The Biometric Authentication Daemon
In modern Ubuntu desktop environments (particularly those utilizing GNOME), biometric authentication is becoming increasingly common. The fprintd.service is the background daemon responsible for interfacing with hardware fingerprint readers. It manages the enrollment of your fingerprints, securely stores the biometric templates, and communicates with the PAM (Pluggable Authentication Modules) system to allow you to unlock your screen, run sudo commands, or authenticate application installations using your fingerprint instead of a password.
If you are using a premium laptop with a built-in fingerprint scanner, this service provides a seamless and secure login experience. However, if you are using a standard desktop PC without any biometric hardware, or if you are configuring a headless server where physical access is strictly limited and authentication happens entirely over SSH keys, the fprintd service is completely useless. While it generally sits idle if no hardware is detected, having an active authentication daemon running on a server that will never use it is bad practice. Disabling it reduces the system’s attack surface and cleans up the process tree.
How to Disable the Fprintd Service
You can permanently prevent the fingerprint authentication daemon from initializing using standard systemctl commands.
- Open your Ubuntu Terminal (or SSH into your server).
- To disable the service so it does not load during the boot sequence, run:
sudo systemctl disable fprintd.service
- To ensure that the GNOME control center, PAM configurations, or other system utilities cannot accidentally trigger the service to start up in the background, you must mask it:
sudo systemctl mask fprintd.service
The system will now completely ignore fingerprint authentication requests. (Note: Only do this if you do not possess, or intend to use, a fingerprint reader on this specific machine).