScript
  • face-api
  • better-sqlite3
  • koffi (Win32)
  • DPAPI + AES-256-GCM
  • PowerShell service

Numbers

2
face rescans before the lock winsREADME, The lock screen
6
digits in the authenticator code, the real secretREADME
90 s
minimum between locks, so a bad camera can’t loop youREADME
0
servers. Nothing leaves the machineREADME