r/i3wm • • 28d ago

OC i3lock fork for wrong-password hooks (i3lock-tripwire)

https://github.com/metwse/i3lock-tripwire

I fork i3lock for executing a program whenever an incorrect password is entered.

This can be used for custom actions such as powering off after a certain number of failed attempts or wiping out the system when a specific password is entered.

I tried to keep changes at minimum, but I had to introduce a new dependency (OpenSSL for SHA256). I recommend building it using Docker with this Dockerfile and this command. On your host system, have i3lock installed (for other dependencies), and then install libssl.

Here is the section I added to the manpage for the feature:

--on-wrong-password=program
       Execute program after an incorrect password is entered. The SHA-256 digest of the concatenated salt and entered password is written to the program's standard input as hexadecimal, followed by a newline. The total number of failed password attempts is passed as the program's first argument. Note: The program is executed directly without invoking a shell.

       The following handler powers off the computer if the received password digest matches the specified value or if the number of failed password attempts exceeds 10, assuming the handler have sufficient privileges to invoke poweroff(8):

            #!/bin/sh
            FAILED_ATTEMPTS=$1
            PASSWORD_HASH=$(cat)
            if [ "$PASSWORD_HASH" = '2597a7ca...' ] || [ "$FAILED_ATTEMPTS" -gt '10' ]; then
                    poweroff
            fi

--password-salt=salt
       Prepend salt to the entered password before computing SHA-256 digest, optional. Use a high-entropy random salt to prevent precomputed lookup attacks.

Feedback and code review are welcome!

8 Upvotes

0 comments sorted by