7 ms·
Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock
I wrote this after the case of a Washington Post reporter, Hannah Natanson, was compelled to unlock her computer with her fingerprint. This resulted in access to her Desktop Signal on her computer, revealing sources and their conversations.
https://www.yahoo.com/news/articles/washington-post-raid-proves-face-153402560.html https://www.yahoo.com/news/articles/washington-post-raid-pro...
Edit: I've a lot more details about the legality and precedence on the apps landing page https://paniclock.github.io/ https://paniclock.github.io/
- deadeye 5mo agoINAL, but if the authorities had captured your device with touchID enabled and legally ask you to use it to login and you do an action that would disable touchID, then that would be "obstruction".
- antiframe 5mo agoThat's the point of this. TouchID is no longer enabled. Someone unknown party approaches you, you close your lid (disabling TouchID). Then they "legally" ask you to put your finger on the sensor. You do. They didn't ask you before you close your lid. You're thinking more along the lines that they ask you to touch the sensor and you use your fingernail razor blades to damage the sensor or something like that.
- deadeye 5mo agoYes, I meant to respond to other comments in here directly, but got messed up. Others had floated the idea of locking by using an alternate finger with touchID, after the fact.
- mrdomino- 5mo agoNeat idea. I remember way back in the day, there was some question as to the legality of compelled unlocking of devices; IIRC, it’s been deemed legal to compel a fingerprint, but illegal (under the first amendment?) to compel entry of a password—IIRC, as long as that password hasn’t been written down anywhere. I gather this is written to that end primarily? Or is there some other goal as well?
- seanieb 5mo agoI wrote this after the case of a Washington Post reporter, Hannah Natanson, was compelled to unlock her computer with her fingerprint. This resulted in access to her Desktop Signal on her computer, revealing sources and their conversations. https://www.yahoo.com/news/articles/washington-post-raid-proves-face-153402560.html https://www.yahoo.com/news/articles/washington-post-raid-pro... Edit: I've a lot more details about the legality and precedence on the apps landing page https://paniclock.github.io/ https://paniclock.github.io/
- mrdomino- 5mo agoCool, thank you.
- dang 5mo ago(I've put a copy of this text at the top of the thread, since it's standard for Show HNs to have some intro/background up there. I hope that's ok with you!)
- seanieb 5mo agoThank you!
- mrheosuper 5mo agoCan you intentionally use the wrong finger so that it will force to enter password
- euroderf 5mo agoHypothesis: If you can assign different fingers to different accounts, you could use (for example) your middle finger to switch to a "panic account" whose automatic login procedure includes disabling Touch ID. Or, to avoid arousing suspicion, link the most common "login finger" (pointer finger?) to the account that locks down, and use your middle finger for your normal account day in and day out.
- 5mo ago
- ttul 5mo agoThe 2026 version of "Boss Key".
- Forgeties79 5mo agoPSA to iOS users: if you tap the lock button 5x it forces password-only unlocking. Useful at protests or any precarious situations with law enforcement.
- chuckadams 5mo agoBringing up the shutdown screen (hold lock and either volume button) will also do it.
- itsdesmond 5mo agoI did not know that. That is extremely convenient. Thank you.
- freehorse 5mo agoTapping it 5 (6? 7? 20?) times works better while panicked, though.
- sigio 5mo agoOn GrapheneOS (and maybe android generic?) this calls the emergency number, I just found out (with a 5 second timer to cancel this luckily)
- spockz 5mo agoIt is also an option in iOS under Settings -> Emergency SOS. And with it turned on it will both call emergency services and require pin for unlock.
- jonpalmisc 5mo agoThis still leaves your device in an AFU (after first unlock) state, with user data decrypted, and should not be treated as secure. The only thing you can do (to protect your data from forensics, etc) is to return it to BFU by shutting it off.
- 5mo ago
- p0w3n3d 5mo agoWhat's the rationale? It should be described in the README.md IMO
- itsdesmond 5mo agoA person might use it to stop someone getting into your computer through certain types of physical coercion, forcing your finger to the reader, or (much less likely but I’m sure security services know how) a copy of your fingerprint. But it isn’t a why, it is a what. That what is a tool that lets you quickly disable Touch ID for whatever reason you want to.
- seanieb 5mo agoThat's good feedback. I just added it to the readme: > "PanicLock fills a gap macOS leaves open: there is no built-in way to instantly disable Touch ID when it matters. Biometrics are convenient day-to-day, and sometimes preferable when you need speed or want to avoid your password being observed. But in sensitive situations, law enforcement and border agents in many countries can compel a biometric unlock in ways they cannot with a password. PanicLock gives you a one-click menu bar button, a customizable hotkey, or an automatic lock-on-lid-close option that immediately disables Touch ID and locks your screen, restoring password-only protection without killing your session or shutting down." I've more details on the apps landing page - paniclock.github.io
- quicklywilliam 5mo agoGreat idea and implementation! If you are hesitant to install this for any reason, you can accomplish the same thing with this one liner: sudo bioutil -ws -u 0; sleep 1; sudo bioutil -ws -u 1 Edit: here's a shortcut to run the above and then lock your screen. You can give it a global keyboard shortcut in the Shortcuts app. https://www.icloud.com/shortcuts/9362945d839140dbbf987e5bce9e1aad https://www.icloud.com/shortcuts/9362945d839140dbbf987e5bce9...
- alin23 5mo agoHook this to a lid angle below 30° trigger in https://lowtechguys.com/crank https://lowtechguys.com/crank and you can easily make it run on a simple lowering of the lid
- Wowfunhappy 5mo agoAt that point, why not just disable Touch ID?
- hervature 5mo agoWhen the bad guys are too impatient to wait until you leave the computer but not fast enough to stop you before 30 degrees while keeping the convenience of life.
- orthogonal_cube 5mo agoHonestly I’m surprised this wasn’t already a feature in macOS. Thank you for coding it and publishing as open-source!
- rglover 5mo agoThis is awesome, thank you. Was just thinking about this problem the other day. Glad someone whipped something up.
- freehorse 5mo agoThis is great. I see many times "security advice" against biometrics replacing password unlock, but most of the time I am more worried about getting recorded by somebody/something while typing a password in the open than anything else. This makes it better for those other cases.
- Terr_ 5mo agoAt that point what you need is true multi-factor. For example, both fingerprint and per-device PIN. Regrettably, that's not often offered as a feature, even when the infrastructure is already there.
- akdev1l 5mo agoNotably macOS cannot do this
- parl_match 5mo agoCareful with absolutist statements :) macOS can in fact be configured to use a third party idp, including interactive elements, on loginwindow. So, you could build your own through the ExtensibleSingleSignOn and Extensible Enterprise SSO macOS plugin API. You would do touchid, and then have it pop your own custom window/app, providing a prompt through that API, except it's just a hardcoded value (or some shit idk) https://youtu.be/ph37Yd1vV-c https://youtu.be/ph37Yd1vV-c So yes, macOS can in fact do that. Just not out of the box. I strongly believe that it is a glaring omission, or at least something they should gate through lockdown mode. idk!
- midtake 5mo agoIf you create a piv certificate on a yubikey and just plug it in while logged in, it automatically registers it as a login method.
- akdev1l 5mo agoYeah but then it will only use the certificate on the yubikey and not ask for a password so we’re back to 1FA
- gruturo 5mo agoThis would be perfect if it could monitor the force with which the lid is closed (macs have accelerometers after all, either this info or an acceptable proxy could be derived?). Gently close? no action. Stronger, faster action? Disable touch ID Slam shut in full panic? yeah disable all biometrics, lose all state, even wipe the ram and the filevault key if it's an option
- QuercusMax 5mo agoYou must not have cats or children if you think that last one is reasonable
- gruturo 5mo agoOk just unload the filevault key from ram, better? And if possible tell the secure enclave to revert to the before-first-unlock state
- thih9 5mo agoPerfect rage quitting machine. There should be an enterprise version: when lid is closed with full force it also sends a professional resignation letter to the current employer.
- wolvoleo 5mo agoI'm surprised Apple doesn't offer an option. On the iPhone you could do this by pressing the power button several times. Not sure if this still works because the iPhone 6 was my last one though.
- nailer 5mo agoIf someone can force you to use touch id they can probably also force you to enter your password. (If you’re about to comment about fingerprints on transparency film and balloons filled with warm water then yes good point)
- skillina 5mo agoCapable? Yes. Willing? I wouldn't be so sure. You don't even need to hurt someone to manhandle them enough to put their fingerprint on a scanner. Whereas forcing someone to give up a password could rise to the level of torture. Of course, I imagine the majority of people would yield their password if you simply threatened to detain them long enough to make them miss their flight.
- FerretFred 5mo agoI agree.. having to spend longer than necessary at UK's Manchester Airport would have me singing like a canary!
- urbandw311er 5mo agoI think it’s about plausible deniability: you can pretend you’ve forgotten your password, you can’t pretend you’ve forgotten your finger.
- surround 5mo ago> in sensitive situations, law enforcement and border agents in many countries can compel a biometric unlock in ways they cannot with a password. If the threat model includes state-level actors, then disabling biometrics won't prevent data from being retrieved from physical memory. It would probably be wiser to enable disk encryption and have a panic button that powers down/hibernates the computer so that no unencrypted data remains on RAM. The website says shutdown "takes time" and "kills your session" but a hibernation button would take effect just as fast and would preserve the session.
- jovial_cavalier 5mo agoa cop works for "the state," but he's definitely not a "state-level actor."
- surround 5mo agoHow do you define "state-level actor?" Police departments certainly have access to state and federal forensic resources to access unencrypted data in memory.
- stackghost 5mo agoIn the context of breaking into phones and laptops, "state-level actor" usually implies a team of people with NSA-type forensic capabilities. That is, they have deep expertise in infosec and related topics, access to 0days that the security apparatus has hoarded and kept secret for their own use, and they may have bespoke hardware to facilitate attacking the device. A random cop might have access to a Cellebrite machine but they can't just call up the NSA and ask them to break into some drug dealer's macbook.
- surround 5mo agoFair enough. Though they certainly could still break in if the laptop isn't encrypted, so this tool is only useful when combined with disk encryption.
- moralestapia 5mo agoThis should be an OS X feature, it's just that good. Great work, congrats!
- deadbabe 5mo agoThere should just be a way to setup an alternate dummy account based on the finger you use. This gives the illusion of compliance but your real data is safe.
- armadyl 5mo agoIf you're in a situation where this is a pressing issue, it's not a good solution as it's trivial to detect if it's a fake environment, especially if they get suspicious and run external forensics on it. iirc the GrapheneOS team won't implement this feature for that reason
- FerretFred 5mo agoThe middle finger could be the emergency use one ...
- momentmaker 5mo agoThe iOS equivalent is to hold the side + volume button until the power slider shows up. Cancel out of it and the next unlock will require your passcode. Pressing the side button 5x triggers Emergency SOS which does the same thing. Been there forever but barely anyone knows about it. Nice to see something like this on the Mac side.
- rsync 5mo ago[flagged]
- armadyl 5mo agoHow beneficial is this versus just being theater? The example used in this is the government accessing the reporters laptop via biometrics. But in this case, and especially under this admin legal or not this app won't stop them, unless I'm misunderstanding the macOS security model. Even with FDE enabled, sending it to the lock screen with biometrics disabled will not do anything to stop them from being able to access the contents of the hard drive via forensic methods with relative ease. I think that at best this will only stop the casual person (i.e. a family member or roommate/random snooper)? In which case there would be no point to switch away from biometrics. You're far better off just keeping more private information on the iPhone and isolating that data from a Mac, since that has far more resistance to intrusion in AFU mode than a Mac.
- gh02t 5mo agoMy interpretation was that it's easier to physically force someone to mash their finger on the sensor than to get them to divulge a password, not that it offers you any kind of legal protection. But yeah, it's a plausible but somewhat contrived situation to find yourself in.
- nofriend 5mo agoIt does offer you legal protection. In the US, the right to not self incriminate protect you from divulging passwords but does not protect you from giving up biometrics. In other countries the rule is different.
- FerretFred 5mo agoI'm reading this nervously on my MacBook Air, but chuckling quietly with my cheapest Mac Neo (my new travel companion).
- october8140 5mo agoIf this were a concern for me the better choice is shutting down the laptop to encrypt the drive and disable biometrics. This does nothing since the drive is still unencrypted.
- dddddaviddddd 5mo ago> This does nothing since the drive is still unencrypted. Even though the data is unencrypted in memory, an attacker would still need either a local privilege escalation (from the login window?), or some sort of side-channel attack if they're still not able to get the password.
- lxgr 5mo agoWhat do you mean by “the drive is still unencrypted”? If your threat scenario includes somebody performing a DRAM freezing attack or similar, these are orders of magnitude harder to pull off successfully than to compel or bypass a biometric sensor, especially when the device is covered in the owners fingerprints.
- VectorLock 5mo agoCan you get TouchID to register multiple fingers and script the actions; maybe your middle finger unlocks touchID, but your index finger disables touchID until you enter your password.
- aequitas 5mo agoYou can have different fingers registered to different accounts. I used it to 'fast user switch' between accounts.
- HNisCIS 5mo agoWhy not just disable touchID if the Bluetooth modem hears advertising packets from the 00:25:DF OUI?
- Kwpolska 5mo ago> No command injection — Timeout parameter is a Swift Int, not a string Please don't use slop machines to write READMEs. If you're launching bioutil as a subprocess, you're passing the timeout as a string. In your code, you read the timeout, convert to int, set timeout to 1, and set it back to the previously retrieved value. There is no difference between keeping it as strings or doing a string->int->string round-trip, assuming no sizing and formatting weirdness.
- seanieb 5mo agoThis comment is based on one of my commits. The round-trip through Int is exactly what makes it safe.Int(value) will return nil (and be rejected) for anything that isn't a valid integer. no ; rm -rf /, no shell. String(seconds) on a Swift Int can only ever produce a decimal number. (which is probably overkill and not needed in this context.) > Please don't use slop machines to write READMEs. Trust me, they do a better job than I ever will. Having said all that, it's probably something that could be dropped from the readme. I'll edit now. edit: updated the readme. Thanks for taking the time to proof read it.
- dilberx 5mo agovery nice thought
- wodenokoto 5mo agoMaybe clicking the Touch ID button could invalidate the login attempt and ask for password? I like logging in with my finger print, but I would like an “out” in the same vein as this.
- tpetry 5mo agoI would love to have a mode that I must use my long password to unlock my mac for security purposes. But when unlocked, use touchid as an alternative to my password for convenience. So just the normal TouchID mode but not for unlocking the mac.
- traceroute66 5mo ago> So just the normal TouchID mode but not for unlocking the mac. Erm ? Just go to System Preferences and turn off "Use Touch ID to unlock your Mac" ??
- tpetry 5mo agoWhen you disable that, its also disabled for sudo operations when unlocked. it basically disables TouchID completely.
- traceroute66 5mo ago> When you disable that, its also disabled for sudo operations when unlocked. And in the context of this discussion is that a bad thing ? i.e. do you want to leave open the possibility of being compelled to sudo via your finger ?
- onchainintel 5mo agoThis is dope OP, well done. Terrific solution on something that Apple clearly missed.
- grishka 5mo agoThis makes me wonder how I can do the reverse — I'd like to always use touch ID and never ever be asked for password except when it's technically necessary, e.g. after a reboot. In effect, I'd like to completely remove this time component from biometric authentication.
- Wingman4l7 5mo agoAn opportune time to mention the real-world example of when the authorities really wanted to gain full access to a computer but did not want to resort to legal compulsion or "rubber-hose cryptanalysis" -- they simply waited until the target was logged in, staged an altercation in the immediate vicinity, and then snatched the open laptop away from them. You can read about the sting, here: "How Did Investigators Catch the Dread Pirate Roberts (DPR) in San Francisco?" https://www.forensicscolleges.com/blog/forensics-casefile/silk-road https://www.forensicscolleges.com/blog/forensics-casefile/si...
- squibonpig 5mo ago>That’s not just one leak investigation—it’s access to a reporter’s complete source network, enabled by biometric convenience features. Really nice to see that everything is AI generated now!
- scoofy 5mo agoI think the thing that really surprises me is that Washington Post reporters are using Apple products and not just a Linux distribution. They are professionals. At some point, Apple can be compelled to work against you, but Linux is just a product off the shelf.
- saadn92 5mo agoWhat's the timing like between the lid sensor firing and sleep actually kicking in on Apple Silicon? I ship a couple menu bar apps on M2 and listening for NSWorkspaceWillSleepNotification feels like you get maybe 200ms before the system is gone. If disabling TouchID requires a round trip to the secure enclave in that window that seems like it'd be a race.
- newsdeskx 5mo ago[flagged]
- bradknowles 5mo agoIt’s easy enough to just configure TouchID so that it doesn’t work to log into your computer. It’s only used for authorization to do certain operations (like ApplePay), once you have logged on with a password. I do this on all my devices. And I don’t use FaceID for anything at all. Which makes modern iPhones a bit of a pain, but I do it anyway.