Docs · Secure and Secure held
docs/SECURE-HOLD-20260906.md in the ZoeyOS source. Last verified 2026-09-06. State current.Secure, and Secure held
One lamp, three states. Business as usual, Secure, and Secure held with the account password.
The law, densest form
Business as usual is the face finder for authority, and the door otherwise. Authority must be granted by the camera. Secure is a hold command on the ordinary expiry of that authority. It pauses two things: the time-based expiry of authority (the few seconds of grace when the owner leaves the frame, and the longer desk persistence), and the face finder's hunting of the owner to keep authority alive. The camera stays on the door. An entry face, or a click off, ends the pause, and business as usual returns.
The flag can inherit authority. It cannot mint it. Only a live look by the face finder mints a grant: the Secure click, a look at the desk or the door, the re-authorisation ladder, the unlock look. A door still, a soft ID, a seat guess or a voice mint nothing; they may only refresh a hold the face finder minted.
The three states
| Business as usual | The face finder keeps re-checking who is at the desk. The owner is User; anyone else is Guest. Authority expires on its own clocks when the owner leaves. |
|---|---|
| Secure | One click on the lamp. Holds the authority she already has, watches the door. A new face at the door drops confidential and casual comms and returns the house to business as usual. A visitor can click it off, never on. |
| Secure held | A double click asks for the account password. While held, door faces and the tripwire cannot drop Secure. One click releases the hold and Secure together, back to business as usual. |
What the hold does, exactly
| single click | Secure on or off, with a face-finder look on the way on |
|---|---|
| double click | asks for the account password; if it verifies, Secure is held |
| single click while held | hold off and Secure off, back to business as usual |
The lamp reads "Secure · held" while held. A presence restart clears the hold, the same law as the flag itself: boot is always insecure, because nobody knows who came in while it was down.
Where it lives
- The presence service owns the flag and the hold. Off is refused for every reason but a click while held. The hold has one minter (the password) and one release.
- The password is checked by the operating system's own login stack (PAM). It is used once, dropped, never logged, and attempts are two seconds apart.
- The Wall server passes the request through and does not log the payload.
- The Control Panel row is the button: click toggles, double click opens an inline password field that clears itself after submit. The desktop wall opens a password dialog on the double click.
On a Mac
A Mac always runs the face check and is never offered Secure mode. A Linux install may be. Voice is only a backup for the face check: it may confirm the owner when the camera saw nobody; it never overrules a face that does not match.
Tests
The hold needs the password and mints the flag; it survives door faces and the tripwire; one click releases and business as usual returns; release keeps Secure; attempts are rate-limited; wrong and empty passwords are refused by the login stack itself.