Face-recognition technology is the new norm
nytimes.com
nytimes.com
Is there a way to get those records expunged?
(IMO the innocent—and maybe those who've served their sentence—ought to be able to do this.)
Really?
"Yes sir, we have entirely expunged your data and you have the US government's solemn promise that we didn't make a copy of the files we're not telling you about."
Effectively, there is no such thing as expunging digital data. There's always probably some extra copy somewhere.
There's no silver bullet, just a long battle of attrition.
And as the leaks have fallen off the news cycle, along with an interesting rise of misinformation in social media, you gradually see people beginning to understate what was revealed and to show ever less concern over it. It's actually a phenomenal demonstration for how a secret agency should handle a leak to avoid any meaningful consequences of what is ostensibly ground-breaking information on programs that are, at best, in legally grey areas, all being released to the public en masse. Snowden no doubt felt that his leaks would change our approach to intelligence if not our entire nation. In reality, next to nothing changed.
[1] - https://theintercept.com/2016/08/14/nsa-gcsb-prism-surveilla...
If the government is not allowed to gather certain biometric data then that is relatively easy for the public to monitor. If the government collects and then promises it is going to delete the data there is a real chance that it won't get done.
Its not an assumption, its a fact that has been proven time after time in every case for the last 15 years.
>Laws give you a way to win a lawsuit, at the very least you have that.
That's just not true. Not only can the government spy on you with impunity, the court has ruled that the government can kill you, without any due process whatsoever, and you are entirely powerless to challenge or even discover if you are on their "kill list" as long as they invoke the "state secret privilege".
https://www.techdirt.com/articles/20190924/20182043065/dc-co...
The unfortunate fact is that our legal system has failed. Instead of enforcing the law and upholding The Constitution - its most core and precious mandates - our legal system has consistently deferred to government claims about the need for absolutely secrecy and legal impunity to do whatever they deem necessary.
In my own stuff, I'd feel obliged to make a disclaimer: "Yes, I've deleted your stuff, and the backups of the data (which I still have), will rotate out of existence in nnn days." I would also need to keep the deletion request handy for nnn days, just in case I needed to restore data (& so that I could re-delete their data).
I think there was an option not to consent and still make it through security, but the instructions seemed to be purposefully unclear. If they make it unclear, they know that 99.9% of people will not bother to ask questions. They know how stressful airport security is in the first place and how people just want to shut up and make it through the line and not miss their flight, and they use that as an advantage. I consider myself to be more informed and concerned about digital privacy issues than a vast majority of people, just like most of you who will be reading this comment.
Even so, in the moment I gave in and let the stupid thing scan my face. And now my face is somewhere in a server at the Pentagon probably. The social engineering around it made it very hard to figure out whether or not there was any real risk of resisting it or asking questions. I was with my wife and we didn't want to miss our flight.
I applaud the person who in the same situation would have turned around and walked out of the airport and skipped their expensive, non-refundable trip to Europe. But when my big moment came to be a heroic activist for digital privacy rights, I wasn't the same person I am when complaining about Facebook and Google on the internet. Oh well, I guess travel is how we learn about ourselves, right?
And that's exactly why facial recognition is going to become completely ubiquitous without much fuss at all. The risks are too abstract for most people to really care in the moment, even if they know the issue fairly well. Real social movements don't gain momentum until people's lives are directly impacted - and the issues are just too nuanced, and the whole infrastructure of surveillance too byzantine, for people to really want to take action.
These days I don't even know if it's still possible to opt out. I haven't seen a sign saying you can in ages.
I think we're going to see a massive increase in extortion as people are able to collect large amounts of data on people based on facial recognition. Sure now it's expensive and slow. But it's going to get cheaper and quicker.
I'd recommend trying to avoid anything that can link your face to your identity being public and online. Sextortion is a big thing at the moment. Who knows what will be next when facial recognition becomes available to the same scammers.
The constant pressure to look good, feel good, make sure information doesnt get out will become a massive mental crisis.
We can already see the edges of this with Facebook envy and other similar mental health issues on the rise.
typo?
The Chinese political system is like this, everyone's corrupt but it's ok because everyone's doing it. Until one day when the bigger guy doesn't like you and starts pursuing corruption charges against you. Then it's a matter of who has more connections (with the chief of police, or the judiciary). Which seems like jungle law but with lawyers...
Lease camera space on buildings. Capture and process everything you see from your global network of cameras.
Sell reports to anyone with money.
e.g. $1000 for any records of this face in the area in the last week.
Clearly this ends up in a situation where everyone can monitior everyone.
I'm equally worried about those two, as well as tech like this in the hands of big businesses.
Not that I don't believe you, but I can't think of any examples off of the top of my head. Can you give me one?
Another is those automated speeding cameras. In several states they are unable to write tickets without a police officer present. My understanding is that this means the machine operates the same way and still writes tickets, the officer just has to be there as a "witness" and play phone games or whatever while the machine works. The end effect is the same, but the law requires an officer to be a witness to the crime in order to generate tickets.
So who know what other methods are used for parallel construction.
No, that's not the Supreme Court. That's the Firearms Owner Protection Act of 1986.[1]
[1] https://en.wikipedia.org/wiki/Firearm_Owners_Protection_Act
Another exemple is the rationale for EU privacy laws. It was fine to have your history in newspapers or judicial archives, as searching for them was prohibitive. But having it searchable through computers makes it trivial for would-be employers, neighbours, etc. to find out about you, transforming any small misdemeanour in a lifetime sentence.
When those tools become more powerful, so does the harm caused by their misuse.
A gun is just a stronger slingshot, but you'd be an idiot to give one to an eight year old child who was slingshotting windows, dogs, and cats.
The fallacy of using Quality statements in order to negate Quantity.
An earthquake of level 10.0 is just like an earthquake of level 4.0, only longer and bigger.
A flooding is just like normal raining, only with more rain.
In most situations a big change in quantity makes all the difference, like in this case.
If police forces analyze 20000 people a year,mostly criminals in criminal scenes, it is completely different than analyzing millions, mostly normal people.
If you want a more in-depth analysis of how classification systems performed on people can have wild consequences, and that it cannot be fixed by just tweaking the algorithms or methodologies, Excavating AI is a great article on it (https://www.excavating.ai/)
Imagine a system where facial recognition technology supplements, but does not replace, manual recognition. Isn’t it better to guide mugshot lookups with the best available technology rather than wasting hundreds of hours on manual searching? Without treating automatic results as final and authoritative, can’t they still be used to drastically hasten manual look-ups?
The issue at hand is about those who should be presumed to be innocent. The many who are in a crowd, the majority that are probably not at all related to whatever search is happening.
I've read science fiction where the opposite extreme happens. Where there's an AI that implicitly interfaces with everyone at all times, but it isn't a surveillance nor advertising state. If anyone does actually do a crime there's an actual sentient witness, no need to track down video, and that witness is also able to get help on the way right away. Further there's no backlog of unprocessed data, no file of all of the various normal day to day things that really aren't important.
I could go for a future with benevolent partner AI(s) and no actual surveillance state even though there are cameras and microphones everywhere. I can also see some public spaces (schools, courtrooms, other places people are required to mingle) having observation and storage for a limited (days/weeks) time for manual review in the case of reported incidents.
However the power as it currently stands is much more likely to be used for leveraged persecution and partial enforcement against specific people, and classes of people (IE not rich), rather than for all the people.
I don't see how this is any more or less true of facial recognition than other evidence-gathering technology.
>The issue at hand is about those who should be presumed to be innocent. The many who are in a crowd, the majority that are probably not at all related to whatever search is happening.
Maybe so, but the laws which are getting passed and proposed as a result of all this journalism are much more broad:
https://www.sfchronicle.com/bayarea/article/Oakland-bans-use...
https://www.theverge.com/2019/8/19/20812032/bernie-sanders-f...
On the other hand for some people addicted to lip implants the system will need a perpetual and constant fine-tuning and upgrading (that will divert resources just to adjust the eyelid position and nose shape). I don't see plastic cirugy being forbidden in a near future if we take in mind the number of rich clients that use it.
The tech community needs to start calling bullshit on these kinds of stories.
Once data is collected, it's collected. It, for all intents and purposes, exists forever. So it's impossible for the group taking the data to promise what the data might or might not be used for. And that's assuming that the group is the only one who ever owns the data. In a world of ultra-high speed internet, that's almost preposterous. It's not if, it's when the data gets out. Once it gets out, it's everywhere.
While I understand that traditional property fits into a format like this, data does not. Trying to pretend that it does? In my opinion it's doing a great disservice to the readers.
Who says these are rights? I agree free speech is a right, but who (legally) grants me the right to privacy and anonymity in public? Does me recognizing someone in public violate their right to anonymity?
This stuff has already been decided. Remember the "Streisand" effect?
If you step out in public, anyone can record you or take your photo. Including a government agency. What is going to be interesting is what public entities (agencies) are restricted from doing with said data. I don't see laws being passed restricting everyone from doing facial ID matches (namely private citizens or companies). Nor would I want them.
I think it is a hard thing for people to conceptualize that you do not have a bubble of privacy everywhere you go. In certain places (home) you do. Not much elsewhere.
Current precedent is out of date. Free society depends on the people's ability to bend and break unjust laws. It cannot survive the ossification of mass surveillance.
Specifically in the US, amendment IV to the constitution says:
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated"
Key phrase: "Unreasonable searches".
A government worker watching me walk from my car to the grocery store, come out and load groceries into the car, let out an expletive and walk back into the grocery store to buy the bread that was forgotten, and then head back to my car isn't something I'm protected against. Not sure the value in it, but there's nothing preventing them from doing so.
Similarly, if someone made a public post on Facebook or some other social media site threatening someone at the city council, facial recognition picks them up at some government building and they linked the facial recognition to name which linked back to their social media and that post showed up, I don't think they'd be in the wrong for then searching them. Constitutionally. Does it feel weird? Sure, but everything there is public and at that point it creates the basis for a reasonable search so searching them for weapons and/or charging them with communicating a threat seems fair now.
Now if we're talking about someone pre-emptively scouring a person's cloud storage and finding something worth investigating, that'd violate it in my book.
2. Each person back then would know their data is being collected, and exactly which kinds, because they are present and engaged when it happens.
3. We can sort of, kind of trust humans and sort of, kind of predict their decisions because we're not that different. We are nowhere near that stage yet with computers. We also know that putting that sort of information into people's hands, with the economy we have today, incentivizes misuse.
Uh, yeah, whatever. I mean, it's not like I disagree or anything.
But it's not like surveillance is only just now becoming a problem, right? Go and roll back the surveillance state revealed by Snowden that would have been a wet dream of the USSR. Roll that back to before Bush II and put a moratorium on that shit.
America's PRESENT. IS. A Chinese-style surveillance state. China is a perpetual preview of what will follow in the so-called "free" world in 3-5 years.
Maybe in cities, but my rural town just barely got stop light cameras, so I highly doubt this is true of rural America.
Plus, use of the surveillance is more reactive than proactive. In China it is proactive. Drive around in a car with a taiwanese flag bumper sticker and the secret police will disappear you in the night. In America no one will bother looking at the footage unless a bank robbery happened and your car was the getaway car.
Ideally the legislative process would step in and curb back the excessively restrictive laws and surveillance, but it don't seem to have much incentive to do so. Plus, legislators are subject to the same onerous regulations which everyone breaks all of the time because "no one is looking".
Do you think rural towns in China are any different?
>> In America no one will bother looking at the footage unless a bank robbery happened and your car was the getaway car.
That might have been true ten years ago, but certainly not today.
https://qz.com/1458475/the-dea-and-ice-are-hiding-surveillan...
Doesn't matter, they still track your location using your mobile and make a copy of all of your phone calls, text messages, emails, corporate-managed voice calls (Skype etc.) and so on. Small town or not.
> Data, both content and metadata, that already have been collected under the PRISM program, may be searched for both US and non-US person identifiers.
There were many such programs that collected the data itself, as revealed by Snowden. PRISM is just the first that came to my mind.
As far as "Chinese style" surveillance, I always note that it's always western or western-friendly information sources giving us the information on it. It's always filtered according to someone's interests, so when I subtract that from the issue I'm left with an estimation that it's probably not appreciably different than what we have in the US.
The government has already managed to get numerous key parts dismissed under state secrets privilege. [3] The government was also directed to preserve key data related to what remained of the case. In 2018 they informed the court they'd accidentally deleted it. Oops. [4] Oh yeah, in the same statement they also acknowledged they lied under oath when previously stating that they had preserved all relevant data on magnetic tapes and stored them with counsel. Oops again! Penalties.. consequences? You can guess.
And yes, you can also sue the government in China. Just don't expect to win.
[1] - https://publicintelligence.net/binney-nsa-declaration/
[2] - https://en.wikipedia.org/wiki/Jewel_v._NSA
[3] - https://www.eff.org/deeplinks/2015/02/jewel-v-nsa-making-sen...
[4] - https://www.lawfareblog.com/summary-jewel-v-nsa-and-accident...
And China isn't going to downplay the speculation. Frankly, they want everyone to think they have the best, most thorough surveillance apparatus in the world. Even if it isn't stronger than what is done here, the perception is to their benefit.
---
The evidence is not too hard to find. This [1] site provides an extensive and ordered collection of most published Snowden related documents. It's also quite nice since it ties the documents to the first press coverage as well, if you'd rather peruse something other than the raw data. There seems to be a curiously large amount of misinformation on this topic, but when you actually look at the evidence - this situation is not in the least bit ambiguous.
These [2] slides give a broad overview of what PRISM is:
- Slide 3 describes PRISM: "PRISM -Collection directly from the servers of these U.S. Service Providers: Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube, Apple".
- Slide 5 describes what is collected: "What will you receive in collection (surveillance and stored comms)?" - "in general" : "email, chat - video + voice, videos, photos, stored data, VoIP, file transfers, video conferencing, notifications of target activity - logins, etc, online social networking details, SPECIAL REQUESTS (caps added here to represent the bolding in the slide)".
This [3] is a document entitled "User's guide for Skype PRISM Collection". It gives some insight into how the program operates from an operative level including screenshots. It details surveillance of skype conversations, including conversations between skype and a landline connection. In skype-skype connections surveillance is available for audio, video, chat, and file transfers. It also mentions another program "DECODEORDAIN" which apparently maps different email addresses to a single person (used when engaging on surveillance on a target with skype registered under multiple email accounts).
That document also details that as data goes from Skype's servers, it also goes directly to the NSA. So this leads to situations where their agents can apparently become a bit confused about receiving multiple copies of the same chat log. That might happen, for instance, when a user logs onto a different device and his chat history is resyced so it goes from Skype to him as well as to the NSA. That's all made even more interesting by the fact that this was back from 2011 when Skype was still peer to peer. So while we get hints of how their process worked, the exact mechanisms are still a bit obscured.
There's a lot more really interesting stuff as well, but you could spend years going through all of it. Anyhow, suffice to say - no the government isn't just collecting just metadata. Anybody that says that is spreading misinformation either intentionally, or because they themselves have been misinformed and now think they're informing others.
----
[1] - https://snowdenarchive.cjfe.org/greenstone/cgi-bin/library.c...
[2-article] - https://www.washingtonpost.com/investigations/us-intelligenc...
[2-slides] - https://snowdenarchive.cjfe.org/greenstone/collect/snowden1/...
[3-article] - https://www.spiegel.de/international/germany/inside-the-nsa-...
[3-document] - https://snowdenarchive.cjfe.org/greenstone/collect/snowden1/...