Facial recognition technology is everywhere, and it may not be legal(washingtonpost.com)
washingtonpost.com
Facial recognition technology is everywhere, and it may not be legal
http://www.washingtonpost.com/blogs/the-switch/wp/2015/06/11/facial-recognition-technology-is-everywhere-it-may-not-be-legal/
4 comments
It might be simpler to just wear a Burka.
Although at least in Germany this will collide with masking regulations (you are not allowed to mask in public gatherings).
Although at least in Germany this will collide with masking regulations (you are not allowed to mask in public gatherings).
Not just in Germany: https://en.wikipedia.org/wiki/Anti-mask_laws
In France in particular, there's a full ban in public places, even if there's no gathering.
In France in particular, there's a full ban in public places, even if there's no gathering.
I don't think the point was that we should all go to the scramble-suit store and buy a scramble suit...
No, but we need to keep ahead of this technology, and fight it whenever we can--for those that care? I'm beginning to think most people just don't care? What I find ironic is any criminal with any forethought is going to become a master of disguise--without going to that much trouble.
periocular recognition is also a thing :)
I would imagine that were this published in 2007, he would also include shoes with actuators in them that are constantly working to alter your gait; perhaps something that also affects how you move your hips or arms, although I'm not sure how this could be done.
https://en.wikipedia.org/wiki/Gait_analysis
https://en.wikipedia.org/wiki/Gait_analysis
Obligatory link to CV Dazzle (a site exploring the use of avant-garde hairstyles and makeup to foil facial recognition): http://cvdazzle.com/
Now imagine the cops in that comic have an unlimited amount of post-its which catalog the most minute and esoteric details about the faces of everyone in their city.
Also imagine that the cops have the ability to sift through and read those post-its at mechanical speeds.
Also, instead of cops they are Wal-Mart greeters.
Then you get closer to reality than the comic did regarding the topic of computer vision.
Also imagine that the cops have the ability to sift through and read those post-its at mechanical speeds.
Also, instead of cops they are Wal-Mart greeters.
Then you get closer to reality than the comic did regarding the topic of computer vision.
I hope you aren't implying a comic strip glossed over some details in an effort to reduce the message to a small, easily consumed and memorably sequence of events, just so they could fit within the limits of the form. I hold the medium in far to high a regard to consider that a possibility! ;)
Joking aside, I think you were primed to interpret the comic in a specific way which may not have been the intent. I don't think it was saying much about the state of surveillance using computer vision as much as it was showing the absurdity, at this point, of using a method that prevents computer vision from working but also makes you uniquely and easily identifiable. Eventually, if enough of the populace takes up a similar method of obfuscating their identity, then it's useful, as you are again anonymized as one among many, but until then you are an anonymous member of a very small group (possibly containing only you), which itself isn't very hard to identify. Not all that useful.
Joking aside, I think you were primed to interpret the comic in a specific way which may not have been the intent. I don't think it was saying much about the state of surveillance using computer vision as much as it was showing the absurdity, at this point, of using a method that prevents computer vision from working but also makes you uniquely and easily identifiable. Eventually, if enough of the populace takes up a similar method of obfuscating their identity, then it's useful, as you are again anonymized as one among many, but until then you are an anonymous member of a very small group (possibly containing only you), which itself isn't very hard to identify. Not all that useful.
I've spent the last three years either working for a company actively implementing facial recognition (and other biometrics) into both security/identity products and consumer retail products or just researching biometric technology in general.
I've come to the conclusion that there won't be a great shift forward in these technologies until someone comes along and completely reinvents the concept of privacy itself. I've seen retailer after retailer try to implement improvements to consumer experience (either through beacons and directed coupons or through some sort of identity recognition) only to be met with ENORMOUS backlash [1] from consumers freaking out because the store can tell where they are in the store at any given time. In security, iris recognition, voice recognition, and facial recognition are all methods of identification that cannot be stolen and yet all are methods of identification that freak people out to no end. They'd rather carry around an ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives than switch over to a more reliable biometric based method of identification
Privacy as we knew it is dead. It died a long time ago; hell you could probably argue that it started to die the first time anyone published a phone book because if I knew your name then I could figure out where you lived. Biometrics, to me, is a recapturing of privacy and personal identification because you no longer have to worry about relying on third parties to protect your identity (which is obviously not working [2]), YOU ARE YOUR IDENTITY. Your face, your voice, your fingerprint, your iris, all of these things cannot be spoofed and are uniquely yours and cannot be taken away from you.
As for the article, this is a perfect example of the kinds of things that require a reinvention of the notion of privacy. Used to be if you were captured on camera in public no one knew who you were unless someone you knew saw that picture and could identify you. Now with facial recognition, that's not possible anymore. But Pandora's box has been opened and it cannot be shut again so articles like this just seem totally pointless in light of that- they're missing the fundamental issue that facial recognition is a thing that exists and it's not going to stop existing just because we're all unsure how we feel about it. Yes I absolutely agree that facial recognition needs to be an opt-in where it can be, like on Facebook or Twitter or whatever. However we're living in a time when absolute right to privacy and anonymity in public no longer exists, and we need to figure out how to navigate that fast or else all of this biometric technology that can and should be used to make life easier is going to be regulated all to hell and we'll be stuck in paranoia-ville and afraid to leave our homes.
[1]http://consumerist.com/2013/05/10/nordstrom-decides-to-stop-... [2]http://www.cnbc.com/id/102752205
I've come to the conclusion that there won't be a great shift forward in these technologies until someone comes along and completely reinvents the concept of privacy itself. I've seen retailer after retailer try to implement improvements to consumer experience (either through beacons and directed coupons or through some sort of identity recognition) only to be met with ENORMOUS backlash [1] from consumers freaking out because the store can tell where they are in the store at any given time. In security, iris recognition, voice recognition, and facial recognition are all methods of identification that cannot be stolen and yet all are methods of identification that freak people out to no end. They'd rather carry around an ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives than switch over to a more reliable biometric based method of identification
Privacy as we knew it is dead. It died a long time ago; hell you could probably argue that it started to die the first time anyone published a phone book because if I knew your name then I could figure out where you lived. Biometrics, to me, is a recapturing of privacy and personal identification because you no longer have to worry about relying on third parties to protect your identity (which is obviously not working [2]), YOU ARE YOUR IDENTITY. Your face, your voice, your fingerprint, your iris, all of these things cannot be spoofed and are uniquely yours and cannot be taken away from you.
As for the article, this is a perfect example of the kinds of things that require a reinvention of the notion of privacy. Used to be if you were captured on camera in public no one knew who you were unless someone you knew saw that picture and could identify you. Now with facial recognition, that's not possible anymore. But Pandora's box has been opened and it cannot be shut again so articles like this just seem totally pointless in light of that- they're missing the fundamental issue that facial recognition is a thing that exists and it's not going to stop existing just because we're all unsure how we feel about it. Yes I absolutely agree that facial recognition needs to be an opt-in where it can be, like on Facebook or Twitter or whatever. However we're living in a time when absolute right to privacy and anonymity in public no longer exists, and we need to figure out how to navigate that fast or else all of this biometric technology that can and should be used to make life easier is going to be regulated all to hell and we'll be stuck in paranoia-ville and afraid to leave our homes.
[1]http://consumerist.com/2013/05/10/nordstrom-decides-to-stop-... [2]http://www.cnbc.com/id/102752205
Your face, your voice, your fingerprint, your iris, all of these things cannot be spoofed and are uniquely yours and cannot be taken away from you.
And you can't take them away from other people, nor revoke them when they are "compromised". In particular for faces and voices, they can be used to identify you without your knowledge and consent. That means they can be used to discriminate against you on whatever basis the discriminator chooses. This may just be price discrimination, which is what people are concerned about in the retail context. Or it may be more extreme. You could use it to deny job applications or credit to anyone who'd been at a political demonstration filmed by police, for example.
https://www.opendemocracy.net/opensecurity/val-swain/disrupt...
We have enough trouble with the simple human-recognisable biometric classifier of "race" being used to discriminate against people.
And you can't take them away from other people, nor revoke them when they are "compromised". In particular for faces and voices, they can be used to identify you without your knowledge and consent. That means they can be used to discriminate against you on whatever basis the discriminator chooses. This may just be price discrimination, which is what people are concerned about in the retail context. Or it may be more extreme. You could use it to deny job applications or credit to anyone who'd been at a political demonstration filmed by police, for example.
https://www.opendemocracy.net/opensecurity/val-swain/disrupt...
We have enough trouble with the simple human-recognisable biometric classifier of "race" being used to discriminate against people.
I agree with your comment. Yet tangentially those things can be taken away! At one point in several African countries they used finger prints for the ATM's. People suddenly started getting their fingers cut off by thieves. I would much rather give them a card then a part of my body.
Update: So I have been doing much Googling and can't find an accurate account of that happening. It appears there are some reports of it happening in Maylasia but that was for vehicles. Better yet is that in South Africa they are just blowing up the ATM's or ripping them outhttp://www.dailymail.co.uk/news/article-1198626/South-Africa..., which honestly makes more sense.
I did see that Poland is pushing out some new ATM's, that are also used in Japan, that use the pattern of veins instead of finger prints. The state this means the finger has to be attached to the person
Update: So I have been doing much Googling and can't find an accurate account of that happening. It appears there are some reports of it happening in Maylasia but that was for vehicles. Better yet is that in South Africa they are just blowing up the ATM's or ripping them outhttp://www.dailymail.co.uk/news/article-1198626/South-Africa..., which honestly makes more sense.
I did see that Poland is pushing out some new ATM's, that are also used in Japan, that use the pattern of veins instead of finger prints. The state this means the finger has to be attached to the person
Have you got some sources for this? If you've got criminal gangs willing to cut people's fingers off for their money, why do they bother instead of doing something easier and more reliable? The threat of having your fingers cut off would, I expect, be all that's needed to get people to hand over their cash. Sure, not everyone has got cash on them right now, but not everyone has got an ATM card on them and not everyone has got any money in their bank account. Additionally, they seem to be not fingerprint scanners, but vein pattern scanners, and the manufacturers seem to say that a finger no longer attached to a body won't be accepted.
If you're willing to cut people's fingers off and then walk to the ATM, you'd be willing to simply rob people in some other much easier and much more reliable way.
It seems that about a year ago someone was considering such ATMs [1]. Are you sure this isn't just the fears of people (as mentioned in the article) blown into urban legend?
[1] http://www.news24.com/Technology/News/Fingerprint-ATMs-Will-...
If you're willing to cut people's fingers off and then walk to the ATM, you'd be willing to simply rob people in some other much easier and much more reliable way.
It seems that about a year ago someone was considering such ATMs [1]. Are you sure this isn't just the fears of people (as mentioned in the article) blown into urban legend?
[1] http://www.news24.com/Technology/News/Fingerprint-ATMs-Will-...
Rational thieves, that's a new concept. Are you sure you haven't been overexposed to macroeconomics material recently?
As a single example, some burglars, when deciding which house to burgle, chooses the house that appear to be easiest to get into (poor physical security, no dogs, no alarms) and that will be easy to escape from (many of them open doors and windows as escape routes before they actually start the stealing). They pick ones that aren't hosting a party. They pick the ones that have concealed (or at least not overlooked) access.
Shoplifters - get this - will often wait until there isn't someone standing next to them before taking something off the shelf. Sounds like a good go at rationality to me.
Of course rational thieves exist. Not hyper-rational fictional models, but rational. The degree of rationality is a spectrum, as always, and is affected by physical and mental health and various other factors, but if you think rational thieves are a new concept, then you're living in some kind of fantasy world.
Shoplifters - get this - will often wait until there isn't someone standing next to them before taking something off the shelf. Sounds like a good go at rationality to me.
Of course rational thieves exist. Not hyper-rational fictional models, but rational. The degree of rationality is a spectrum, as always, and is affected by physical and mental health and various other factors, but if you think rational thieves are a new concept, then you're living in some kind of fantasy world.
Most theft is fueled by desperation.
Desperate people do desperate things for small, or often no gain.
People are injured or killed all the time over possessions they may or may not have on them.
Desperate people do desperate things for small, or often no gain.
People are injured or killed all the time over possessions they may or may not have on them.
Price discrimination? Denying credit? Sure, but there are far worse things to worry about.
How many people have escaped genocides with fake passports, or fake laissez-passer?
Worry that biometric will make it harder to escape being sent to the gulag, not that Walmart will deny you store credit.
How many people have escaped genocides with fake passports, or fake laissez-passer?
Worry that biometric will make it harder to escape being sent to the gulag, not that Walmart will deny you store credit.
Well, I was trying to give plausible first-world examples of the top of the slippery slope, because people might readily dismiss arguments about genocide as hyperbole.
I'm reminded of https://www.jewishvirtuallibrary.org/jsource/Holocaust/IBM.h...
In some ways we have the reverse situation prevailing; people are successfully escaping the genocidal collapse of the middle east into Europe, but are under threat of deportation by increasingly determined immigration enforcement.
I'm reminded of https://www.jewishvirtuallibrary.org/jsource/Holocaust/IBM.h...
In some ways we have the reverse situation prevailing; people are successfully escaping the genocidal collapse of the middle east into Europe, but are under threat of deportation by increasingly determined immigration enforcement.
You can, of course, worry about both.
> Price discrimination? Denying credit? Sure, but there are far worse things to worry about.
pjc50 (https://news.ycombinator.com/item?id=9705558) says exactly that:
> This may just be price discrimination, which is what people are concerned about in the retail context. Or it may be more extreme. You could use it to deny job applications or credit to anyone who'd been at a political demonstration filmed by police, for example.
pjc50 (https://news.ycombinator.com/item?id=9705558) says exactly that:
> This may just be price discrimination, which is what people are concerned about in the retail context. Or it may be more extreme. You could use it to deny job applications or credit to anyone who'd been at a political demonstration filmed by police, for example.
You have already many tags on your clothes that can be linked to you credit card and then to you.
Mine just has washing instructions, not a unique identifier.
They are hidden in many expensive clothes.
http://beforeitsnews.com/christian-news/2014/01/use-cash-tra...
http://beforeitsnews.com/christian-news/2014/01/use-cash-tra...
Wow those are some tags. The ones I dealt with (programming a portal scanner for WalMart) were the size of chips - would fit on your little fingernail. That article shows ginormous strips of plastic that would choke a badger.
I microwave my clothes.
What we need is more pervasive control of discrimination, then, and of other things that could use biometric information.
Simply "hiding" your biometrics or banning biometric identification altogether would be moving backwards in the bigger picture, which I'd compare to forbidding evolution research because it's against religious teaching.
Simply "hiding" your biometrics or banning biometric identification altogether would be moving backwards in the bigger picture, which I'd compare to forbidding evolution research because it's against religious teaching.
Unfortunately that “control of discrimination” can change uncontrollably in the future so any system we develop now should have some thought to the risks of leaving data which could be abused by a bad actor in the future.
The BackStory podcast had a recent episode on the history of surveillance in America:
http://backstoryradio.org/shows/keeping-tabs-2/
Among other topics, one segment discussed how a racist official in Virginia used data collected in the 19th century to protect free African Americans as part of his effort to enforce racial purity laws in the 20th century:
“HELEN ROUNTREE: In the county courthouses, there was another kind of record made, and that was the register of free Negroes. He had to get a certificate stating that they were of free birth, otherwise they could be kidnapped and sold into slavery.
The law about that went in in 1806. Plecker was able to get copies of those registers – every county had one. And then if he got a tip later and he could have his people trace geologically back to a free negro register, he had that present-day person as a person of African ancestry.”
The full segment is worth listening to:
https://soundcloud.com/backstory/one-data-point-one-drop
The BackStory podcast had a recent episode on the history of surveillance in America:
http://backstoryradio.org/shows/keeping-tabs-2/
Among other topics, one segment discussed how a racist official in Virginia used data collected in the 19th century to protect free African Americans as part of his effort to enforce racial purity laws in the 20th century:
“HELEN ROUNTREE: In the county courthouses, there was another kind of record made, and that was the register of free Negroes. He had to get a certificate stating that they were of free birth, otherwise they could be kidnapped and sold into slavery.
The law about that went in in 1806. Plecker was able to get copies of those registers – every county had one. And then if he got a tip later and he could have his people trace geologically back to a free negro register, he had that present-day person as a person of African ancestry.”
The full segment is worth listening to:
https://soundcloud.com/backstory/one-data-point-one-drop
pervasive control of discrimination
The US equal protection clause dates from 1868, and yet not just racism but actually unequal law enforcement is still widespread.
The US equal protection clause dates from 1868, and yet not just racism but actually unequal law enforcement is still widespread.
To take your "shopping improvement through beacons" example: A solution where the beacons merely send an ID (and not receive _anything_) and have the client do all the processing with a map of features they downloaded once would alleviate the issue. That would be customer service.
Using that data to track users in the shop is not. That's just Big Data.
If you're also interested in hot spots around the shop to optimize ways and where to present high value items, those can be obtained through different means (eg. light barriers that simply count and send accumulated data every 10 minutes - no need to infer where any given customer has been at any time).
When wondering about "ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives", there are several ways to approach it. One of them involves making loss of ID instruments a less severe event.
"ID theft protection services" is a business model I've only seen in the US.
It's not privacy that's broken, but lazy and unambitious business models that collect data first and think about how to use it second, and tolerate that abuse of that data leads to horrible outcomes every now and then (as long as it's on somebody else's dime).
So your concern is that privacy gets in the way of commercializing biometric technology. May it do that for a long, long time.
Using that data to track users in the shop is not. That's just Big Data.
If you're also interested in hot spots around the shop to optimize ways and where to present high value items, those can be obtained through different means (eg. light barriers that simply count and send accumulated data every 10 minutes - no need to infer where any given customer has been at any time).
When wondering about "ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives", there are several ways to approach it. One of them involves making loss of ID instruments a less severe event.
"ID theft protection services" is a business model I've only seen in the US.
It's not privacy that's broken, but lazy and unambitious business models that collect data first and think about how to use it second, and tolerate that abuse of that data leads to horrible outcomes every now and then (as long as it's on somebody else's dime).
So your concern is that privacy gets in the way of commercializing biometric technology. May it do that for a long, long time.
Pretty sure the transmit-only beacons you describe that just broadcast an ID are exactly what Apple iBeacons are. Basically just indoor GPS. (And yet there was still massive privacy backlash, go figure)
According to http://consumerist.com/2013/05/08/nordstrom-now-using-your-s... they tracked MAC addresses.
That is not iBeacon.
I was still referring to the original comment's incident with Nordstrom.
So iBeacon provides a proper solution? Great. What's your point - that privacy-friendly solutions are possible? Then we're in violent agreement (see my original reply in this thread).
So iBeacon provides a proper solution? Great. What's your point - that privacy-friendly solutions are possible? Then we're in violent agreement (see my original reply in this thread).
I wasn't arguing with you, I was just adding that the ideal solution you present as a hypothetical is pretty close to something readily available.
We don't need the concept of privacy to be reinvented so much as we need the US to catch up with Europe on strong legal protections and active enforcement. The fear of tracking is driven by quite reasonable expectations that this data will be abused and mistakes impossible to correct with little recourse for the average person.
If, instead, there were limits on what could be shared and companies were credibly liable for misuse, breaches, etc. I think many people would be far less concerned with use of information.
> Your face, your voice, your fingerprint, your iris, all of these things cannot be spoofed and are uniquely yours and cannot be taken away from you.
Conversely, this illustrates how important it is to have massive penalties – on the scale of “you are out of business and managers cannot have a position of authority involving personal data for years” – for storing biometric data because there's no way to recover when it's compromised. This is particularly important when you realize that biometric data cannot be trusted over a network connection so there's no point in deploying biometric systems anyway because they can only be trusted when one entity has end-to-end control over the entire system.
What should be deployed is PKI which, unlike direct biometrics, can be made robust against compromises using a revocation mechanism. This also allows biometrics to be used safely because you could have an authenticator which uses biometrics which never leave the device and has no replay value for an attacker once a compromise has been discovered.
Consider the recent breach at the U.S. Office of Personnel Management. The attackers reportedly got everything listed on background and security clearance applications, which burns every common authentication system because the attacker could easily answer most “security” questions. Consider how much worse that would have been if biometrics were in common use and scans of fingerprints, voice or iris patterns, etc. were also available to the attacker.
If, instead, there were limits on what could be shared and companies were credibly liable for misuse, breaches, etc. I think many people would be far less concerned with use of information.
> Your face, your voice, your fingerprint, your iris, all of these things cannot be spoofed and are uniquely yours and cannot be taken away from you.
Conversely, this illustrates how important it is to have massive penalties – on the scale of “you are out of business and managers cannot have a position of authority involving personal data for years” – for storing biometric data because there's no way to recover when it's compromised. This is particularly important when you realize that biometric data cannot be trusted over a network connection so there's no point in deploying biometric systems anyway because they can only be trusted when one entity has end-to-end control over the entire system.
What should be deployed is PKI which, unlike direct biometrics, can be made robust against compromises using a revocation mechanism. This also allows biometrics to be used safely because you could have an authenticator which uses biometrics which never leave the device and has no replay value for an attacker once a compromise has been discovered.
Consider the recent breach at the U.S. Office of Personnel Management. The attackers reportedly got everything listed on background and security clearance applications, which burns every common authentication system because the attacker could easily answer most “security” questions. Consider how much worse that would have been if biometrics were in common use and scans of fingerprints, voice or iris patterns, etc. were also available to the attacker.
> we need the US to catch up with Europe
Europe is on a path to technological stagnation and demographic collapse. There's a reason its economy is depressed, its electricity fantastically expensive, its people angry, its programmer wages depressed, and its startup scene anemic.
Europeans refuse to embrace modern technology like genetic modification and nuclear power, much less allow the flourishing of information technology. They'd rather comfort themselves with their pseudoscience and their precautionary principle and their Luddite privacy regulations than join the rest of world in imagining something better.
Europe is absolutely no model to emulate.
Europe is on a path to technological stagnation and demographic collapse. There's a reason its economy is depressed, its electricity fantastically expensive, its people angry, its programmer wages depressed, and its startup scene anemic.
Europeans refuse to embrace modern technology like genetic modification and nuclear power, much less allow the flourishing of information technology. They'd rather comfort themselves with their pseudoscience and their precautionary principle and their Luddite privacy regulations than join the rest of world in imagining something better.
Europe is absolutely no model to emulate.
A more careful reader might notice that I was specifically referring to privacy. If you wanted to have a conversation about something else, preferably involving citations not from U.S. political blogs, this is not the place for it.
Irrational and emotional European paranoia on privacy chills technological development. Look at all the silly cookie warning on the European web. Now imagine having to "warn" users before applying basic algorithms to data they willingly provide.
Let it be known that an entire continent's economy has been suffocated because of warning boxes on users' computer screens.
I don't mean to derail a rant with inconvenient facts, but 75% of France's power comes from nuclear power and they have the ITER fusion research facility.
And a big segment of the French public loathes nuclear: http://www.seattlepi.com/business/energy/article/French-bill...
The shortsighted and fearful German Greens are making that country shut down nuclear plants and switch to filty brown coal: http://www.bloomberg.com/news/articles/2014-04-14/coal-rises...
ITER isn't getting nearly enough funding, and it took a fucking decade to decide on the place to build it.
Europeans have the same fearful attitude toward GMOs.
The shortsighted and fearful German Greens are making that country shut down nuclear plants and switch to filty brown coal: http://www.bloomberg.com/news/articles/2014-04-14/coal-rises...
ITER isn't getting nearly enough funding, and it took a fucking decade to decide on the place to build it.
Europeans have the same fearful attitude toward GMOs.
It's not just the German Greens. There is a consensus on shutting down nuclear pants among basically all political parties in Germany. A conservative coalition was at power when Fukushima happened and the early shutdown of the plants was decided.
A substantial number of people object the GM foods on the grounds that it will inevitably limit their freedom of choice. Americans are supposedly in favour of freedom of choice but it seems that such freedoms can only be exercised by large corporations.
You are free to buy whatever foods you want. If you only want to buy organic or non-GMO, then there is nothing preventing you from doing so.
As a European this post made physically laugh out loud, bravo!.
Privacy is dying because there will always be people willing to implement anything for enough money.
> They'd rather carry around an ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives than switch over to a more reliable biometric based method of identification
That's a problem with the financial institutions, not a problem with privacy. Reliable biometric identification is not a requirement for safe finances.
Credit bureaus having way too much power over the lives of individuals (see, privacy!) is as big a part of the problem.
> They'd rather carry around an ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives than switch over to a more reliable biometric based method of identification
That's a problem with the financial institutions, not a problem with privacy. Reliable biometric identification is not a requirement for safe finances.
Credit bureaus having way too much power over the lives of individuals (see, privacy!) is as big a part of the problem.
> an ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives
Not the first time I read this. It seems that in USA the identity theft issue is a very big one... even someone knowing your bank account number is hugely risky, from what I read. This not need be like this, there are other countries where this is adequately protected by law.
In Europe is normal for small businesses to publish their bank account so people can send them the money of a purchase, and that does not put them in risk. Also, for me it is unheard of that someone had a problem because his/her ID got stolen. Credit cards? Ok. But ID?
Is it a law issue? A financial industry one? (Another poignant thing for me is the degree to which US, France and other countries still use the cheque, or the problems to pay with international cards - visa / mastercard / amex - in Germany).
Not the first time I read this. It seems that in USA the identity theft issue is a very big one... even someone knowing your bank account number is hugely risky, from what I read. This not need be like this, there are other countries where this is adequately protected by law.
In Europe is normal for small businesses to publish their bank account so people can send them the money of a purchase, and that does not put them in risk. Also, for me it is unheard of that someone had a problem because his/her ID got stolen. Credit cards? Ok. But ID?
Is it a law issue? A financial industry one? (Another poignant thing for me is the degree to which US, France and other countries still use the cheque, or the problems to pay with international cards - visa / mastercard / amex - in Germany).
To give another perspective: you are legally required in Brazil to have ID (I'll spare you the fact that they are two IDs, it's historical and uninportant). You are not required to carry one, but almost everyone does, as having to show ID is very common. Even for things like store purchases, if you are not paying in cash. Or medical care.
IDs get lost/stolen all the time. They are sometimes used by crooks to do nasty stuff, such as try (and sometimes succeeding) to open companies in your name, bank accounts and the like.
However, should you lose your ID, you need to go to a police station to file what's called a "BO" (loosely translated 'accident report'). This can be done electronically these days (unless there was violence involved).
Should an identity theft happen, this document is usually enough to clear you up of any wrongdoing. And to undo whatever damage, financial or otherwise. It can still be a hassle, but nowhere near "ruining the financial livehood", much less for the rest of one's life.
It helps that checks are almost dead already and all bills can be paid electronically.
IDs get lost/stolen all the time. They are sometimes used by crooks to do nasty stuff, such as try (and sometimes succeeding) to open companies in your name, bank accounts and the like.
However, should you lose your ID, you need to go to a police station to file what's called a "BO" (loosely translated 'accident report'). This can be done electronically these days (unless there was violence involved).
Should an identity theft happen, this document is usually enough to clear you up of any wrongdoing. And to undo whatever damage, financial or otherwise. It can still be a hassle, but nowhere near "ruining the financial livehood", much less for the rest of one's life.
It helps that checks are almost dead already and all bills can be paid electronically.
The US has (a) a much greater insistence on credit and credit checks (b) a pseudo-ID system in the "social security number" that doesn't really work and (c) much weaker consumer protection.
"ID theft" really means "credit fraudulently obtained in one's name". That this is a problem for the person whose name was used and not the business defrauded is a tribute to the US's strong pro-business culture.
"ID theft" really means "credit fraudulently obtained in one's name". That this is a problem for the person whose name was used and not the business defrauded is a tribute to the US's strong pro-business culture.
Agreed. But ID theft can go far beyond that of course. It can involve filing for your tax refund in your name, or getting fake IDs and committing crimes in your name, or registering websites etc in your name as a cover. It goes far beyond credit, though that is certainly a popular scam.
Following the usual US business standard, it's probably just cheaper to deal with it as it stands instead of fixing it.
For example, create a law that forces a business that transacts with an identity thief to pay to the victim three times (or whatever) the amount spent in their name as compensation. Then you might see some changes being discussed.
For example, create a law that forces a business that transacts with an identity thief to pay to the victim three times (or whatever) the amount spent in their name as compensation. Then you might see some changes being discussed.
Of course your voice/fingerprint/face can be taken from you - with a camera, or fingerprint kit, or tape recorder. Then you're stuck - you can't change them. THAT's when you're screwed for life. The plastic ID can be changed at will, which is why its infinitely more appropriate for secure application. A good security key (password) should be changed often, which is of course impossible with biometrics.
> They'd rather carry around an ID that can be stolen, copied, and sold on the black market thus ruining their financial livelihood for the rest of their lives than switch over to a more reliable biometric based method of identificatio
I'd rather have my ID token stolen than my finger chopped off.
I'd rather have my ID token stolen than my finger chopped off.
Biometrics are helpful for identification, but useless for securing anything. As a password it has all the wrong properties. It cannot be changed regularly; you leave it out in the open all the time, its way too simple (most fingerprint 'biometrics' reduce your print to about 10 bits, like your garage door opener code).
See this is another thing that has to be changed in the public perception before biometrics become viable for widespread usage- they're useful for some things but not others, for exactly the reasons you lay out here. They're not a be all end all and immediately solve all problems of both identity AND access management, and they need to be applied judiciously and only when they actually solve a problem.
Some people should watch Demolition Man to understand why biometrics might not be quite as secure as one may think.
In this one particular instance, liveness detection is what keeps that from being a viable thing, as does combining multiple methods of authentication and not just relying on one biometric modality for identification.
Are people desperate enough to chop off a finger to gain access necessarily going to check if there's a liveness detector first?
To "reinvent the notion of privacy" so that it's socially acceptable all we need to do is agree to one rule -
If you are going to financially benefit in anyway directly/indirectly from my biometric data, you pay me each time you do so. Privacy maybe dead, but wealth doesn't need to accumulate in the hands of Mr. Zuckerberg because of it.
$34 Billion zuck tax that the world has contributed to is more than enough.
I am picking on poor Zuck here but we all know whatever wealth gets generated from biometrics is going to land up in the hands of the few who already own all our data.
I am picking on poor Zuck here but we all know whatever wealth gets generated from biometrics is going to land up in the hands of the few who already own all our data.
Financial benefit is not all that easy to prove. Put another way, it's easy to make it ambiguous as to whether the use of the biometric information was responsible for the financial benefit. Think parallel construction.
Biometrics are unsafe as hell. It's often amusing how easy those systems are to circumvent (printing out a picture of someone for face recognition for instance, fingerprint scanners near to places where you leave fingerprints like a door handle).
One common failure of biometrics is that they often fail to work reliably and then you have to offer a feedback mechanism that offers really low security. Security is always only as strong as its weakest link.
One common failure of biometrics is that they often fail to work reliably and then you have to offer a feedback mechanism that offers really low security. Security is always only as strong as its weakest link.
"Your face, your voice, your fingerprint, your iris, all of these things cannot be spoofed..."
Maybe I'm misunderstanding your focus here, but face, fingerprints, iris and voice prints have all been spoofed - some of them trivially easily. Fingerprints are particularly problematic as you leave them on most things you touch. Fingerprints have been lifted off of objects and fooled scanners with apparatus as everyday as gummi bears...
Maybe I'm misunderstanding your focus here, but face, fingerprints, iris and voice prints have all been spoofed - some of them trivially easily. Fingerprints are particularly problematic as you leave them on most things you touch. Fingerprints have been lifted off of objects and fooled scanners with apparatus as everyday as gummi bears...
It's entirely possible for biometrics to spoofed. For example, folks have already figured out how to trick deep neural nets:
http://arxiv.org/abs/1412.1897
Not to mention bio-engineering possibilities on the horizon. Of course, just because we can use a certain technology doesn't mean we should...
http://arxiv.org/abs/1412.1897
Not to mention bio-engineering possibilities on the horizon. Of course, just because we can use a certain technology doesn't mean we should...
One nice thing about an ID is that I can leave it in my pocket if I don't want to identify myself. That's much harder to do with biometric identity.
Again, though, that's the Pandora's box of the argument- these technologies already exist and are in the wild, so we must come up with a way to co-exist with them instead of hand wringing and fretting that the world is changing and there's nothing we can do about it.
I'm absolutely on the side of wanting to come up with those as yet unknown solutions, and I abhor all of the people who say "well just don't be doing anything illegal and then it won't matter!" I'm suggesting a fundamental shift in the underlying societal zeitgeist which, I realize, is a huge stretch and a bit of a pipe dream, but I can still hope.
To clarify- I'm NOT saying it shouldn't be regulated, and I'm NOT saying we need to move to some sort of post-privacy utopia, I am saying "Gee it'd be nice if we moved past the hand wringing and started coming up with ways to use this technology in beneficial ways.)
I'm absolutely on the side of wanting to come up with those as yet unknown solutions, and I abhor all of the people who say "well just don't be doing anything illegal and then it won't matter!" I'm suggesting a fundamental shift in the underlying societal zeitgeist which, I realize, is a huge stretch and a bit of a pipe dream, but I can still hope.
To clarify- I'm NOT saying it shouldn't be regulated, and I'm NOT saying we need to move to some sort of post-privacy utopia, I am saying "Gee it'd be nice if we moved past the hand wringing and started coming up with ways to use this technology in beneficial ways.)
I don't know why you think that it's impossible to regulate these technologies. There could be laws against biometric identification without consent of the identified.
My brain does biometric identification. Are you going to outlaw my brain?
It's demonstrably incapable of nuance, you might want to get it checked out.
Shift to what, though? This is a bit like the vague calls to overthrow capitalism and replace it with something nicer. We're to overthrow privacy and replace it with .. what? We're really not ready for Culture-style machine-enforced morality.
"However we're living in a time when absolute right to privacy and anonymity in public no longer exists..."
And that is the crux of the issue. It needs to be made a right and enforced like every other right. The problem is that it isn't and it is like the wild west when it comes to people's privacy and data. Given the rapid rise of big data and the surveillance state I would say that a time of flux is just starting. My sincere hope is that it ends with strengthened rights for the individual. I am not convinced it will, however.
And that is the crux of the issue. It needs to be made a right and enforced like every other right. The problem is that it isn't and it is like the wild west when it comes to people's privacy and data. Given the rapid rise of big data and the surveillance state I would say that a time of flux is just starting. My sincere hope is that it ends with strengthened rights for the individual. I am not convinced it will, however.
>> Privacy as we knew it is dead. It died a long time ago; hell you could probably argue that it started to die the first time anyone published a phone book because if I knew your name then I could figure out where you lived.
A quibble, but perhaps not a minor one. Privacy and anonymity are not the same thing. While it's possible to argue that the U.S. constitution confers a right of privacy, I am not aware of any serious argument that it also confers a right of anonymity.
A quibble, but perhaps not a minor one. Privacy and anonymity are not the same thing. While it's possible to argue that the U.S. constitution confers a right of privacy, I am not aware of any serious argument that it also confers a right of anonymity.
Yes, and I agree with them. There is a right to "anonymous free speech". But that is not the same as a general right to anonymity, and I would question whether anyone has a general right to remain unknown.
So the biometric information used to identify an individual can't be stolen? How is that possible? I can change a password, and I can replace a hardware token.
Where people live has never been private information. Nor has the whereabouts of a particular person (other people may or may not know the whereabouts of someone, but if I happen to see you walk into your house, I'm not violating privacy as we know it).
It's also the case that fingers, voice and eyes can be taken from a person. It's a brutally violent act, but it's quite possible. Maybe not in way that is useful in attacking biometric security, but think denial of service...
What we need is to take the thin concepts around publicity rights and expand them a bit. So for instance, Walmart probably has reasonable business reasons to track purchases, but society can push back and say that they are not allowed to publish those observations without the permission of the observed (or at least clear notification).
It's also the case that fingers, voice and eyes can be taken from a person. It's a brutally violent act, but it's quite possible. Maybe not in way that is useful in attacking biometric security, but think denial of service...
What we need is to take the thin concepts around publicity rights and expand them a bit. So for instance, Walmart probably has reasonable business reasons to track purchases, but society can push back and say that they are not allowed to publish those observations without the permission of the observed (or at least clear notification).
[deleted]
> more reliable biometric based ID
> Privacy as we knew it is dead
I wonder if the next round of physical criminal technology advances will be about shielding and forging identities, using fake fingerprints (3d printed, perhaps), fake contacts (again, perhaps 3d printable?), fake faces (again, perhaps 3d printable, plus makeup?), fake gaits/comportment (which can be disguised or imitated, with enough practice).
And where that's not practical, like DNA evidence at crime scenes, there will be countermeasures. The second episode of Almost Human comes to mind, with its passing mention of "DNA bombs" that shower a room with what I expect was imagined as lots and lots of dna snippets, or perhaps rapid-growing bacteria or fungi with many engineered variants of human STR loci to FUBAR PCR analysis.
> Privacy as we knew it is dead
I wonder if the next round of physical criminal technology advances will be about shielding and forging identities, using fake fingerprints (3d printed, perhaps), fake contacts (again, perhaps 3d printable?), fake faces (again, perhaps 3d printable, plus makeup?), fake gaits/comportment (which can be disguised or imitated, with enough practice).
And where that's not practical, like DNA evidence at crime scenes, there will be countermeasures. The second episode of Almost Human comes to mind, with its passing mention of "DNA bombs" that shower a room with what I expect was imagined as lots and lots of dna snippets, or perhaps rapid-growing bacteria or fungi with many engineered variants of human STR loci to FUBAR PCR analysis.
I wonder if Nordstrom's collection allowed them to have personally identifiable information. It seems like they just shipped it off to a third-party analytics company, which might be worse since they could do things like match up your MAC address with another place you shopped at. Just speculation, though.
Can you carry a small laser on you that can fry the sensor? It is not that hard to make it invisible and automated.
No, a small laser won't fry a normal camera. And how will you know where all the cameras are anyway? Also that would be very illegal.
A green laser will happily burn out sensors, but you'd have to really work at it to burn up all of the sensor because the laser light will typically only fry a couple of pixels at the time.
It's not a magical 'point and fry' solution, more like a take up position and stand around for half an hour or so while the laser systematically hits every bit of the sensor long enough to fry it. A hammer would be a lot more effective (assuming you can reach the camera).
It's not a magical 'point and fry' solution, more like a take up position and stand around for half an hour or so while the laser systematically hits every bit of the sensor long enough to fry it. A hammer would be a lot more effective (assuming you can reach the camera).
> A hammer would be a lot more effective (assuming you can reach the camera).
So would a can of spray paint.
So would a can of spray paint.
What it can do quite easily is mess with the AGC / white balance while a big part of the image is obscured by a bright green blog. As a temporary effect this may be good enough, and has the advantage of not being property damage.
For confirmation: [1] is a video of someone assaulting their webcam with a 1.5w blue laser. All it does is create a few horizontal lines, burn a few tiny marks on the image, and discolor the highlights.
[1]: https://youtu.be/zNUgO1Npihk?t=130
[1]: https://youtu.be/zNUgO1Npihk?t=130
I've seen products such as hats with infrared LEDs mounted on them; if the sensor doesn't have an infrared filter in front of it, it looks like a person's head is just a bright light.
Those hats fail really hard. An IR led looks like a point of dim light on cam. You need hundreds of them to achieve an obliterating effect.
You often see the hat. You rarely see what it looks like to various cameras.
You often see the hat. You rarely see what it looks like to various cameras.
As the computer looped through its banks, it projected every conceivable eye color, hair color, shape and type of nose, formation of teeth, configuration of facial bone structure - the entire shroudlike membrane took on whatever physical characteristics were projected at any nanosecond, then switched to the next...
In any case, the wearer of a scramble suit was Everyman and in every combination (up to combinations of a million and a half sub-bits) during the course of each hour. Hence, any description of him - or her - was meaningless.
From A Scanner Darkly, by Philip K. Dick.
Published by Not Known in 1977