Facebook photo-scanning lawsuit could cost it billions
eastbaytimes.com
eastbaytimes.com
I upload photos to Google Photos because I want them to be grouped and categorized so I can easily find them. That is, if I click on a picture of my daughter, or my wife, I want to see ALL pictures of I took of them grouped together.
Looking at the text of the law itself, it seems to exclude photographs, here's the relevant section:
" (740 ILCS 14/10) Sec. 10. Definitions. In this Act: "Biometric identifier" means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry. Biometric identifiers do not include writing samples, written signatures, photographs, human biological samples used for valid scientific testing or screening, demographic data, tattoo descriptions, or physical descriptions such as height, weight, hair color, or eye color."
I'm not really sure what they mean by "face geometry" whereas at the same time, excluding photographs. Does this mean if my service measures the distance between the eyes, and the width of the mouth, and clusters photos by that, or by eye or hair color by using say, segmentation or histogram clustering, all of a sudden it's illegal? That would seem to be a fairly absurd and broad definition of biometric security information.
In theory, I suppose, the computation of the features, could be done on the client, and then have the features cloud-synced and replicated to all clients, but this would make for a shitty search experience, especially if the machine learning or feature extraction technique improvements overtime, and all of a sudden, you've got to download 20,000 photos and recompute everything on your phone.
A hung trial is closer in meaning to not being found guilty or innocent.
Arguably, a semantic difference does apply in that you may still be found liable in a civil case. However, civil cases don't declare people guilty only liable.
Incidentally, this is largely why Scots law verdicts of acquittal -- "not guilty" and "not proven" -- reflecting the two standards of not guilty. "Not proven" carries the implication that the jury is not convinced of the defendant's innocent, but there is not enough evidence for conviction.
It makes me kind of sad, not for the lack of privacy, but for the feeling of getting older and just not caring about fighting the technology to make it do what I want.
If the only thing you care about is backup, Dropbox and other services offer that (e.g. Keepsafe). I use Google Photos because of peace of mind. I know I never have to worry about losing photos, and when I need to find them, it's easy. I've got like 20 years of photos backup. Just yesterday, I wanted to show someone a picture of my daughter from a trip we took in 2012, and I found it in about 5 seconds. When I take photos of my kids, they are automatically shared with my wife, instead of having to constantly manually be asked for them, and manually select them. I focus on just taking pictures and spending time with my kids, I never worry about photo backup, or photo organizing anymore.
Would you still use it if the grouping feature didn't save pictures it could not confidently group?
Pretty useless if it throws away singleton sets.
You need something like CryptoDL: deep learning over homomorphic encryption, that would let the photos stay encrypted in the cloud, but still allow DL computations to be run.
It does work, but it's not nearly as seamless as Google's cloud implementation. I have many tens of thousands of photos in my Apple Photos library and I think it takes over a month to process everything if I start from scratch on a new computer. Somehow it seems much faster on the phone, and I'm not sure if that's because the processing is better hidden from me, it's much more efficient on the custom chip, or maybe a bit of both.
The later, a bit of both. It’s also probable that your phone is turned on and plugged in more often than your computer (especially for laptops).
It doesn't matter how clever you are: if you disallow processing the photos on the server, then any index you have on the client that is cached will be invalidated by an algorithm update, and there is no way to rebuild the index without downloading all the photos once again.
I'm not talking about federated learning, that's a different problem. Let's say we solved that problem using on-device learning and differential privacy. The problem still remains that retrained/updated models on devices require the photos to be processed locally again.
So if for example, you can now detect "hugs" in photos, and I search for "photos of my me hugging my daughter", Google Photos gives me what I want, and your local-only model means I have to wait a long time to redownload and reindex my entire collection. It's a huge user problem.
A workable solution to this problem has to somehow entail homomorphic encryption, if you somehow want to keep the photos encrypted on the server.
But it certainly works on large libraries because it shows me recent photos mixed with cats that died years ago.
Absolutely not. Companies should not be able to do this without explicit opt in. They need to learn that they are not free to do whatever they want, whenever they want, users be damned.
Analyzing peoples' biometric data from pictures of their faces is a special case.
> I upload photos to Google Photos because I want them to be grouped and categorized so I can easily find them.
So make it opt in. Most people just want to show their images to friends, not have Facebook analyze them.
What's your definition of biometric data? if I cluster by eye-color, is that biometric data? "Show me everyone with green eyes". Have a run afoul?
Fundamental to what, though? This court case is not about somehow criminalizing the existence or the use of this particular tech.
> I upload photos to Google Photos because I want them to be grouped and categorized so I can easily find them. That is, if I click on a picture of my daughter, or my wife, I want to see ALL pictures of I took of them grouped together.
Facebook is not Google Photos. The former is a social network, the latter is a service for storing, organizing and sharing photos. In my opinion, even Google Photos should implement a setting that disables this.
> Does this mean if my service measures the distance between the eyes, and the width of the mouth, and clusters photos by that, or by eye or hair color by using say, segmentation or histogram clustering, all of a sudden it's illegal? That would seem to be a fairly absurd and broad definition of biometric security information.
Come on, if you made the effort to read that part of the law, why did you stop there? No, it's not "suddenly illegal" to measure and gather that information. It's illegal to do without following certain rules about retention, destruction and usage of that information. It's in the very next section, here's an excerpt:
"(740 ILCS 14/15) Sec. 15. Retention; collection; disclosure; destruction.
(a) A private entity in possession of biometric identifiers or biometric information must develop a written policy, made available to the public, establishing a retention schedule and guidelines for permanently destroying biometric identifiers and biometric information when the initial purpose for collecting or obtaining such identifiers or information has been satisfied or within 3 years of the individual's last interaction with the private entity, whichever occurs first. Absent a valid warrant or subpoena issued by a court of competent jurisdiction, a private entity in possession of biometric identifiers or biometric information must comply with its established retention schedule and destruction guidelines."
If facial recognition becomes legally recognized as a "biometric marker" (no reason it shouldn't) - I think we'll see all sorts of other suits come out of this.
1 - https://blog.varonis.com/us-state-data-breach-definitions/
As an aside: Google's Arts and Culture app (that matches your face to historic artwork) doesn't show up in Illinois - the feature within the app for face matching is geolocated out.
http://abc7chicago.com/technology/why-googles-face-match-fea...
The case hinges on a particularly strict Illinois biometric privacy law.
http://abc7chicago.com/technology/why-googles-face-match-fea...
The analogy for this regarding physical altercations would be assault vs. battery.
Getting punched in the face is "theoretical harm" until the fist connects with the nose. The connection of fist and face is battery. The swinging of the arm is assault (even if the fist doesn't connect).
However, I think the point is moot as the tagging itself is an invasion of privacy. You may not see a problem but it's not difficult to imagine some. What if someone posts and tags me in a picture with revealing information and my stalker sees it and hunts me down? If I'm someone that has had a stalker, a boss that has no boundaries, or an unaccepting family, knowing this feature exists would cause anxiety.
I remember thinking the tagging feature was incredibly creepy when it came out, but it seems to have become normalized in society.
https://www.plainsite.org/dockets/2mwpixhn9/california-north...
One of the tactics that they used was going over his head to the Ninth Circuit to request a stay at the district level (https://www.plainsite.org/dockets/download.html?id=253527059...), which the Ninth Circuit then granted (https://www.plainsite.org/dockets/download.html?id=253580963...). So then the district court judge had to effectively grant the stay anyhow, which he had just denied:
"ORDER. In light of the circuit court's order, all remaining pre-trial and trial dates are vacated. Signed by Judge James Donato on 5/29/2018. (This is a text-only entry generated by the court. There is no document associated with this entry.) (jdlc3S, COURT STAFF) (Filed on 5/29/2018)"
This is what having infinite cash buys you in the American legal system.
>Asked to sum up the tech community’s feelings about Mr. Edelson, Sam Altman, president of Y Combinator, a technology incubator that invests in very young companies, said the lawyer was regarded as “a leech tarted up as a freedom fighter.”
He's the American Max Schrems.
[1] https://www.nytimes.com/2015/04/05/technology/unpopular-in-s...
Where do you draw the line? If the site processes the EXIF metadata are they in violation? If they use a neutral clustering algorithm to group visually similar images, are they in violation (be it humans, cars, or chairs)? if I take a visually clustered group of images and tagthem "a_imho", have I now made the site have biometric data related to you?
I mean, a lot of people say "well, as long as you're in the spirit of the GDPR, don't worry", but lawyers don't care whether you're in the spirit of something, they only care if they can win a case, and when the law is vague, "spirit" seems like one judge could hang you, and another judge could free you depending on the luck of the draw.
This is were you draw the line. Taking pictures of people without their consent (and a good reason) is a big no-no in most parts of the world.
This is either because it's not considered appropriate or because it's condemnable [1] or both. It is also nothing new and not some effect of GDPR, but deeply rooted in culture. Germany, Austria, Switzerland, Italy long had strong laws regarding the right of persons to their own likeness. There is also a big rift, not only legally but primarily culturally, between Anglo-Saxon culture and mostly the rest of the world.
GDPR and other laws concerning informational self-determination[2] never can be interpreted without context. They are always limited by other rights and freedoms, like the right of artistic freedom. So a lot depends on your intent and if you can justify what you do.
I'm not saying this is all well and good. As kind of a street photographer wannabe I'm very sympathetic to the position that the UK and the USA take on this. I'm just saying that the rest of the world has very different ideas about this and this has consequences if you operate globally.
[1] https://commons.wikimedia.org/wiki/Commons:Country_specific_...
[2] https://en.wikipedia.org/wiki/Informational_self-determinati...
I'd personally say taking pictures of people without their consent is a big no-no in some parts of the world, but not all.
I have never personally had any issues with my street photography in the UK, it boils down to being respectful and not behaving in a harassing manor. If there is a reasonable expectation of privacy then one should consider taking an unsolicited photo as an invasion of privacy.
I added the reference to the list as support for my thesis that it can have legal consequences, a fact that in my experience people from the USA or the UK are often oblivious about. Just because it is not forbidden doesn't mean it is acceptable though. I think it is no coincidence that we see strictest regulation in central Europe because these countries are around the border line between the different attitudes. Go farther east and there is no need to regulate the culturally obvious.
> I have never personally had any issues with my street photography in the UK,
Of course not, UK is one of the best countries for shooting street.
> it boils down to being respectful and not behaving in a harassing manor. If there is a reasonable expectation of privacy then one should consider taking an unsolicited photo as an invasion of privacy.
Absolutely.
"Identifying" a purpose could range from simply clustering visually similar photos using any number of non-machine-learning, non-biometrically-aware image processing algorithms, to using DNNs like FaceNet, or using the old eigenvector facial recognition algorithms of the 90s.
As soon as I upload a photo I took of you to a photo hosting system that has any kind of search functionality at all, the risk is raised that you can be categorized and identified somehow. Really, "consent" was broken not by the company, but by the uploader.
I really think the genie's out of the bottle on photos now. So many people are constantly photographing on their phones, and so many are uploading them to publicly accessible feeds all over the internet, that a federated crawler could already be built to track you, in fact, I think there's already some social media monitoring services that offer this.
If you're out in public, you should pretty much assume you have no privacy with regards to your imagery, GDPR isn't gonna save you. You can control your own photos, but you can't control what other people do of photos taken of you.
I suppose you can object and campaign for the EU to setup its own Great Firewall or something along those lines and only allow companies to operate within its borders which adhere to stringent rules around posted imagery. Good luck with that.
Europe isn't China, and the distribution of those photos isn't an existential threat to the government, so a Great Firewall is overkill.
Facebook has assets, operations, and revenue that originates in Europe that could be easily targeted with little controversy to gain compliance. If that doesn't work, Europle could always try to make the executive decision-makers personally liable. I'm sure Zuckerberg wants to be able to visit Europe in the future without being arrested.
That said, I don't take it as a given that will always be the case. I can imagine future US companies offering services that run sufficiently afoul of current or future regulations in the EU and other jurisdictions that it makes sense to just not offer them there.
I guess the "relax, bro, as long as you're thinking good thoughts you have nothing to worry about" crowd have all recently awoken from 60-year comas.
There's zero precedent to suggest that they won't get away with it. All Facebook has to do is go undercover with their data collection and hope that it's never revealed that they're still doing it, or when it does leak, they pay some fine equivalent to half a percent of 3 minutes' profits.
How yould facebook go undercover with their data collection ? every thing they do is provide an infrastructure for data collection.
Give it a couple years and there'll likely be a leak revealing that nothing has significantly affected the main meat of the mega corps' data gathering, someone will say "mistakes were made but we're looking into it", a year later some investigators will say that they can't really do anything because it's technically outside the scope of the law, and it'll vanish until another leak happens the next year.
The EU. Remember, Facebook is an Irish company, headquartered in Dublin.
Nothing will change :(
I don't think we're quite to the dystopian vision of international megacorps being totally above the law, yet. No matter how much cash Facebook has to fight lawsuits, the government has more and actually makes the laws to boot. Facebook is also clearly a non-essential service, if it was run out of business, most people who don't have the last name of Zuckerberg would adapt and get over it in a couple of months.
Could someone please elaborate on this? I feel like I've seen clauses like this all over the place. Are they really unenforceable? What is the judge's reasoning?
ORDER re Summary Judgment Motions ([257], [299], [307]). Signed by Judge James Donato on 5/14/2018. (jdlc3S, COURT STAFF) (Filed on 5/14/2018)
Unfortunately, I don't really have access to PACER or money to gamble on opening random documents to see which one has the actual info. The US "public access to court electronic records" isn't very "public"-friendly.
(docket listing kindly provided by user thinkcomp - https://www.plainsite.org/dockets/2mwpixhn9/california-north...)
Choice of law ... law is not always straight forward.
You shouldn't rely on it as any sort of guarantee that you'll get to be haled into court only on your home turf.
This country's legal system is like a swiss cheese with holes everywhere. Dealing with states, federal governments and municipalities costs our businesses billions of dollars each year.
Facebook also has Chicago offices. http://www.chicagotribune.com/business/ori/ct-facebook-expan...
The current law is that they need to have some sort of physical nexus in a state such as an office or a distribution center. Which Amazon probably has in most states at this point and, in any case, they've agreed to collect sales tax in most if not all states. That said, the relevant Supreme Court decision (Quill) [ADDED: that doesn't require collection absent a physical nexus] is being revisited because of another case this term and the betting money seems to be on it being partially or completely overturned.
It wouldn't be a retroactive solution, either.
It is due to the Interstate Commerce Clause that the government might pass a law, not that it entitles them to sole jurisdiction over a company breaking a state law. Put simply, if there's a law against killing puppies in Georgia, but there's no law against killing puppies at the federal level, that doesn't mean that Facebook can kill puppies in Georgia and get away with it.
If there is also a federal law against killing puppies, and Facebook kills puppies in Georgia, then either Georgia or the federal government can file charges, and jurisdiction would be settled then.
In this case, because it was an Illinois law, only people who have used Facebook in Illinois may be plaintiffs.
I wonder if the golden age of startups is over. It would be impossible to navigate through these regulations if you just wanted to create a side project for fun.
It's probably a rounding error, and a pretty reasonable trade-off to make.
"Move fast and break things" should be applied to your technology, not the laws where you operate!