Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'
wired.com
wired.com
"The new authentication scheme is the second in recent weeks that relies on photos. Earlier this month, Facebook asked users to upload nude photos to Facebook Messenger, as part of an effort to prevent revenge porn. Facebook said it would use the nude photos to create a digital fingerprint against which to compare future posts."
Wait what? I had to check whether today was April 1st.
Teenagers who have naked photos in the possession of their peers need a solution for preventing dissemination.
And so if you're in this situation trusting Facebook is by far the lesser of two evils.
I am just surprised Facebook didn't instead look at a way of running these image hashing algorithms on the device instead.
[1] - https://www.theverge.com/2017/11/9/16630900/facebook-revenge...
If you want Facebook's computers to automatically take down any copies of the photo, yes, you're going to have to trust them with a copy of it.
Automated DMCA takedowns of copyrighted music and movies work in very much the same way.
No. They could have you compute a fingerprint locally without uploading the image itself, preferably through some audited open source software, without auto-updates. They only don't do that because they want to guard their image hashing as corporate secrets.
if there is no match you gave them no data of interest. if there is a match then they already have that image anyway and you didn't make your privacy situation worse, except maybe telling them that you claim that is you, now allowing them to associate more images was you, but that's probably an acceptable tradeoff if there is actual revenge porn of you out there.
Regardless, I think your point stands.
If they don't have it, but are doing verify-after, then the image won't actually be blocked right away. The proposed system would be of pretty marginal value. Some value, yes, but low enough that facebook decided it wasn't worth building that system.
You can't avoid having a tradeoff somewhere.
one downside: i think this could allow a bad actor to directly observe the fingerprinting and assist in developing a method to defeat it.
That's what is missing from the internet, generally speaking. Services like public notaries. That's kindof what CAs provide. But there are a lot of similar services that could exist for things like this.
Though really would be better to fingerprint all removed photos and automatically prevent any matching photos from being uploaded.
You should just post the nudes yourself IMHO and be done with it.
I imagine for most people in most situations regarding their* unwanted explicit media being published, the opposite is true i.e. Facebook(social media) is the worst place for it to be
You do have a choice, use the service or not. If I ever found out a nude picture of me was leaked, I'd definitely trust FB more than whoever took it and leaked it in the first place. The whole point of the service is pretty much: your picture is already or about to be out there.
But basically saying “as long as it is unreversable” is redundant unless you think there’s some reason to think the hash sucks.
For starters, it's intended for victims of revenge porn, which is a fairly extreme category and one in which the harassment is distinctively aggressive and virulent. Because if it weren't, the way FB deals with abusive content generally would seem to be good enough. If you come into this thinking that FB is asking everyone to upload their nudes for "safekeeping", then you've missed the point.
Secondly, it's hard to think of an implementation that wouldn't create a potential disaster that justifies doing anything special for revenge porn victims. Using the Facebook app is the most secure channel for sending FB the photos because it is a secure app that all FB users know how to use. Having the user hash on their own requires either an external app or website.
I don't think it needs to be said how such ancillary applications can be spoofed. Even if only 0.5% of users are dumb enough to fall for these spoofs, each incident would be a complete fucking disaster, for the victims and for Facebook.
As for the prospect of FB owning people's nudes. Again, in the case of revenge porn victims, the horse is already far from the barn. If we assign the worst of motives to FB, that it's a way to secretly collect nudes from users. Again, horse, barn. This secret process would be less efficient by magnitudes compared to what FB can already do today.
"We remove photographs of people displaying genitals or focusing in on fully exposed buttocks. We also restrict some images of female breasts if they include the nipple, but our intent is to allow images that are shared for medical or health purposes. We also allow photos of women actively engaged in breastfeeding or showing breasts with post-mastectomy scarring. We also allow photographs of paintings, sculptures, and other art that depicts nude figures. Restrictions on the display of sexual activity also apply to digitally created content unless the content is posted for educational, humorous, or satirical purposes. Explicit images of sexual intercourse are prohibited. Descriptions of sexual acts that go into vivid detail may also be removed." https://www.facebook.com/communitystandards#nudity
If a user shares pornographic content, it may be visible on the site for a short period of time before the content is removed by Facebook.
The goal of the initiative Facebook was attempting to implement was to prevent any revenge-porn photos from being shared on the website at all. Even for a brief period of time.
From a user's standpoint, one hour of pornographic content available is disturbing but not catastrophic. However, one hour of images of pornographic content of themselves being shown to their friends and family is catastrophic.
It's kind of like having the police live at your house because 'just in case'.
I think the idea isn't that this is a "just in case" service. More like, if someone sends you a message that they've got compromising photos of you and will release them unless you pay $XX,XXX then you would use the service.
In the analogy, it'd be more like having the police live at your house after having a credible threat made against your life. Which is a thing that happens
Classification is a harder problem to begin with, and 'pornographic' is a subjective judgement.
- It sets a precedent for uploading nude photos to FB and for them asking for it.
- You need to trust FB to delete the photos when they receive it. Yes, I understand that they probably will, but really, how many systems are those bits going to touch? How many logs are going to have this information? Can you be really sure?
A better implementation would be for the FB client to hash the file and for the hash to be uploaded. Trust issues are still there but at least mitigated to devices that you have some control over.
Evil users that hash legitimate photos can be overcome with the same review system that is being tested today.
Before we reduce this to a slippery slope, what scenario do you envision in which FB could coax its userbase to upload nude photos? I know the OP is about taking a selfie to prove existence. What would FB use as the basis to mandate the general user to send a self-nude?
> You need to trust FB to delete the photos when they receive it...can you really be sure?
No, never, of course. But that's why I point out that FB already has this potential vector of attack. Every time a user flags content for abuse, that is logged and presumably a copy of the asset made for manual verification. Nevermind all the sensitive content millions of users everyday send across Messenger or private groups.
> A better implementation would be for the FB client to hash the file and for the hash to be uploaded.
If the image is hashed before it reaches FB servers, then it gives every user the power and impunity to attempt to censor via a Content-ID like approach.
The one where FB asks its userbase to upload nude photos[0].
Another commenter makes a good point that you could still have a human verify the first time a provided hash matches an image.
In the current setup, there is a human that verifies the image to be hashed is a nude photo instead of the McDonald's profile picture. In the proposed setup, you wait until a hash matches the photo and then have a human verify if it's pornographic content.
Let's assume that it is possible, the other issue that might come up is that the system is still suspect to a sort of denial of service attack, in which a group (for whatever reason) floods FB with purported sensitive images, and FB is flooded with constant takedown requests to review.
The current implementation can be attacked by uploading thousands of legitimate images delaying takedown requests - therefore any images that should be taken down will stay up longer.
I'll agree that whatever approach FB is doing to hash the photos may not work on a phone for technical reasons, but given FB's resources I'm not sure how far that argument really goes. But consider this - if you truly, deeply cared about user safety and privacy, would you implement this feature the same way?
How would that work, exactly? A user uploads hundreds of fraudulent images to FB's revenge-porn-abuse queue. At some point, the human who verifies whether the image is legit is going to realize that the user account is fraudulent and then disable the account.
If images are hashed, FB has no way to know if a user who is uploading hundreds of hashes is a malicious user or is actually an incredibly unfortunate revenge-porn victim. And the price for being wrong is extremely high. Maybe it's possible for FB's auto-detection system to be robust if the hashes it has to scan for is now several orders of magnitude than ever expected, making this all a moot point. But I can't imagine that the system scales with no penalty.
> But consider this - if you truly, deeply cared about user safety and privacy, would you implement this feature the same way?
The wording of your question implies a false dilemma, and I think reveals how different the premises you and I have about it. What exactly about Facebook's implementation of this feature makes it any less safe for users and their privacy than not having the feature at all? When a user sees and reports an abusive image of themselves -- that photo and that user, and that user's connection to the photo are already in Facebook's system".
Every fear there is about this data being exposed to malicious human workers, or that FB is trying to harvest sensitive images for nefarious means -- that risk has always existed. How do you think abuse-takedown requests are currently handled?
So if my argument is accurate, that an evil-pervy Facebook wants to do a mass collection of sensitive/comprising images of its user, all the infrastructure and dataflow is already in place, then this revenge-porn initiative does nothing to make that process more efficient. Even worse for pervy-Facebook, the initiative's very existence, nevermind announcing it, reminds the entire world again that holy-shit-think-of-all-the data-Facebook-has-on-us-including-our-sexy-times -- which is generally the kind of PR you want to avoid when you're conspiring to mass-harvest illicit imagery and data.
And let's be real here: Facebook doesn't have to do anything special for revenge porn victims, in the way that the Postal Service isn't obligated to open everyone's mail to make absolutely sure there's no child porn being sent -- the act of prevention ends up causing far more harm to all users than it benefits the comparatively small number of potential victims.
The status quo seems to be to do nothing until reports come in, which is OK for most situations but inadequate for the kind of attack vector that revenge-porn victims suffer. Facebook could have accepted that, as everyone else does, but invested time/resources into coming up with a technical solution that only benefits a very small but high-suffering part of its userbase while not increasing invasiveness (FB already autoscans the content of user messages, including with the use of PhotoDNA [0]).
Call me Pollyannish, but I don't see this instance as yet another time of Facebook being heartless and devious.
[0] http://www.businessinsider.com/facebook-google-and-microsoft...
They could jump straight to using ml and ai and the future where only you are in charge of who sees your FacebookEroticExpressions™ on any platform, all across the cloud!
But in the mean time they should probably tell her/him/them if they use the method that already exist to upload them we can use the method that already exist to have them gone in time for recess/study hall/wedding day/when Congress resumes/his state of the Union Address this evening/etc.
Also, if you just give us the other ones that undoubtedly exist we can nip this whole thing in the bud right now.
Phishing attacks against users that this feature is supposed to protect are more likely to succeed.
Now, it's fair to say that even in a technically safer implementation where the photos never leave the device, many users can't tell the difference, so this point doesn't hold a lot of water.
Still, I think making the uploading of scandalous photos to FB is a dangerous precedent to set in general. Will other services and startups that have users suffer from the same problem implement this feature in the same way, and guarantee user safety and privacy? That's a pretty high bar.
umm, no. If I understand correctly, the user believes that their nude may end up on FB. The user takes initiative to upload their copy of the nude to FB to prove ownership or damages.
https://news.ycombinator.com/item?id=15648080
https://www.google.com/search?q=ycombinator+fb+revenge+porn
> too lazy to look it up now
People doing this frustrates me greatly. You had to type 30 key strokes. ⌘+t "ycombinator fb revenge porn" ↵ and paste the results back. How many people are going to read your comment? Maybe 10% of them want to read those links. You spared yourself a trivial amount effort by offloading it to tens or hundreds of others.
I wish people would provide links and source what they say more often. Maybe more discussion sites should let others suggest edits, like on stackoverflow. We could save some of that wasted effort.
What? Why can't the hashing take place in the FB Messenger app on your phone? Why does the picture need to be uploaded to FB's servers? That just goes to what Troy Hunt was saying earlier today in his testimony to Congress about how corporations are collecting data that they shouldn't even want to have. They should collect only the hash from your phone, not the picture. The hashing should be done locally to your device.
I mean, I consciously think about every time I actually give a close approximation on my age in a public forum (like I did above), and make a call on whether it's needed or not. I feel like a dinosaur because of it sometimes, but I also feel like there's only so much privacy you're allotted, and once it's lost, there's really no getting it back. :/
in theory or in practice? do these ways have other caveats?
What does this FB thing protect against? In practice? Upload the images as a zip file, message "hi, here's X in the nude, remove all fruit from htappletp://linkbananashortener.copearm/84395708345643785 and use "theytrustmedumbzuckerbergfucks" minus the FB founder as password". Yeah, it's a hurdle, but those who want to see the images will take it in a heartbeat, and abusers can still do things like message all mutual "friends", right there on FB. So you gained nothing, and pre-emptively gave FB your nude photos.
Besides, Barrin92 said "If someone sees their own nudes show up on facebook" -- well, nude images aren't allowed on FB anyway, are they? So if you or anyone else can see them, if they're not posted in a private group or private messages, you can just report them, no need to even give away that it's you in them. Then what would stop FB from generating perceptual hashes of these images and removing them site-wide and in the future?
There's so many holes in this that I can't really get mad on behalf of the people who fall for it.
This reads more like a gullibility challenge than a true rationale.
http://www.thecrimson.com/article/2003/11/19/facemash-creato...
Example: SphereFace: Deep Hypersphere Embedding for Face Recognition
Pedophiles would be using something encrypted and anonymous anyway.
Except for the ones who apply for a job reviewing the nudes Facebook is collecting, anyway.
Facebook has absolutely no businesses to store nude pictures of their users.
Note that they explicitly state that a human will look at the image and then hash it. So they are storing it at least for a while. And you will not be able to verify whether they really delete it or not.
presumably an attacker will just use the local process to observe and develop a method to defeat it.
that said, perhaps such a methodology would require extra effort on the part of a revenge porn perp, so it might reduce the occurrences.
If they can do that then the whole method fails anyway.
Besides, I think the set of your average revenge porn idiots intersected with those that are capable of defeating the hashing scheme in order to do their dirty deed is going to be exceedingly small.
i'm not that sure. the memory of any application can be observed, which means the process of fingerprinting - whatever it is - can be observed. executing the process enough times with a range of inputs will provide a load of analyzable data, via recording the transformation of bytes.
this is (loosely) why basically all software can be "cracked" and drm methods defeated.
> intersected with those that are capable of defeating the hashing scheme
they don't really have to, much. think of the attackers as software crackers/warez groups, and the perps as visitors to pirate bay. you don't need to know how to break drm to download cracked software, or use nefarious push-button software. there might even be (possibly illicit) business opportunities here.
This all of course besides the best defense against all of this: do not create such images in the first place and do not allow others to create them.
Can't they just train their system to do whatever it is they propose that it do in response to alleged revenge porn, but with any nude image/nude images generally? Will their system prevent the propagation of revenge porn videos?
when will people stop using facebook?
'Please provide a clear photo of yourself holding your government issued ID, and a piece of paper with the following code handwritten on it'.
No, fuck that for a joke.
There's this growing trend of everyone wanting your photo and some ID, and then you have no way to verify that information is being kept securely or used for appropriate reasons.
How I wish large scale surveillance was conspiratorial. Do you really believe in what you say or is it only habit?
Also being a part of the 14 eyes means if the United States wanted my biometrics all they need to do is ask. My country is already moving towards real time cctv identification in airports etc. using biometrics from any issued license / passport.
It does however make Facebook even harder to use for anti-government organizing, though Facebook is already pretty clear about not wanting truly anonymous profiles.
Your country must be very gullible and have poor standards of proof. Facial recognition is nowhere near capable of any such feat. Even in cases where the picture is taken under controlled circumstances, with ideal lighting, in good resolution, without extraneous background details, etc, facial recognition is still utterly terrible at matching people against a database of known images.
Tell your government to prosecute whatever contracting company lied to them and said such a thing could work for fraud and instead look into technologies that work, like those touchless optical fingerprint scanners that can take a persons prints from several feet away. Heck, I wouldn't be surprised if gait recognition had a higher ID rate than facial recognition. Prints and irises are both very good biometrics, facial is less reliable than having a schizophrenic practice phrenology on people one by one.
These cameras were 360 degree and nicely hidden away, you could zoom in and see the pimples on people across the street at decent resolution.
This was 10 years ago, betting against cameras improving since then or in future probably isn't a good idea.
Just an anecdote.
But the movement to identify and share information is not being successfully pushed by governments, but by private industry, largely for personal use. That is where my comment came from.
They wanted me to scan and upload a government issued ID in order to give them money. Nooope, not a chance in hell.
This isn't Coinbase twirling their evil mostache and scheming about selling your personal data.
why the hell instagram would need this, I have no idea.
AML rules can be complex, but it also has trivial rules like if the occupation of a person and the amount of the money he exchanges do not make sense, the transaction will be flagged and reported to the central bank. The transaction will go through, but will be reported to the central bank using a webservice or as a monthly report. Its upto the central bank to investigate it further.
In fact, every bank requires this. If you opened a bank account in-person some years ago you may not remember but they asked you for your government-issued ID card.
It's the same thing.
I also work in a bank, breach of KYC procedures could in the worst case land the caseworker and/or manager in jail for two years and all employees are required to undergo AML training at least once every two years.
Edit: was to be a response to the parent comment as there is no requirement for video here.
KYC processes are a type of situation where it is not a good idea to extrapolate all people's experience from one person's. The underlying mechanisms intentionally vary from person to person.
This is next level bat shit crazy even by FB's own standards.
Maybe it's region based? Or did they remove it?
> A photo of your photo ID card, taken in front of today's physical newspaper clearly showing the date, or over your screen showing your open ticket needs to be added as an attachment to the ticket.
> Please also ensure that the ID is a valid government-issued document and has not expired.
You can see it here: https://blackdesert.zendesk.com/hc/en-us/articles/210745969-...
I decided it wasn't worth it for the cost of my ID being stored with no transparency as to how/where it would end up.
I thought you were being sarcastic, but the page you linked indeed states that.
What is that for, a hostage negotiation? Proof that the time machine works?
How many people buy physical daily newspapers in this day and age?
I moved to Singapore. Their purchases are region locked (and may they burn in hell for that alone). Tried to change my account's country, but that requires submitting your ID and your address, the latter has to be verified by either being shown on the ID or by .. submitting a utility bill or something related.
For a game account. For a change that is irrelevant and only matters because of their shitty business practices in the first place.
In fact, I created a new battle.net account. Located in Singapore. No address or government ID needed, I just curse the people at Blizzard everytime I have to log out of the SG account to play a game that is linked to my original (DE) account.
So they believe me, without verification or anything, when I create an account in Singapore. They consider me a liar and hold my account hostage before I provide details that I'm not willing to share when I tell them that my existing account should follow me.
That is _not_ normal. That's bizarre and stupid. If they'd require this for every account, new or changed, then it would be consistent (but .. I still would think that's not okay and wouldn't create an account with them). Handling these cases differently is just hurting the existing account in good standing.
(for the record: I don't have any utility bill, electricity or otherwise. That policy is not only brain dead, it wouldn't even work for me if I wanted to hand over anything like that. Singapore: My utilities are covered by my rent, I don't get bills for that. I don't get any physical bills anyway and literally the only bill I have would be an online mobile bill. Coming from Germany: I get a utility bill (water, electricity) once a year. This whole idea of proving my address is not only utterly stupid, it also seems to expect things to work in ways they don't outside of Blizzard's home country)
Banks have asked me for a utility bill as a proof of address when I opened an account, but never after that and nobody else ever has.
Specifically, I have never been asked for proof of identity, or proof of address, when purchasing a service, online or otherwise. Even when I purchase flight, train or boat tickets online, where I have to enter my identity and address details, I've never been asked for proof of those, like a scan of my passport or a utility bill.
That is not normal, stating it is normal is not normal and accepting it as normal is not normal either.
So I steal your password and account, sell it off (who buys stolen accounts? What do I know): Why would you need to change the account country?
I literally just wanted to change the account country to .. give Blizzard money. Anyone with access to one of my (now) two Battle.Net accounts can play my games and use anything in-game. What is this address verification actually protecting?
This is why in the EU there are laws about that sort of thing
Does Instagram need to be that sure? Probably not.
Personally, I'd go so far as even if you're opening an email or social media account under your purported real name (so someone else can't set up a Twitter or Instagram account pretending to be you).
To clarify, given how easily people trust social media, identity verification should probably be required unless it is clearly a pseudonym.
This is literally stuff authoritarian regimes are doing to control their populations.
As to whether it is possible to extract such information, per my understanding the internals of ML pipelines are rather opaque, so it would be non-trivial, if not impossible. I have no idea either way.
This is just as much PII as your fingerprints. Fingerprint based devices store metadata not images. I can't look at a fingerprint and connect it to a person, but a machine can. Similarly the output of a NN designed to recognize people will be useful for validation. Otherwise biometrics would not work.
Remember if they are using your photo as training data the NN is going to learn you vs someone else or it's useless. If they can find you in any photo that's as effective as handing a person the uploaded photo and giving the same task.
This article talks about how those data points are extracted using a different method.
https://medium.com/@ageitgey/machine-learning-is-fun-part-4-...
Nothing of value will really be lost, replacements would spring up super quickly and I'd like to think that we would have learned enough about the downsides of the current social-network systems for the next generation to avoid the pitfalls and hopefully make something much better.
That’s the point. Google recently came of comparatively well with a 4 billion EUR fine, but 2 more fines of the same height for Google are expected.
The only way to force a company to follow a law is to make infringing the law more expensive than any profit you could ever dream of making from it.
And European courts consider intent carefully. Mere aggregation of personal data isn’t necessarily a violation, but using it commercially almost certainly is.
There are lots of things that constitute an infraction: the GDPR aims to broadly protect EU citizen rights. Some infractions can be per individual harmed.
Not sure if this is the law though
Being European doesn't automatically subject everyone you interact with to EU laws, especially while you're outside the EU.
The EU can seize hard- and software of Facebook on their EU servers, the EU can seize Facebooks cash holdings in Ireland, the EU can seize (and sell off) Facebook’s patents held in the EU.
Stuff like this has happened before, and european governments have previously even seized airplanes from airlines right after landing to pay customers for a refund for a flight that the airline refused to pay.
This can, and absolutely will happen.
I think in practice it will mean Facebook, say, can't suddenly breach the normal EU regulations just because you went on a trip outside the EU.
https://images.apple.com/ca/fr/business-docs/FaceID_Security...
We only have Apple's word to go by.
https://hackaday.com/2017/08/18/apples-secure-enclave-proces...
Yeah it may be a binary dump, but it's now decrypted and understandable.
https://www.theiphonewiki.com/wiki/Bootchain
https://www.theiphonewiki.com/wiki/Bootrom
https://www.theiphonewiki.com/wiki/25C3_presentation_%22Hack... (^F "The first piece" [of code])
https://www.cse.wustl.edu/~jain/cse571-14/ftp/ios_security/i...
The only part that is fundamentally read-only is the bootrom/SecureROM.
...Which is why https://ramtin-amin.fr/#nvmepcie and https://ramtin-amin.fr/#nvmedma are among my favorite articles ever. (iPhone 6, but still.)
It is a blurred line, but one that most rational companies (=not Uber) would prefer to avoid in the first place by only storing data that is necessary for their main functionality.
e.g if you are building a captcha test feature, it should not keep more data than is needed for it to function.
This is the policy where I work at least, and I believe this is shared by most privacy-conscious companies (which facebook is... as far as the legal definition of privacy is concerned :)).
It's time we all invest a bit of our time to provide real open and benevolent alternatives to facebook, google, amazon, and all the rest, because they're steering internet toward an orwelian nightmare.
I also don’t want state-run web sites to try to provide alternatives to Google ( like europe tried to do 10 years ago), so i think the foundation model is the perfect structure for that. Economically responsible, but not profit driven.
They can see that phones belonging to four people, who regularly chat with each other, were all at the same location at the time the photo was taken.
How would they "see" your phone without the facebook app installed?I've been stingy about that for a long time. FB doesn't have my phone number and I disabled the email address I used to sign up. I delete all my cookies often and use different browsers and turn off and reset my modem to get a new IP address.
I have no apps on my phone, don't use iCloud, and don't use the native "Contacts" app, I made my own for that.
I know I'm still being tracked, but not as much as most and I don't think FB could ID me right now with photos they have.
If anyone who has you in their contact list uses Facebook, I can pretty much guarantee they have your number.
That's a good idea. You could then grant other apps permission to see your contacts, but have the app optionally return fake or empty data.
Facebook would have no way of knowing that it's not you, and they aren't likely to complain that you look like somebody else, since facial recognition will likely always pick up loads of duplicates when used on a global scale.
You'd have to seed the account in advance by uploading some photos and identifying them as yourself, and you'd have to be able to find photos that haven't been uploaded to Facebook previously.
My experience deleting it 5 years ago is summarized as: my friend count went way down, my friend quality went way up.
Your results may vary, but the purpose of my comment is not to immediately be worried that Facebook is a mandatory lifeline for your social life.
It's not like facebook is a nightclub that will refuse re-entry once you leave or anything.
I ended up returning to Facebook and purging my "friend" list down to just a dozen actual friends.
I always wondered what my Facebook acquaintances thought when I left.
I figured they didn’t care Id left to give it much thought or that I was being a prick and had deleted them.
I'd add that the lessened noise contributes to a sense of clarity which in turn contributes to an ability to think critically on the spot.
This is an important distinction. FB has programmed us to believe quantity is the goal, when quality probably should be. How many FB "friends" does the average user have meaningful relationships with? I'd speculate not many more than it's possible to maintain offline/without FB's "help".
"I bet all these idiots cannot tell the difference between real friends and the Facebook friend counter like I can. ;) BTW I've deleted my Facebook because I had a crippling addiction to it."
I too quit around then, and I think I feel that most on my birthday. I only hear from probably a tenth the people but now when they remember on their own and text/call it means a lot more.
For example, my best friends are on the opposite coast. It's not financially realistic for us to hang out in person frequently. The 5 hours a week I could spend sending them letters or calling are not the same as 5 hours I could be spending turning acquaintances who live next door into good friends. Maybe even best friends. It's not theoretically a zero-sum game, of course, but we all know that's not how life actually works and that for one friend to have more of your time/attention means that another loses some time and attention.
What FB has helped me do is to remain easily connected to good friends and acquaintances everywhere. When moving to a new town, finding acquaintances who live there who have common interests with FB is much easier than calling those acquaintances out of the blue and hoping they'll hang out. Most of these acquaintances remain acquaintances, but some become friends -- and the cost of making those friends was substantially lowered.
For remote best friends, FB gives us a way to passively share our lives beyond calling and writing letters. Even if I had unlimited time to spend creating and sending scrapbooks and doing FaceTime, my other friends may not. It's not as good as being together, but I love the option to browse a friend's albums of past recent events on my own time, and then being able to at least experience those memories in a small way.
So I guess I see Facebook has being a very interactive rolodeck. It's not where I conduct my friendships (although I do, to some degree), it just makes maintaining friendships much more efficient. To the point that I keep connections that I would've otherwise dropped, because Facebook has reduced the long-term "maintenance cost". But since it's ultimately a rolodeck to me, I find it easy to ignore and not care what anyone is doing if I don't feel like it, and I have lowered expectations of what I should be getting from FB
Tadaa. Another pointless privacy invasion that only affects the fair and honest.
I missed the part where they said they might use it for account creation as well (which makes less sense and seems like a pretty baroque, intrusive and ineffective captcha).
>"To determine if the account is authentic, Facebook looks at whether the photo is unique."
The two statements are a bit contradictory. They might delete the photo but they won't delete its signature/fingerprint, because they need the later to check for uniqueness of other accounts.
Anywho, once the 'revenge porn' crowd starts hacking around this by chopping the said head from the said images, the central servers of FB are sure to ask for pics of genitals.
No.
Facebook is not the Almighty God.
It's already nontrivial to create fake Facebook accounts. For those serious about it, who already deal with IPs and mobile numbers, I can't imagine that creating novel photorealistic faces would be all that problematic.
If not, then go ahead, by all means.
why not a normal 2fa? it seems like there is a hidden agenda behind collecting and analyzing users facial characteristics.
They probably plan to use your facial profile for a number of things, none of which have to do with authenticating you to the Facebook website. I even see them sharing the profiles with the DHS to build more accurate facial recognition at airports, and other stuff like that. But of course they wouldn't admit it now, because it would mean everyone refusing to use it from day one.
No wonder Facebook's attempt at getting people to give them their credit cards to enable ecommerce on the platform has been such an utter failure. The most popular searches on Google on this issue are whether or not you can trust Facebook with your credit card data.
That's happening for a reason - Facebook has consistently tried to build a reputation of "shady-as-fuck" company throughout the years, and it's going to pay the price for it, either through stuff like people rejecting its ecommerce platforms, which means fewer billion-dollar monetization opportunities for Facebook in the long-term, or simply stopping using it when they get tired of the company's practices.
> They probably plan to use your facial profile for a number of things, none of which have to do with authenticating you to the Facebook website. I even see them sharing the profiles with the DHS to build more accurate facial recognition at airports, and other stuff like that. But of course they wouldn't admit it now, because it would mean everyone refusing to use it from day one.
This validates my little project of uploading a ton of stock photos to my Facebook account and tagging myself in them.
Unfortunately, I think the fact that many people don't realize platforms like Instagram and WhatsApp belong to Facebook will allow them to avoid paying the price.
https://www.facebook.com/help/148104135383285?helpref=search...
In addition, they also have a lot of 'fresh' servers out there, spinning about for months, not being written to, as some algorithm works it's way around using the fresh servers. These also fail, having never been used. Seagate does not mind when companies like FB do this nonsense.
Haven't been able to log in since, as I refuse to partake in that sort of bullshit. Can't say I miss it.
I generally ask everyone who knows me not to upload photos I'm in to facebook at all beyond what's already there.
I wonder if they would ever do something like show you three photos of friends as the captcha, but they only know the answers for two of them and are using the third to get you to give them info they didn't already have without you knowing.
Maybe by now FB actually has knowledge about people in the image but back then my peers just tagged random things as other friends or themselves for fun.
Many countries already have crypto-secure solutions for verifying their identity when submitting things like tax forms. Facebook just needs to start using them, but they won't, and it's obvious why.
Because most countries don't have crypto-secure identity verification, which means Facebook would still need something like this? I suppose they could contract out to Experian (or other local providers) and ask you to answer some questions from your credit report, but I'm not sure that's really a good solution either.
I made a point that there are already ways for Facebook, in certain countries, to verify the identity of their users, if they so please; and that Facebook will never use these because they'd rather control the system of verification themselves (prioritizing profit, not privacy and integrity of users). They could use the systems already in place and say "you know what, the state of Estonia is telling us this guy is who he says he is, we'll accept that". What you're doing is arguing against government-backed digital identification in any broad definition of the term, and you can have that opinion but it's off topic.
I won't create a new one, but I might as well use the one I have to do some good.
You realize Facebook's algorithm is most likely keeping those posts well hidden from your "friends", right?
Yes, but not completely. I do get a handful of likes/comments on them and one friend commented in person about how often I post them. If they're suppressed by the algorithm, they're not getting suppressed too much.
In any case, I don't put a ton of effort into them. They're just articles I've discovered naturally with a pull quote or short summary.
My basic logic/truth table says there's another (possibly more likely scenario): that you give FB more (intimate) data AND botnets still influence your social networks.
I mean, a bot could simply designate using a given stock image for each of their imposter personas, non?
I suspect that what they're not saying is that they will keep some signature/hash/data about the photo, which I'm sure they will use for much more than just verifying uniqueness.
I'd be surprised if they weren't extracting other info from the photo or training ML models on it as others suggest here.
If they're hashing the raw bytes, sure. If they're hashing a representation of the face that encodes meaning (like the relative locations of facial features), then changing one pixel is unlikely to affect that.
The advertisers can always protect that system with some DRM to get the mighty DMCA on their side. That way they don't need to build a robust solution and can still wipe their hands clean if they loose it all to a 12 year old script kiddie.
>> To determine if the account is authentic, Facebook looks at whether the photo is unique.
I assume this means that the photo itself is deleted but a one-way hash of it created to test against later.
However, if I change one pixel of a picture of my face, A, to produce a new picture of my face, A', the hash of A' will not be the same as the hash of A, correct? And I can repeat this process n x m times, where n, m the dimension of the image, ja?
Additionally- when they say "unique", do they mean "known as unique" to Facebook, or "unique in the entire world"? If I take a picture of myself and put it on, dunno, my blog on Blogger, what's stopping someone copying it and uploading it to Facebook to pretend it's me? Will Facebook search the entire web for images potentially matching an uploaded image?
For the record, I don't use Facebook. And there are no pictures of myself anywhere on the internets. As if.
I'm not sure how it identifies a human from a bot though.
There is a wikipedia page for 'perceptual hashing' as well as a number of libraries available which claim to do perceptual hashing, so it may just come down to what kind of crowd you roll with :)
I'm sure it's still possible to steal a picture from someone else's online presence outside of facebook though and upload it as "unique" and facebook won't have any way to know that, unless they scan every other social site (and the rest of the internet, possibly).
And someone could always take a picture of someone else's face, with a bit of social engineering, and use it to get access to their facebok- although I don't think that's the kind of thing facebook want to detect here.
[1] https://www.tineye.com/faq#how
EDIT: Part of the black magic. This doesn't explain how they'd stop someone from using a random picture of you on the net.
I'll give up Facebook before I give up that level of privacy.
So in others words people who travel or go on vacation?
Personally I welcome it, especially when banks do it. It's low-hanging fruit TBH. It massively fucks with those using VPN or Tor but I'm fine with that.
Also this argument falls flat as we are an increasingly mobile population whether that be travel for pleasure or business.
I remember watching in amusement/horror as a friend I was traveling with in Thailand wasn't able to access her Facebook account unless she verified via her phone that she was actually attempting to log into her account from Thailand. It's like you're supposed to check in with Facebook and let them know where you are. So creepy.
Second, for a lot of people, their FB profile has a lot of confidential information, and is tied to their personal identity so they can't have the risk of it being compromised based on leaked passwords or whatever. It may not matter for you, but I am happy that they are safeguarding my account just the way a bank would.
>"Second, for a lot of people, their FB profile has a lot of confidential information, and is tied to their personal identity so they can't have the risk of it being compromised based on leaked passwords or whatever."
Who puts "confidential information" on FB?
FB is based on the premise of voluntarily sharing" information. If people are willing to share information on a social networking site it can't really be considered "confidential" or even "sensitive" to you can it?
Also FB is not one's identity, despite what FB would like you to believe that it is.
That's actually a pretty funny line given the current political situation in the US.
Imagine the surprise we'll have when we'll find out our accounts were cloned.
(I don't know a mark for whatever this is, it's not sarcasm or irony, something about tragic comedy fate…)
Maybe it’s time to open your eyes and see that there is no Santa since 1984?
So I don't get if this "captcha" process is automated or manual (...or both)? Somewhere else in the article it says that users are apparently locked out of their accounts until the pic is verified. Seems odd that there should be a lock-out period if the process is automated (as the first sentence of the above quote implies).
ALSO, for a captcha, isn't this dead easy for bots? Get a DeepDream/Generative Adversarial Network instance to generate faces for you. Bam. This is not a barrier.
1.) The face verification is automatic. It is among other processes that are automatic and some other processes that are manual.
2.) Lock out periods are to prevent repeated attempts.
3.) The face has to match the face of the account, so generating a new face won’t work.
It quite easily could work well if the account has, or is tagged in, any public images and those are used as input to the generation process. (Or if it's associated with a person of whom there are public images in other sources, off of Facebook.)
I'm assuming the process is sophisticated enough that you can't just post an existing public Facebook image of the user without modification, but that may be too generous.
> ...users are locked out of their accounts _while the photo is being verified_. A message said, “You Can’t Log In Right Now. We’ll get in touch with you _after we’ve reviewed your photo_. You’ll now be logged out of Facebook as a security precaution.”
Emphasis mine.
"after we've reviewed your photo" --> FB can autotag people as pictures are uploaded. Surely they can verify face similarity instantly?
it seemed to work at first, but when i tried logging in a month or two later my account was disabled. perhaps i wasn't the only person using that image and they were displeased.
Your likeness is your data.
Abandon ship.
Or abandon Facebook. .
Both nanobots and a genetically engineered super virus, for example, would be very well suited to extinguish humanity in a timeframe that makes resistance / retaliation impossible.
Now if I as a dumb human can come up with that, just imagine what a being incredibly smarter than anything we could imagine could come up with.
I assume this only happens if you’ve uploaded pictures of yourself in the past, so they can compare them.
Seems as silly as uploading your nekid pics so facebook can prevent them from being distributed. If they really wanted to protect you they would just let you download an app that could analyze the files and upload just enough to detect similar video/pictures.
What has facebook done in the past to earn such trust? Seems just the opposite. Isn't it crazy to assume facebook will keep anything you upload secure?
> In a statement to WIRED, a Facebook spokesperson said the photo test is intended to “help us catch suspicious activity at various points of interaction on the site, including creating an account, sending Friend requests, setting up ads payments, and creating or editing ads.”
They're basically training people to provide PII/biometrics on-demand as the price of using their service.
big brother zuckerbergZuck: I don't know why.
Zuck: They "trust me"
Zuck: Dumb fucks.
I am not a user, but I see the value. It’s creepy as hell, yes, but I see the value.