The guy who made a tool to track women in porn videos is sorry
technologyreview.com
technologyreview.com
However, ethics aside, the cat is out of the bag. People can shame the guy into deleting the data, but computing power will only get cheaper and data matchers faster. Sooner or later some will do this again and launch a Tor site with an up-to-date database. We have to adjust to the idea that if you have a social media profile any public images of you will lead people to it sooner or later. And it will be sooner, not later, with every passing year.
Permit should not be hard to get, as long as you can justify professional or research need.
But letting this go is creating a society I don't want to live it. I already hate, living my anonymous life, when some stranger take my photo without asking. It happens more and more.
On the other end, people filming the police get in more and more trouble.
We got things reversed.
It’s a ridiculous proposition to restrict software access, akin to making it illegal to write on paper.
Similarly, it's legal to write or download a neural network that is programmed for facial recognition. Same for a basic crawler bot.
Probably Telcos and especially also CDNs should do the same. I don't talk about any packet inspection. But sometimes it's obvious what people are up to.
Basically everybody in society can do something against this by not looking away. Also more diversity in tech would have prevented a lot of malicious uses I think.
Forward intelligence teams already record the faces of people taking part in peaceful and legal protests. You can bet your ass they cross-ref the feed with their Linkedin and Facebook data dumps. The same tech is now becoming available to everyone.
The USA can prevent its people from putting an M2 on their truck. Mexico can't (in some states). Syria can't (almost anywhere). The internet is closer to Mexico than the US.
Most people are law abiding citizens most of the time, so laws are not pointless.
And laws typically give us a way to come after those who violate the law.
Sure, laws won't fix a problem once and for all, but if they can reduce the problem by 90% they are a big win.
This approach will just entrench FAANG even more and squeeze out SMBs even more.
For a long time now I've assumed that everything I post online will eventually be cross-referenced back to me, if somebody cared enough.
2ch (4chan ancestor) users identified girls from porn and harassed them, outing them to their families and friends using this service.
Later company discontinued this service and now sells technology to the Russian government to monitor CCTV footage from Moscow subway.
VK kind of fixed data scraping issue (not sure if they actually changed much).
Usually Russia copies everything from the west, interesting to see western news follow Russian lead after a few years. Not saying I am proud of mother Russia in this case, just an observation.
This is an extreme case and I hope most engineers would look at this and understand how awful & damaging it could be; but given our influence on the world nowadays (as a class, if not always as individuals) we really need to be much more aware of what we're doing and how it affects people.
Some of the greatest atrocities we will see in tech (and we will see them) in the coming century will be the result of combining things created with good intentions.
Not much we can do I’m afraid except endure.
That said, a lot of engineers actually are in the position to make demands. The chances of getting fired for saying "I'm not going to do that because it's wrong" are probably very low. Most managers would rather not feel bad, and hiring someone new is usually touted as being a pain in the ass.
There may be some very good reasons that I haven’t thought of not to support this ethics idea. But putting food on the table shouldn’t be it because this one reason applies to any activity that could ever put food on the table, no matter how illegal, immoral, etc.
Is creating face recognition software unethical? Your answer is not really important, just the fact that different people will classify this differently. I thought it was creepy as f* when facebook started wanting to automatically tag people in photos. But if that's all the tech was for it may well be ethical, if creepy to some. And yet, face recognition is really all that was used in this case - matching up porn images with social media ones.
But I was thinking more at FAANG for example. They could be required to hire “certified ethical” engineers at least on sensitive projects at first. This means that even if the code is out there no coder would implement it in the company’s solution without risking losing the “certification” and the job. Anyone working for the Hacking Team (those guys selling exploits to oppressive governments) should be more or less unhireable especially if all code in a company’s portfolio should be traceable to a specific engineer.
The principle is already in place for other fields. Journalism being the closest probably. It could be made more effective if needed. It’s obvious that something is needed in this direction.
If a mechanical engineer creates some evil weapon, say a gun that shoots frozen mercury slugs (just to make up a ridiculous example), we don’t really have to worry about the proliferation of cryogenic weapons. When a software engineer pushes some questionable program’s source to github it’s game over.
Another scenario: a neo-Nazi protest rally occurs, and counter-protesters use this tool to determine who the Nazis are, in order to publicly shame them. Is this OK? Again, the Nazis have not consented to the use of their images to shame or "out" them.
You could go on and on... a vigilant neighbor filming a "porch pirate" stealing packages... someone filming people leaving a gay bar, an abortion clinic, a "massage parlor". Someone constantly running red lights. Who decides what is shaming vs what is "protecting people"?
Although most people who did some porn are most likely not proffesionals, most porn (by volume) is done by people who might even consider your finding part of their CV. So going by sheer numbers alone, there might be so much more cases of false positives. Now, even if it becomes terribly obvious how inaccurate it is, I don't think that matters much when it comes to weaponising it, because people are easily fooled or don't care. As long as you kind find a vid of a girl that looks just like Clara from accounting, you can spread it as a false rumor. Or not even claim it's her; it's just as embarrassing. And that's even assuming you could tell them appart, because the seed of doubt extends the problem to people who didn't even do porn.
For comparison think of deepfakes. Everybody knows it's not actually Emma Watson, but I bet she isn't particularly happy about it.
That said, why would someone, once someone was identified, just go about harassing them and telling all their friends they do porn? Like who does that?
Unfortunately, it's also enabled a selection of less socially aware and/or socially responsible people to bypass the natural limits and filters that society had in place, to effectively cause suffering on a fairly broad scale.
Harrassing somebody on the other side of the world from the safe anonymity of your bedroom was once logistically very difficult, as was reaching significant numbers of people with a wildly malicious idea if you couldn't first find people in your immediate (physical) social circle and community to vouch for you/it.
Now, we have entire online communities which have embraced this new normal and provided these folk with the tools and an audience.
Is failing to tell someone something the same thing as deception?
Is this supposed right symmetric? Does bride-to-be have the right to know if the husband participated in porn video?
Yes, absolutely. Imagine you are the only person that doesn't know your fiance was in porn and you committed to her without knowing that.
> Is this supposed right symmetric? Does bride-to-be have the right to know if the husband participated in porn video?
Of course. Even though social stigma for males is lower, it has a devastating impact on their business relationships.
If a person is afraid that their fiance might have done porn in the past, or if they care so damn much, they should just ask the person.
If you truly are just naive, please think about the points I mentioned; if not, there is no point to discuss, as your mind is set in stone anyway.
but note: the "you" in that sentence isn't you. I'm not saying you are a fool. Then why did you say I was? "let's be generous and assume the question is just naive"
Again, you've never established a right. And there is also this horrible assumption or belief that once doing porn forever marks or stains you. Well, certainly some people believe that. But I do not, and I challenge it.
There are good logical and moral reasons, IMO, why the doctrine is unsound. For example: individual photos are qualitatively different to movies, even though movies are made up of individual photos; the fixed interval conveys speed, which individual photos are quite poor at. Similarly, pervasive photography is different to individual photography: instead of an incident at a single location, someone's whole day may be mapped out, and who they're talking to, etc.
In other words, reasoning about privacy is not transitive or scale invariant. You can't say that the end result is ok or moral based on its component parts. Composition changes the thing qualitatively.
One thought perhaps is that the porn movies, even if it’s public information with consent, often do not identify the actors. The problem may be in connecting “anonymous” public information from one source with personally identifying public information from another source. But, this seems doubly problematic since all the information may be public with consent and since someone’s face might reasonably be considered identifying information. Does GDPR make it illegal to connect any personal data even when from public sources that all have consent?
If you give an authorization, it has to be for a specific purpose and not generalized. So just because you gave an authorization to appear in a movie doesn’t mean you gave an authorization for other purposes, such as face matching. Same thing for social media.
There are also copyright issues. If France, you always own copyright (droit d'auteur), you may transfer the exploitation rights but the work is still yours. It means you still retain some level of control, in particular regarding decency.
France is just one European country but that's to show that there are limits to what you can do, even with publicly available data.
And unless everything happens in France, it would be a huge mess and I don't think anything can be done. GDPR is an attempt to harmonize the rules of different countries and make them enforceable internationally.
I don't know how it is done in other European countries but rules regarding personal data and authorship tend to be stronger than in the US, and freedom of speech is more controlled (ex: hate speech, libel, ...).
"just collecting the data is illegal if the women didn’t consent, according to Börge Seeger, a data protection expert and partner at German law firm Neuwerk. These laws apply to any information from EU residents, so they would have held even if the programmer weren’t living in the EU."
#1 the programmer is implicated (it's possible this is in the context of "the programmer" also being "user in Europe") #2 even if they weren't living in the EU
#2 is the particularly interesting one and also opens up the general question of "what happens if <external group> collects data but does not handle monetary transactions in Europe or deal with money abroad". GPDR is very much written around how to wrangle companies in financially, what if it's not a company?
When you leave your home, your privacy is gone.
When you make anything public your privacy is gone. Not sure anything is ethically wrong with the software existence, the problem seems to be data usage, just as if somebody found out his neighbors wife is in porn and went to twitter and said it publicly with few pictures as a proof, and people do that.
It's naive to think that this thing can/will go away, if anything, because of this news alone who knows how many more random programmers are retrying this (or even make business plans) at this very moment.
GDPR states that the lawful basis for processing of data depends, among other things, on:
* the individual's explicit consent to the processing of his or her personal data.
* protecting the vital interests of a data subject or another individual
This violates both criteria, thus is indirect violation of the GDPR.
* What the heck is vital interest ? For person playing in a movie it may as well be that everybody watch it.
* Screwing up someone's life, as it is extensively desribed in the article, fits well into the definition of "vital interest".
I find it quite baffling how someone posting on HN is oblivious to the link between GDPR and the need to punish those who abuse data collected from social networks against the wishes and best interests of the users to screw up their lives.
The question is if photograph is personal data according to GDPR. Here is what I found [1]:
Under GDPR Article 9, biometric data is among the special categories of personal data that is prohibited from being processed at all unless certain exceptional circumstances apply, and the definition of biometric data specifically refers to "facial images".
Any images collected, whether via photos or videos, will only constitute biometric data if “specific technical means” are used to uniquely identify or authenticate an individual.
GDPR makes an important distinction between facial-recognition data and photographs. Recital 51 of the GDPR states the distinction as follows:
The processing of photographs should not systematically be considered to be processing of special categories of personal data as they are covered by the definition of biometric data only when processed through a specific technical means allowing the unique identification or authentication of a natural person.
[1]: https://iapp.org/news/a/how-should-we-regulate-facial-recogn...
>If I simply sit in the cafe watching someone continuously near me, I am collecting data, and nobody can do anything about it.
But the tool is doing more than that as it's also using data gathered from crawling social media profiles and then matching people, you cannot do this without specific consent under the GDPR.
>When you leave your home, your privacy is gone.
>When you make anything public your privacy is gone.
GDPR provides controls on privacy, it does not say you are guaranteed privacy in every situation but that if somebody misuses your data in a way that violates your privacy you have rights to correct this misuse, e.g., the right to opt out and the right to erasure of data among others.
The GDPR also generally applies to everybody (within the EU or serving EU customers) except 'a natural person in the course of a purely personal or household activity', it's important to note that non-profits still have to comply with the GDPR. Generally there's a lot of legal ways to process data as a legitimate business, the law is mostly concerned with giving individuals a means to opt out or to give them some rights with regards to their data, like the 'right to be forgotten' or the right to access the data a company may have on them.
Algorythm doesn't have to collect any data on you besides your image which is not considered private data given that you need to carry one. It can have single image and compare it to the porn collection without storing any results anywhere, but just returning 'XXX was a porn star in YYY'.
Tool can also create opt out mechanism which would have to be pretty complex as providing ZZZ in the name blacklist isn't appropriate solution given that many people share this name.
> But the tool is doing more than that as it's also using data gathered from crawling social media profiles and then matching people, you cannot do this without specific consent under
Implementation detail. This can be totally avoided. Tool can accept picture and return the result.
The GDPR doesn't care about 'private' data (for the most part) as it only cares about personal data, and faces absolutely are considered personal data under article 4 point 14. Faces are even in a special category of data which you are prohibited from processing at all unless some conditions are met, although article 9 point 2e allows processing such data if they have been 'manifestly made public'. The GDPR doesn't define what 'manifestly made public' means but the Scottish Parliament[0] suggests that it could mean images purposely uploaded to social media and made public, but note that just because you are not prohibited from processing such images does not mean you have a lawful basis for processing that data in the first place.
>It can have single image and compare it to the porn collection without storing any results anywhere, but just returning 'XXX was a porn star in YYY'.
>Implementation detail. This can be totally avoided. Tool can accept picture and return the result.
This is an implementation detail that I had not considered. The original tool and article talks about crawling both porn sites as well as social media and both are fraught with legal issues, not every video or image on porn sites is going to be legal in the first place (revenge porn, stolen images) never mind the copyright issues involved, and crawling social media for this information is simply not acceptable under the GDPR.
>Tool can also create opt out mechanism
Such a tool would almost certainly need to be opt in from the data subject, article 6 makes this clear, you need specific consent from the data subject or some other conditionals which aren't applicable here. Best case scenario if you want to operate such a tool in Europe is that you argue (in court, mind) that you have a legitimate interest to run such a tool which does not override the fundamental rights and freedoms of the data subject, which does not seem like it would go in your favour at all.
[0] Page 6: https://www.parliament.scot/S5ChamberOffice/2018_06_01_Motio...
Consider however the variant I proposed (picture 2 result). Would that be penalty according to GDPR and if photo is already public and not used for personal identification ?
Perhaps it could be said that the any algorithm that makes person identifiable is problematic. However, random photo of you doesn't identify you AFAIK and porn star names are also made up, so you are connecting 2 non-identifying things and the end result most also be non-id ?
>However, random photo of you doesn't identify you AFAIK and porn star names are also made up, so you are connecting 2 non-identifying things and the end result most also be non-id ?
I'd say this would still be against the GDPR. The porn image (assuming a professional production and not revenge porn/stolen images) and an image from social media would both be public images of course, but under the GDPR you still need a lawful basis for processing data as defined by article 6 [0], one such basis for this is that the data subject concerned (i.e., the person in the photo being uploaded) gives specific consent for this purpose. The only way I can see such a site being legal is if you're providing a service to allow people to upload their own images to see if porn of them is being uploaded without consent, however you would need to ensure that the person in the image is the one consenting to that use as you would be liable if other people were uploading those images. It may also be legal to run such a tool for purely personal reasons as the GDPR does not apply to personal activities [1], but it would be illegal to make this available to other people and you would still have other legal issues with such a tool (like copyright).
This is not true in Europe.
They should have a right for privacy.
Imagine you were a stripper or porn actress, your right to privacy wouldn't preclude someone recognizing you at the strip club or video.
Or suppose you went to the strip club or watched a video and then also happened to be on Facebook and saw the profile of someone you saw stripping at a strip club or in the video, matching the face and name in your head.
How is the slow case different fundamentally from the case where programming is used and throughput and speed is much higher and faster?
I mean would it be illegal for someone to just start going through Facebook profiles by hand trying to find an actress they just saw?
So, understand what your fetish means and how it can backfire. Any age will have its own problems like that.
Your ex posts the photos/videos of you on Pornhub, or 4chan, or anywhere.
Someone uses facial recognition to match the photos to your social media profiles. And then you get doxxed, outed, and the photos are shared with all your friends and family.
A) Are you a "pornography actor" in this scenario, or someone who trusted the wrong person? Is everyone who has ever had nude photos or videos taken of them a "pornography actor"? B) Just because something is technically possible, does that mean it should be legal? Do the ethics or the thing ever come into play? C) Do you believe that that laws/regulations are only effective if they prevent someone from doing something, and not effective if they only punish after-the-fact? Are deterrent laws useless?