Face-verify.js: Monitoring who is physically looking at a website
blog.machinebox.io
blog.machinebox.io
> Banks don’t want private account details (like the user’s current balance and credit limits etc) being seen by anybody other than the account holder.
This is exactly the kind of justification they'd use. And surprise surprise there won't be a box that says "I'd rather risk somebody seeing my account details than have a biometric model of my face stored in your database and given to whoever you give it to".
Two examples:
Social networking - Enabling more meaningful and greater connection between people, leading to greater happiness and fulfillment? Or, fostering more divisions, balkanization into "like" echo chambers, promulgating fear and prejudice, leading to greater depression and mass manipulation?
Cryptocurrencies - Disintermediation! need I say more ;) All kinds of utopian views of how this is supposed to promote freedom, security and efficiency. But top of the wish-list for the most paranoid and repressive authoritarian tyrant would have to be a magical way to fully control and monitor all economic activity: A cash-less society where every single transaction is done with the government controlled digital currency, recorded on the government controlled blockchain.
I don't believe that this was a serious motivation for any of these companies for a second. That might have been in the press release, but most of these social networks were either born from Geocities-begets-Myspace incrementalism, or "watch these idiots give away their personal data" egocentrism.
An abridged survey of recent history:
Snapchat: it'd sure be easier to sext if these pictures disappeared
Instagram: it's easier to take a pic than write something
Twitter: pivot from failing product to internal tool
Facebook: privacy invasion as a service
Myspace 2.0: maybe we can make money off napster?
Myspace: Geocities clone
Geocities: AOL clone for the World Wide Web
AOL: Prodigy clone
Prodigy: Walled garden for selling Usenet access
Napster: OK, this one was probably the only one motivated to enable more meaningful and greater connections between people, leading to greater happiness and fulfillment
That wasn't the motivation-- it was instead to make identities discoverable online. And-- with Facebook-- to make it easier for college students to get laid.
Both were liberating.
The technology can just as easily be applied for other purposes, mandated by an authoritarian government to be the only legal way to conduct commerce. You'd use it not because you want to, but because you want to avoid their ire.
There's literally no reason to use it at that point, just make a simple db of account numbers and balances.
It would be actually possible to use a government's money in various new ways. Think of what could happen in the economy if the government provided flexible and free payment services.
(Which is exactly why they'll never do it, but just pointing out that a government-controlled blockchain for normal people would have a LOT of applications)
Actually my government already has rules on that. Using my debetcard at a store, withdrawing money from an ATM or transferring money between bankaccounts is free.
Its almost as if we live in 21st century already!
Second, go to your nearest store, bakery or whatever, and ask them just how free debit cards are.
But consider the fact that you are using terms out of the humanities, while most of my fellow CS students endlessly griped about how useless their humanities courses were and how they wished the school would get rid of that course requirement (six courses total over 4 years).
Until we teach the tech-priests of the 21st century the great responsibility due to the power that they hold, I doubt things will improve.
In the UK, for instance, we have no requirements for a university degree other than the courses relevant to that degree. I was there to study computer science, not get a rounded education at someone else's insistence.
And yet most of the really rapacious, conscienceless, anti-human stuff seems to me to come from the libertarian and 'bro' fringes of Silicon Valley, seemingly despite the requirements to study more 'humanities'.
Which depends almost entirely on the university in question. My computer science degree (Cambridge) had two separate courses focusing on ethics/humanities. Year 1 had Professional Practice and Ethics (which starts as broad as "Ethical theory. Basic questions in ethics. Survey of ethical theories: [...]. Advantages and disadvantages of the two main theories: utilitarian and deontological.", not just as it relates to CS), and Year 2 had Economics and Law (broad introduction to micro/macroeconomics, and a general overview of the law as it related to CS). The course introduction for the latter notes that you are to treat it as if reading a humanties subject:
> One word of warning: many part 1b students may never have studied a humanties subject since GCSE. It is a different task from learning a programming language; it is not sufficient to acquire proficiency at a small core of manipulative techniques, and figure out the rest when needed. Breadth matters. You should spend at least half of the study time you allocate to this subject on general reading. There are many introductory texts on economics and on law; your college library is probably a good place to start.
FWIW, I don't recall many complaints about the presence of these courses. Most seemed to find it useful to get a more rounded view, and it was a nice change of pace from tens of hours of pure computer science a week). It was also likely helpful for my later studies in Law.
This is also true in the US. I actually chose to study religion and philosophy in addition to CS. My reasons for doing so aside, I truly benefited from it as it helps guide the type of work I will take. I'm torn on whether it should be required, mainly because I am not in a position to decide what makes a 'better' software engineer.
> Like any technology, we need to consider the ethics of its application carefully so we don’t build tools that are open to abuse, or worst case, terminators that can travel through time to kill people.
So no, they took the opportunity to clear up any fears or concerns about the project and used it to make a really, really scary joke about robots specifically designed to identify individuals by using cameras and kill them with guns.
Nobody at this project gave one real thought about ethics. Ethically, you can't make that joke about your software, it's nauseating.
The terrifying thing is that this type of application "demo" is being built by smart people who are already fully aware of the _theoretical_ concept of ethical violations being enabled by software.
And yet refuse to connect the obvious dots to the dystopian, anti-human capabilities enabled by the tools they're building. "Oh yes well we didn't mean it for THAT".
WAY more respect (fear) if they came out and just honestly explained all the revenue generating capabilities this could extract from users. Better business. Less disingenuous.
I certainly feel MUCH safer knowing that my software could FORCE me to spend my attention on it for whatever reason. Bravo Machine-Box, really helping make the world a better place.
It's an ethics arbitrage. This kind of business looks for unethical technologies that other companies wouldn't dare to create, and then packages it up in a form that is palatable enough to bring to market at a profit.
In my book, the ethical viewpoint would be, “someone else might eventually do that, but it sure as hell won't be me”.
I was curious about this claim, so I did some cursory research.
A Pew survey from 2013 [0]--which is perhaps a bit dated--found that 66% of respondents believed a photo of them existed online--which, notably, says nothing about access to the photo or metadata that relates the photo to an identity. Pew found in 2016 [1] that about 68%, 28%, and 25% of US adults, respectively, have a Facebook, Instagram, and LinkedIn account. These are presumably the main vectors for accessing the face:ID pair. So this gives us some ability to quantify the first part of your claim, "most people".
As for the second part of your claim--that this subgroup's face:ID is available to nearly anyone--I did not find data on who or how many people might have access to this information. The vector here is important, though. Let's consider the public UI, which is realistically the only interface most interested entities have access to. With only a name and no other queryable bits of information, finding the matching face is unlikely because of how many identical names there are. The ability to query other bits like geolocation, work history, the social graph, and, of course, the face itself should greatly increase the chance of finding face:ID, which is minimally an account with profile picture. The profile picture is not per se sufficient to extract a face model but also not per se necessary, as other face photos might be viewable in the profile. At this point I can really only speculate about the intersection of privacy settings and photos, but I think it's far from clear that this information is "available", which I take to mean that the information is accessible with relatively little effort and means. And again, this is just the people who have a social media account and probably a photo tied to their account, not the population at large.
Of course, there are entities which have access to far more data than this, but that is not "nearly anyone".
[0] http://www.pewinternet.org/2013/09/05/anonymity-privacy-and-...
[1] http://www.pewinternet.org/2016/11/11/social-media-update-20...
What about any birthday parties or group pictures you might be in? Photos for a work event or with friends?
Unless you've been very careful not to appear in any public photos of any kind, especially ones taken by your family and friends (as it is easily traced to you), then I would expect you have just as much of an online photo-profile identity as anyone else.
> I’ve searched for a picture of me, and have only ever found a grainy one from two decades ago. That is it.
But that's not what I mean.
Facebook knows who you are. Maybe you can't find it yourself using search terms, but that's not the point. You have a Facebook profile with an email and a set of pictures and a social web connected, I'm sure, even if you've never signed up. There's just a db flag set that says 'waiting for this person to sign up'.
Facebook knows.
Phone cameras are high res. If you live in a city or go out in public often in busy places, then the sheer number of people taking selfies and photos is immense and makes it likely that over time, each of us is caught repeatedly in these photos.
With Facebook et. al's newfound face recognition and social scale, people who have never heard of a computer or phone or Facebook can now be automatically identified and tracked throughout the real world just by your face in other people's social photos.
I realize this dystopia might not accurate portray your life, but it is also meant as a comment for others. Privacy is not an individual choice any more. Our social networks have forced a change in expected privacy and there's little that we can do right now to change that, as the profit motives for the corporations like Facebook are aligned this way.
Note: Yes, being in public has an element of privacy. It is reasonable to expect that if you buy some groceries at a store in Atlanta, and the next week walk to Central Park in NYC, that a company in San Francisco who you have no relationship with would not know about it. But that expectation is now gone, and already it seems wild that we could have ever had it. That is a kind of privacy that is lost forever.
https://www.upress.umn.edu/book-division/books/digital-stock...
"Now, the modern person is determined by data exhaust—an invisible anthropocentric ether of ones and zeros that is a product of our digitally monitored age."
I won't doubt that in 15-20 years, using the process of deduction of your phone/laptop/browsing habits/credit card usage/address info a company could, if bothered, collate that data to get "your picture". And I mean literally zoom in a security cam to snap the photo.
Goes a bit like:
1) a place to start, 2) a way to follow, virtually, in time and space - augmented with total surveillance.
1) "In China, KFC tests out ‘smile to pay’" https://www.techinasia.com/kfc-china-tests-facial-recognitio...
2) "China’s facial-recognition systems crunch data from cameras to monitor citizens"
https://news.ycombinator.com/item?id=14643433
Also:
https://www.theverge.com/2013/2/1/3940898/darpa-gigapixel-dr...
https://motherboard.vice.com/en_us/article/nzey3w/what-those...
Apple could burn me horribly though.
There's really nothing else you can do apart from wearing a mask and sunglasses, which will also be bypassed soon enough. (Not to mention that no one wants to do that.)
Unlike weapons, a lot of these ai tools have some force of good behind them as well - so good governments won't pass laws against this either.
It's here, and I can't think of anything you can do about it (especially in public).
Yes, but they will have to fight a giant up-hill battle because ads exploit a quirk of human psychology, which is that most people strongly undervalue their own attention.
My co-founder and I have talked about things like this as an "anti-cheating" measure (we developed a take-home assessment platform), but it always feels way too overboard and invasive for an exaggerated problem (and I'm just against it in pretty much every way imaginable).
Interestingly this somehow feels better than overt measures like ProctorU, but that's an emotional reaction and not a logical one. In some ways it's probably much worse.
https://www.chronicle.com/article/Behind-the-Webcams-Watchfu...
> Rather than one proctor sitting at the head of a physical classroom and roaming the aisles every once in a while, remote proctors peer into a student's home, seize control of her computer, and stare at her face for the duration of a test, reading her body language for signs of impropriety.
That article is from 2013, I wonder how much of this is now partially automated (i.e. relying on human remote proctors)?
Source: As a remote student, I have used ProctorU several times. Most recently within the last few months. I use a dedicated PC for this proctoring.
Edit: Clarified text and fixed some typos
I would assume you wouldn't only use this tech to secure information. But I don't see really how this adds any security when software cams exist.
Plus you have other issues, like people like me who work in low light, or picture frames in the shot, etc.
Cool hobby project though.
And even if you could trust the entire website-to-webcam path end-to-end, you can't trust the image the hardware is reading. There's a reason that other face recognition systems like Windows Hello require that you have an IR camera, so that it knows it's not just looking at a photograph of a person.
Stop trying to find solutions to problems that aren't real.
And, if so, couldn’t they use a camera, or mirror, or periscope to bypass this software?
Unless it's an in-person interaction, a face has little security value, because it's not a secret. Getting a photo, or even full motion video of someone often just requires finding their Instagram page.
My concern is what if some one show my digital photo to the website, will framework detect it ?
Apple said that they over come this by using true depth technology (which i guess required specific hardware).
I like the idea thought, but there is a big reason people did not implemented this before.
"Eye roll detected. Would you like to send feedback to this ad partner?"
However, from a credit card processor point of view and combating "friendly fraud". This could be an excellent tool to prevent that.
For example. The scenario where a transaction has been processed and 6 weeks later, it is disputed because the card holder doesn't recognise the transaction. Perhaps the wife used the husbands card whilst he was in the shower, for [insert candy crush clone].
A capture of the users face would definitely help the merchant win the representment against Visa/Mastercard.
In a scenario where goods are being shipped cross-border. Lets say from China to the US and it's for a large amount. Then this could be an extra step, where the data hasn't passed a certain threshold and thus further information is required. Having a real-time snapshot and validation to prove the card holder is legitimate. Ensures the transaction goes through.
Ultimately, I do understand it's about weighing privacy concerns. But that doesn't mean some good can't come out from this.
Of course this would incur a slight fee on the final sum, and buyer protections would be void, but you would still be free to opt out :-)
However, my comment was purely from a credit card processor, acquirer or even bank.
At the end of the day, if something like this was introduced. You are free to not comply, pay with an alternative method or shop elsewhere.
You are increasingly not free to choose an alternative, given the increasing centralization of the "too big to fail" finance and tech industries.
They do exactly the amount of security that they think is most profitable - balancing losses to fraud vs abandoned sales because of inconvenience.
Jumping straight to face recognition is a bit like physical security adding strip searches when they haven't yet bothered visually scanning for weapons.