Well, it better be a publicity stunt! You can't change those stupid behaviors of facial recognition without such bad publicity. I hope they make as much publicity as possible, and maybe some money (but he won't get 1bn, that's not the point).
Well, it better be a publicity stunt! You can't change those stupid behaviors of facial recognition without such bad publicity. I hope they make as much publicity as possible, and maybe some money (but he won't get 1bn, that's not the point).
I didn't need to allow oath that to read that. I have my browser configured like so https://github.com/gorhill/uMatrix/wiki/How-to-block-1st-par...
For that page all I had was: https://i.imgur.com/DQe8TIr.png you can clearly see oath was not enabled.
It would appear you do need to allow 1st-party JavaScript to allow the <script type="application/ld+json"> portion to load which contains the "articleBody": ....."
I am connected through my VPN, currently in NL, so yeah, GDPR.
If they don't offer an opt-out that is as easy as opt-in, I'm going to assume malign intent on the part of the site, and they can do without my traffic.
www.engadget.com -- script https://consent.cmp.oath.com/cmp.js 3p
www.engadget.com -- script https://consent.cmp.oath.com/cmpStub.min.js 3p
> Sure, I know there are ways I could work around it. But I shouldn't have to.Sadly that's the world we live in.
> It's supposed to be easy for a visitor to refuse consent for all that unnecessary tracking - which has no justification in terms of legitimate interest for the purpose of publishing a news article. It shouldn't require technical countermeasures (that 99% of users will not understand).
It shouldn't yet, it does .
> If they don't offer an opt-out that is as easy as opt-in, I'm going to assume malign intent on the part of the site, and they can do without my traffic.
With media that's a pretty safe assumption.
They searched for the wrong face into facial recognition software ... which did it's job perfectly.
This is akin to the police arresting someone because their name matched a name a criminal left behind. Happens all the time, and I'm sure that more than a few wrongful convictions happen this way. This is 99% the fault of the police.
Perhaps there's an argument that facial ID lowers the bar slightly for this to happen, but that's about it. When push comes to shove, neither Apple, nor the police did their work properly before resorting to heavy handed tactics ...
What's the "stupid behavior"? Some Apple stores have been robbed. Apple got video footage of the robbery and setup a system to look out for the suspect and alerted authorities when the suspect entered the store. It's no different than an FBI wanted poster. The knee jerk reaction of anti facial recognition has gone overboard.
Also, it's also not entirely clear but the article suggests that the person had used a stolen ID of the arrested teenager, which makes the arrest all the more reasonable:
> Apparently, the real perpetrator used a stolen ID that had his name, address and other personal information
Finally it's worth noting that Apple didn't arrest the person, the police did. Apple likely just notified them and then the proper due process happened
No, he wasn't in the store. He was at a party in another state. And perhaps he'd never been in an Apple store.
And yes, the thief reportedly used a stolen or counterfeit ID. But it wasn't a photo ID.
I get that some comments can be interesting without reading the article. But someone discussing and finding fault with an article they haven't read (properly?) ... that's the bit that just baffles me.
Reading the article seems like a reasonable minimal entry requirement, IF someone wants to discuss the content itself.
Instead of giving snarky comments you could at least acknowledge that the article is utter garbage.
The only link between the thief and the person who was arrested is the NAME.
Edit: and here is better article:
https://googleness.com/unitedstates/student-sues-apple-for-1...
Apple identified (using facial recognition) the same person who stole multiple items across different states and since the thief used a fake name - they associated all crimes with that name.
So in the end the only link was NAME due to the stolen id.
Following further thefts associated with that ID, the innocent man was accused of all the thefts based on the ID and an INCORRECT photo match to the stolen ID which Apple had created in its facial recognition system, and used as the basis to inform the police of the suspect.
I tried my best not to be snarky. I thought the article was a normal average article.
Edit: I'm not sure the article says facial recognition was responsible, I think that's what the courts will decide. But to me, its clear that facial recognition was involved, based on the article's title and content
If Apple sent a security camera picture of the robber together with information from the stolen ID to police, and police the same would have happened. So the core issue here is that the validity of the ID was never questioned, not the use of facial recognition. That might just have amplified / accelerated the identification of the wrong person.
If, it was just a single theft and the stolen ID was used on that occasion, then I would agree facial recognition would not be relevant.
He was arrested because his name and details were presented at the crimes by the perpetrator. I've read the article and this is what I've taken away from it.
I really can't understand how facial recognition played a critical role in his arrest over his name being used.
I make that assumption, because the person accussed of multiple crimes is suing Apple based on their use of facial recognition. He wouldn't do that if the ID was used in each crime.
Another article confirms my assumption is correct.
https://www.bbc.com/news/technology-48022890
"A detective with the New York Police Department allegedly told Mr Bah that the thief probably used Mr Bah's driving licence as identification during one of the robberies. The detective reportedly said that this may have caused Mr Bah to be charged with thefts committed at Apple Stores in New York, Delaware, New Jersey and Massachusetts, according to court papers."
Unfortunately "Stolen ID Blamed for False Arrest" doesn't make for a good story.
That would be consistent with “Apple said on Tuesday it doesn’t use facial recognition in its stores”.
On the other hand, “Security Industry Specialists Inc., a security firm that’s also named as a defendant, declined to comment on the suit” could mean that Apple hires a third party for its store security, and that firm could use facial recognition.
Thanks for answering that question.
https://www.insurancejournal.com/news/national/2019/04/23/52...
That was my point, though. He’s abusing the legal system by asking for compensation he knows he will not receive to gain publicity. The issue involved is fine but I’m not a fan of exploiting and clogging up the legal system in this way. If this is “what it takes” I think we have a bigger problem we need to solve.
The real problem is that the government considers arrest without conviction to be a civil duty, not a tort.
I'm arguing that they misused data that they had. And so they actually didn't have enough evidence to file a police report.
But it's also arguable that the police screwed up, by not noticing that the photo from the video didn't match the suspect. So maybe the kid should also sue the police for false arrest.
Maybe I'm just naive, but I doubt that people typically get arrested based on such iffy identity theft. It wasn't a photo ID. And such ID is typically useless for legally meaningful authentication. It won't get you alcohol when you're underage. It won't get you a bank account. Or a drivers license, or even a replacement social security card.
Putative damages need to scale with the size of the defendant or they're meaningless.
The only way to stop a corporation from doing something undesirable is to make the punishment great enough that the undesirable act is a net financial loss to the corporation.
I would personally fully support massive % of yearly revenue fines for anything to do with privacy.
See: petrochemical pollution, bank money laundering, telcos selling customer data, etc.
Legal or not, the discussion is whether a 1B punishment is appropriate. Yes, I think it is appropriate for an organisation with a reported quarterly revenue in the 90B range, maybe even on the low end.
It seems to me that we already have the proper way of dealing with this situation. Have the company pay punitive/exemplary damages.
A negligible settlement won't act as a deterrent for an entity with deep pockets.
We can't tell what the arrest was worth to the teenager. Depending on timing and results on his life, that could be anything between mild inconvenience and 1bn.
Agree.
> it should cost Apple enough to hurt them
Don’t. I think it should cost them proportional to the amount of “suffering”: this is a lawsuit after all, not a criminal trial.
> We can't tell what the arrest was worth to the teenager. Depending on timing and results on his life, that could be anything between mild inconvenience and 1bn.
Agree as well, but I hope you can forgive me for leaning towards “mild inconvenience” rather than “one billion dollars”.
and Punitive damages - which are paid to the court to discourage the behaviour of the defendant.
Both parts need to be considered.
Why?
All Apple did was provide the police with the information they had, in good faith: that is, the information on the ID the thief had.
It's not Apple's fault the ID was stolen and the information was false. It's also not Apple's fault that the police didn't do basic due diligence to determine if it was physically possible for this guy to have committed the crimes before arresting him.
What, exactly, is Apple to blame for here that "this should be a valid case and it should cost Apple enough to hurt them"?
If you are an individual, and someone steals your iPhone, then you use the locator feature to pinpoint the exact address where it is, look up the name of the person living there, have a plausible story for why that person had opportunity to steal it, dig up the serial number from your records, and hand all that info over to the police, they will give you a report that you can give to your insurance company, caution you against approaching the thief yourself, and do literally nothing else. You did all the investigative work. All they'd have to do is show up with a search warrant. Aaaand nothing happens.
If you are Apple, and someone steals your iPhone, then you use facial recognition tech to link the thief to the name and address of a stolen identity, then the cops will raid that address and arrest the person, without even bothering to investigate, or even validate Apple's info, first. Perhaps they call a VIP number rather than 911 or the public number for the main automated phone tree, that bypasses all the layers of "we're busy with important work, so piss off"?
This is the same problem as SWATting attacks. Police procedure is hackable, by saying the right words to the right people, to turn it into a guided weapon against a target, who is occasionally killed by a cop made too twitchy by the "everyone wants to kill you" training.
Apple provided false information to the police. This resulted in an arrest, which is potentially traumatic and violent. They could have given just the video footage of the thefts. But instead, they became part of a system that hacks police procedure to launch attacks against innocents. Someone was arrested on the basis of the output of a facial recognition program, without any consideration to the fact that it had been hacked, using the very simple and very easy attack of linking the face to someone else's name.
Consider it from the perspective of not having the information that the ID was false. Why would you give the police less than all the information you had? Why would you want the police to have to do all the work to figure out who that face on the video is, when you have their ID?
Furthermore, even if you knew the ID was false (or even suspect), giving the ID information to the police, along with your assessment of its validity, would still be better. They would have an extra data point to use to try and trace the real thief.
And, again, the facial recognition program did not perform the identification of the thief. It merely linked his presence in multiple stores at the times of theft. The identification information came solely from the stolen ID the thief gave when he purchased something legitimately in one of the stores.
Giving the footage, without the name, forces the cops to positively identify the suspect through investigation of crime scene evidence. The FaceID-generated name is just speculation from Apple.
Operating under the assumption that the cops will do the absolute minimum amount of work to clear the case, just giving the video runs the risk that they will decide that identifying the suspect is too difficult, and give up. But bear in mind that they failed to identify the real suspect anyway, and also arrested an innocent person, just because Apple said that's the person who did it.
The professional cops, who are usually not as knowledgeable about computing science as the professional software developers, may be unaware of the GIGO principle--garbage in, garbage out. They don't know how Apple assigned a name to the face, but they trust them, because Apple spends a lot of marketing dollars getting people to believe that all their stuff "just works".
The facial recognition software linked the face with a name attached to all the faces that didn't. Apple can certainly give a rate of false positives and false negatives for the face-matching, but I'm not sure they have any idea how many people are showing them fake IDs. That's something cops and bouncers would know, not ordinary retail employees.
If you were a cop, and someone dropped this case on your desk, what would you do? I, personally, would search for that name on every corner of the Internet before getting off of my ass. I'd be looking for any excuse I could find to not go out to arrest someone, because that's work, and solving property crimes, especially shoplifting cases, is not noteworthy or glamorous. But Apple is rich, so I'd put just a tiny extra effort in to find the real thief, in case I ever wanted to run for sheriff, and get them as a corporate campaign donor.
I'd probably go to one of the department's fake Facebook accounts, upload a cropped still from one of the videos, and see if their auto-tagging software produces a match. If that didn't come up with anything, I'd have to get a search warrant for the named suspect and their home address, looking for any stolen Apple stuff. Then I'd see that the named suspect does not match the video footage. I'd give the best face-shot and a short video clip to the local TV news to see if that generated any tips or leads, and then finally write a report saying that the suspect could not be identified or located from the available evidence. But I'd be polite about it, because Apple is rich, and would certainly want to read the report. And then that would be it. Because every retailer has to live with a nonzero amount of shoplifting and other forms of shrinkage, even the rich ones.
No, it's not. As I've said multiple times, the name came from the stolen ID the thief had. The only use of facial recognition in this case was to link his presence at the time he gave the ID, to his presence at the other stores where thefts took place.
Facial recognition played no role in actually identifying the thief (either the actual one or the poor sap whose ID was stolen).
1. Facial recognition played a role.
2. Facial recognition played no role.
One of the two must be false. It is the second. Facial recognition played a role. Specifically, it linked the face seen in video where a crime was observed to a face that misidentified itself.
The speculation on Apple's part was that the name the face presented for itself was genuine, and not a deception. It did not stop to assess the probability of all customers presenting fake ID, or the conditional probability of a customer presenting genuine ID given that they are a suspected serial shoplifter.
That last one is relevant. A person that can do a grab-and-run theft might also be willing to do a fraudulent purchase theft by giving a stolen, cloned, or credit-fraud card and stolen or faked ID. So while you might be able to assume that regular customers usually give genuine ID, giving fake ID and stealing from retail stores are probably not independent events. Once you have reason to believe a person is stealing, based on the facial recognition matches, you can't trust that they are who they said they were with the same confidence.
And what would Apple have done if the same person had given a different stolen or faked ID, on a different occasion, and that name was also linked to the case by facial recognition?
My first paragraph does not contradict itself. Facial recognition software was not used to identify the thief. That was purely done through the use of the ID. Facial recognition software was then used to link the already-identified thief in a single instance to other instances of theft at other stores. Even if the facial recognition software had never been used, the guy the ID was stolen from would still have been fingered as the thief in that first instance.
This is not a story about Big Bad Apple, or Big Bad Technology Gone Wrong. This is just a story about Humans Making Mistakes. Specifically, it's a story about the police not doing their due diligence.
If he sued for some trivial sum, they'd probably just pay him to go away.
And yes, publicity is the point. This is how you get new precedents established.
Well, yes - we do. Using publicity (via mass media and/or the legal system) is, at this point, one of the few recourses citizens (at least in the US) have against tech giants when they engage in morally-questionable behavior. In the idealized capitalist world, we could move to competitors, but the current situation is that a number of markets are extremely monopolistic (search engines, online markets, platform app stores) or duopolistic (mobile devices, computers, news aggregation) - and consumer apathy, combined with toothless or entirely missing regulation, trivialize the impact of anything except for the most visible of reactions. If there were stronger legal repercussions in cases like this, it would make publicity stunts unnecessary.
Asking for an unrealistically huge sum is par for the course. The judge can arbitrarily reduce that sum down, all the way to zero.
> The issue involved is fine but I’m not a fan of exploiting and clogging up the legal system in this way.
The legal system isn't being exploited or clogged up, he was going to seek damages (as one should) in either way, whether the number sought is a billion dollars or a thousand dollars doesn't make a difference.
Hey, a billion dollars got your attention. Perhaps, in fact, after investigating it: we will find that in fact Apple has done more than a billion dollars worth of damage to society. If they can screw up like this once - perhaps there is more? 100 more cases, perhaps?
We will see, once enough publicity from this "abusing of the legal system" runs its course ... considering that, indeed, there may in fact be bigger problems to solve.