European Union Calls for Five Year Strict Ban on Facial Recognition Technology
techgrabyte.com
techgrabyte.com
We ban sites that ridiculously overplay stories like this. Please submit from more reliable sources.
I don’t understand why I shouldn’t be able to make an adult decision about taking risks with my own personal data.
Allowing a free-for-all in all new tech that has clearly defined privacy issues at scale can cause a lot of runaway problems. A society who tries their best to reduce harm caused by bad actors using wild new technology that has huge privacy implications is a reasonable society to me.
Automated detection of your face matters to the rest of society, too. It's not just your privacy that is affected, it is other people's too.
Computers aren't like humans. They have the ability to permanently and irreversibly forget certain information, and they always do exactly what they're programmed to. A local, on-device facial recognition programmed to immediately discard information on unrecognized faces has exactly zero privacy impact. (See also: smart speakers listening for a hotword.)
(See also: smart speakers listening for a hotword.)
Another problem is that the risk of abuse is too great, even if the accuracy was flawless.
If the accuracy were flawless then there would be zero false positives, and the aforementioned issue wouldn't exist at all.
Oh, and it is hardly the only issue.
This just isn't true, though. Hotword detection fails frequently for me with Siri, Google Home, and Alexa. I haven't tried the others. They all pick up unrelated sounds and record them as if the hotword was spoken when it definitely was not. Not even a similar sounding set of words.
There are absolutely privacy implications for technology that does automated scanning and recognition of its environment. They are buggy, as all programs are, and they are hackable, as all programs are.
Being both potentially buggy, potentially hackable, and constantly alert and running algorithms on their environment is absolutely a valid and real privacy concern.
Consent should not be assumed and should be revokable if ever given. Yes means yes -- everything else means no.
May be London wants to take a different approach than Finland. That should be fine. Let each countries figure out what works for them.
-It had been a peaceful night in Europe where all the women are strong, the men are good looking, and the children are above average. Martin woke up on his EU regulated bed and looked through his EU regulated window. This night, Martin had slept like a baby thanks to the 109 EU regulations concerning pillows, the 5 EU regulations concerning pillow cases, and the 50 EU laws regulating duvets and sheets. Martin went to brush his teeth with his toothbrush regulated by 31 EU laws.
After that, our EU-regulated man went to his EU regulated kitchen to grab a Class 1 EU regulated apple. For the benefit of society, the EU had defined what a “class 1” fruit actually is: to class a "Red Variety" apple as "class 1" then 50% of its surface must be red. To class a "Mixed red coloring variety" of apple as a "class 1" apple 33% of its surface must be red, and so it goes for the 3 quality classes and 287 individually named apple varieties. Martin ate fruits and vegetables because the government told him it is the right thing to do. He switched the TV on and listened to the “eat five fruits and vegetables” government ad with attention. Martin’s apple was not very tasty, but at least it was controlled by a European central authority. “Isn’t that great,” thought Martin, “the EU takes care of our food. We now can eat only nice and safe products!” Martin is paying 40% more for his food because of the EU’s highly protectionist agricultural policies, but it is the price one has to pay for civilization.
---
The states themselves also retain substantial powers. They can block a Constitutional amendment or call a Constitutional convention, they can appeal to courts with 250 years of common law precedent backing them up, etc. There is much more clarity in the American system.
The EU doesn't work the same way.
> https://www.youtube.com/watch?v=0oJqJkfTdAg
All I can hope for, is that some activist group takes the police to court and the legislative branch reacts to then impose rules for spying on its citizens.
Some of the things I can think off the top of my head:
1) Citizens can legally opt out by putting on face masks. Especially when it's cold.
2) Video / Images are stored outside of government bodies and akin to a black box. Must require warrants to review footage.
3) Video / Images / Data are deleted after 1 year.
4) No data of citizens facial features, body structure, gate are transferred into a national database.
Honestly though, where the UK is going. I firmly believe in 20 years all citizens physical meta-data will be tracked and stored in a black box somewhere and then later leaked on-line.
1984 isn't just a book. It's a handbook by all accounts.
the UK has issues with creeping authoritarianism in an number of areas, but millions of shops having crappy 2FPS black and white CCTV isn't a particular concern of mine
It doesn't matter who owns what as long as the government can request access to the data.
in this situation: the fact they're not controlled by, or accessible to the state without effort is neither pedantic or irrelevant, sorry.
The fact that there is some extra effort required to get to the tapes does make it a bit inconvenient, but that won't do you any good if you're caught by those surveillance cameras in the wrong place at the wrong time. The investigators will almost always make that effort, since it's part of the job.
You don't have (yet) some beautiful law like we have in France?
https://beta.legifrance.gouv.fr/loda/texte_lc/JORFTEXT000022...
> Nul ne peut, dans l'espace public, porter une tenue destinée à dissimuler son visage.
Noboby may, in public space, wear an outfit intended to hide his face.
Clear and simple, I guess. That was directed towards radical Muslims but the definition encompasses everyone. And last year we got this extra one:
https://www.legifrance.gouv.fr/affichCodeArticle.do?idArticl...
It is about hiding all (or part) of your face, within (or near...) a demonstration, in which troubles arose (or might have arisen...). The first law was an infraction, this one is a misdemeanour with much harder sentence.
And it's by no means certain that you and I can't do better. I think the reason Yandex image search is better than google's, is that Yandex entered the game later and thus could incorporate better methods from the start. There have been important advances in extreme classification even in 2019.
I think the best we can hope for is that this power of identification isn't exclusive to governments and police, but can be used by us as well. So that there aren't more Bob Lamberts than necessary.
"Met Police to deploy facial recognition cameras"
> As for facial recognition, the Commission document highlights provisions from the EU’s General Data Protection Regulation, which give citizens “the right not to be subject of a decision based solely on automated processing, including profiling.”
It's more nuanced than "a ban on facial recognition". The leaked white paper is also available [1]
[0] https://www.euractiv.com/section/digital/news/leak-commissio...
[1] https://www.euractiv.com/wp-content/uploads/sites/2/2020/01/...
These bans have good intentions, but won't solve the actual root of the issues, and does more harm than good.
It sounds like the ban needs to be broader, and extend to ban any technology used to automatically identify individuals without their consent using surveillance sensors.
It's similar to how GDPR and similar laws operate. Collecting the data is fine, but you'll get in trouble if you process & distribute that data without clearly notifying your users.
It signals intent.
The reference to smartphone tracking before the one I believe you're referencing in that article details the myriad other of ways to track people: financial transactions, license plates, MAC addresses, heartbeat, gait, etc. You can substitute those in for the fallbacks.
Fair enough but I've just asked this somebody in another thread here: What innovation? This seems completely hypothetical, facial recognition is neither hard, nor complex. Neither is image clustering and other backend stuff required to use this for malicious purposes. If innovation means use cases like clearview I don't really care. Surely the privacy of millions should be valued higher than a few startups with smart photo album technology or whatever that will likely fail anyway for completely untechnological reasons. The EU seems to be, quite surprisingly, relatively specific with this call for a ban.
> The reference to smartphone tracking before the one I believe you're referencing in that article details the myriad other of ways to track people; financial transactions, license plates, MAC addresses, heartbeat, gait, etc.
Don't see how that changes my argument, in the EU none of those are treated like they might be in the US. Especially after the introduction of GDPR that's already mostly illegal tracking, no matter the specific technological implementation, and should satistfy the critique Schneier brings in his article.
This is a question that possibly can't be answered if it's illegal to experiment with it from the get-go. Off the top of my head, it could be used for thought-provoking art installations; perhaps one that utilizes facial recognition to derive the viewer's emotions and let the procedural art change accordingly.
> that's already mostly illegal tracking
Yes, GDPR's a great step in the right direction. It's stopping a lot of the corporate surveillance. Right now the EU needs to keep an eye that their governments are also subjected to the same level of restrictions, which are currently not if its ends are for "national security" or similar reasons.
I fully concur w.r.t. applying the same restrictions to European governments, i.e. this sentence from the article: "These include the German government is planning to roll out facial recognition technology [...] after a successful trial in Berlin." The "successful" trial published an anonymized evaluation, results were horrid. It's quite amazing how split the political field must be here. In Germany that's also down to law enforcement exemptions from quite a few privacy laws, no "national security" pretense needed.
A relative was the lead policeman in a case where a person A accused a person B of a very serious crime. Person B appeared on a camera in the area, police identified him instantly based on the national database of ID cards (it contains photos of every person over the age of 14) and arrested the guy. Luckily for him, he was covered by a different camera for the whole time he was accused for the crime, but that was discovered after he spend a day in arrest. The person that make the false accusations simply walked.
There is a database of pictures of people that get an ID card (which is mandatory, not having one with you at all time grants you a fine). Another one for passports, but those are optional. Another one for driver's license (having a driver license with you does not save you from a fine if you don't have also the ID). These are databases everyone knows about and police are using every day, no authorization is required.
Consider the following scenarios:
- I can pay for a person to watch archival video and take notes on paper as to who comes in and out of frame.
- I can have software that helps a person crop faces of people coming in and the person can tag and catalog the people coming in and out of frame.
- I can have software that identifies human looking things and things that look like faces and a person can tag those
- I can have software that identifies human looking things and things and recommends a similar face. A human confirms.
- I can have software do everything.
At which point does it become facial recognition? The end results are the same regardless of which step you ban. So is any ban just meant to make the cost artificially high? I think you could outsource it anyway via Mechanical Turk or something similar if there is a real value to facial recognition.
I don't think banning technology is the answer.
Quantity has a quality all its own. Something that is acceptable at a small scale may have unacceptable consequences when done at much larger scales.
Making the cost artificially high by banning a particular type of technology is not addressing the real problem of civil liberties.
I think it helps.
You can't seriously expect to build a system like big brother and be so naive as to think this wouldn't be result sooner or later.
I don't think people are worried about computer vision identifying Human vs Not Human as much as they are about the (not humanly possible) pinpointing and following of every move.
But aside from that, to address your questions:
1. If there's a human in the loop, the human can be accountable. Explainability and accountability of algorithmic decision-making is an emerging concern, especially to the extent that algorithms may encode bias in their training data.
2. Real-time systems. Being real-time qualitatively changes the impact this can have on your day-to-day life. Taking the human out of the loop makes many applications feasible that otherwise wouldn't be. Like doors.
The reason one would ban a machine from doing what a human can do is that it's stupendously faster, and enables all sorts of dystopian effects that manual face-tagging doesn't.
Rando Startup can start scanning faces in public. Then it starts matching those faces with actual identities. Then it adds in the cell phone location data to determine which ones visit synagogues regularly. So it adds a little notation to the data table about each of these people. Perhaps a yellow star will do nicely.
If you know anything about recent European history, you will understand why this is a bad thing.
So you run the risk of having large numbers of innocent people being incorrectly tagged as persona non grata - be that with the police, in-store detectives, hotels, potential employers etc.
Having a computer say "this person is bad/unwelcome/a shoplifter/bad credit/a sex offender/etc" is powerful, and difficult for laymen to counteract. Computer says no - sorry, it's policy, nothing I can do.
And you can do this at huge scale for pennies and in the blink of an eye with a computer. You can't do that with a human manually/semi-manually doing it.
https://www.washingtonpost.com/technology/2019/12/19/federal...
We do it all the time.
- Phone autodialers are legal, but particular uses are fairly heavily regulated (in theory, at least).
- Heavy machinery use is regulated in a variety of ways.
- LEOs in the US recently were told GPS bugs (which "just" do what humans can do - taking notes on where a human goes) require warrants.
- Explosives dig much faster than humans. These are heavily regulated.
- Most radios sold in the US will refuse to tune certain bands for legal reasons, even though it is trivial to modify some of them to do so.
Etc.
As far as your slippery slope argument, it simply doesn't matter. The point is to reduce the harm done by a given tech, not achieve some sort of abstract purity of thought.
Isn't the whole point of facial recognition security projects
That's pretty bad IMO, regardless of what you think about the use case for law enforcement.
After all, seems a fair few laws are a loophole away from enabling more crime than the law prevents. So a step back like this, does so in balance towards the consumer/people over government/business.
But like many things, there will always be exceptions and those that will take exception to them, which is fair as that is how democracy works - equal voice and often it has taught us that whilst today their may be a small child at the back questioning things, there may be more tomorrow and the next day. Showing that all questions need answers, this is a good start in enabling that. Will the public engage and have their say heard, or will the EU pull for pubic say and what balance will play out. We will know over the years and be great to see how far that goes 5 years from now, once the ban has ended, or been extended.
Just a few silly demonstrative edge cases:
- If I run facial recognition software on a public camera feed on a computer in private would it be legal? - If in Europe in public and running facial recognition software on my laptop processing say my own personal family photo album would I violate the law? - Would running it on news footage of a public street be legal? What about if it was an interview where you would get thrown out if you tried to enter.
It's also a very different thing to process an image and permanently mounting a camera in a public space. Something that already requires a license in many/most jurisdictions, and getting one is hardly trivial.
Bans on facial recognition means prosecutors of corrupt officials have to rely more on eyewitness testimony and eyewitnesses can be intimidated and have "accidents".
If you ban the tech, then you prevent research on it as well. If you ban the use, you can not catch violators.
As for whether it's enforceable, that's another question entirely. Historically, bans on the creation, use, and/or distribution of software haven't done so well in that department. (See export ciphers, piracy, DRM.)