Swiss journalist re-implements ClearViewAI in two weeks with OS software
twitter.com
twitter.com
He said because they are media it may be ok but the average joe and company should not get any ideas of doing the same thing.
He also said it is facebook/instagram's responsibility to keep the users data safe and prevent it from being scraped.
I'm not sure how anyone can prevent data scraping and I also don't see how it can be illegal if the data is on the public internet. Can anyone elaborate why it would be considered illegal to scrape data in Switzerland? I can see there being a conflict between the privacy laws and doing identifying recognition on public images but downloading the images themselves I don't see being illegal?
We deal with scrapers taking our data all the time and this is the first time I heard that it may be illegal.
[1] https://www.srf.ch/play/tv/10vor10/video/fokus-heikle-gesich...
That's not the first time I've seen someone claim that a journalist claim is allowed to perform some kind of information processing that's off limits to regular people. These claims are specious and ridiculous. Journalists do not form a distinct class with special privileges, even if they claim to be one.
For the love of god can we please stop pretending that every country on the planet is the US.
There is no such thing as a "licensed journalist" because such licensing has been historically used to limit freedom of the press. However, there is an implicit understanding of what constitutes being a journalist that is similar and it is displayed when Judges choose whether or not to force a journalist to reveal their sources.
The core idea is that intent matters. Building such an app to create public discourse by someone with a clear history of journalistic actions is likely to face different regulatory penalties than an individual with no such history who builds such an app for entertainment or profit.
Edit: There is argument to be made that this "soft licensing" serves to extert control over journalists.
”Journalists in many nations have some privileges that members of the general public do not, including better access to public events, crime scenes and press conferences, and to extended interviews with public officials, celebrities and others in the public eye.”
https://en.wikipedia.org/wiki/Reporter%27s_privilege:
”Reporter's privilege in the United States (also journalist's privilege, newsman's privilege, or press privilege), is a "reporter's protection under constitutional or statutory law, from being compelled to testify about confidential information or sources."”
Also, in some (¿many, I would think, but I don’t know stats?) countries the justice system will weigh the right of the public to know against law infractions when deciding whether to prosecute journalists who performed crimes in order to gather information.
For an example, see the pentagon papers (https://en.wikipedia.org/wiki/Pentagon_Papers). All concerned knew the information was top-secret and stolen, but in the end, nobody got convicted for publishing them.
Speculation but I think it can be as simple as Art. 4, p. 3 FADP [0]: "Personal data may only be processed for the purpose indicated at the time of collection, that is evident from the circumstances, or that is provided for by law."
When users upload data to Facebook, they don't consent to have that data used by third parties for facial recognition.
[0]: https://www.admin.ch/opc/en/classified-compilation/19920153/...
I suppose they could use facial recogniton to prevent those uploads...
(PDF link) https://edpb.europa.eu/sites/edpb/files/files/file1/edpb_gui...
> Personal data may only be processed for the purpose indicated at the time of collection, that is evident from the circumstances, or that is provided for by law.
> The collection of personal data and in particular the purpose of its processing must be evident to the data subject.
Note that it adds the qualifier "for the purpose indicated at the time of collection". I don't think there's a realistic argument that Facebook's UI indicates or makes evident, at time of uploading/posting a photo, that the photo can be used by third parties performing facial recognition.
And then, even if you give Facebook consent to do certain things, that consent does not extend to third parties scraping it.
Not the first time politicians proposing something technically off limits. It’s all just magic to them anyways.
There's no way to technically prevent murder or assault, or dumping chemicals in a river, but it doesn't make them any less illegal.
If I remember correctly, broad terms like "for anything" are not permitted.
Or else what?
How would they even know this was done?
All facial recognition tech benefits from plausible deniability. You could just easily say a face was recognized by an individual who saw the photo online and sent an anonymous tip. They have no leverage.
If the government gets serious it also could simply come knocking on the door and demand a tour.
Is rules/legislation against scraping really meant to prevent it, or merely provide a mechanism to punish the perpetrators when discovered?
It can be seen as an issue of intent. By posting something, that datum might be there for personal use, and is not intended for further commercial use, especially by companies outside the one hosting the information originally.
The act of data aggregation is one that I personally think should be heavily considered for regulation, especially since it can de-anonymize people. This in my opinion is a privacy invasion, performing extra actions to access additional private data when no access to the more private details was granted, and those details did not exist publicly in an accessible way. Especially at scale and yielding personally targetable results, this isn't something we want organizations or governments to use against people unchecked.
In the topic of restricting access to others the author says:
But I ask myself: How difficult can it be for a billion dollar revenue company?
Pretty difficult when the law prohibits you[1]. Hopefully that forces regulation to cover the weaponization of technology not access to data. Right now this comes off as; you’re not allowed to enrich uranium, unless you own the land.
[1] https://www.eff.org/deeplinks/2019/09/victory-ruling-hiq-v-l...
Everyone can do this at home today and on a budget, with publicly accessible data.
https://threatpost.com/facebook-to-pay-550m-to-settle-class-...
You may have not noticed, but entire cities are under 24/7 video surveillance. https://ring.com
You may have not noticed, but the ubiquitous mobile phone is morphing into a 24/7 surveillance radar. https://atap.google.com/soli
Am I the only one who has trouble believing that someone who was at a technical level involved in scraping and running facial recognition on 200k photos would genuinely answer "Not very?".
It was years ago, and it was not very difficult.
I’d guess this would be an easy summer intern project for a bright undergrad.
I'm not so sure any more. I feel like we've reached a point where a massive, trustable, profile of me is for sale. I don't think I want a bank that is allowed to do it any more.
Does anyone have any recommendations for a bank focused on privacy? (and for that matter credit cards?)
I know I know - probably impossible, but I am pretty sure I just created a market, who's with me?
I think this should satisfy most friend-finding use-cases while eliminating comprehensive large-scale scraping.
You can still reconnect with that guy you saw at a party a few years ago or that teacher from high-school. Chances are they're within 2 or 3 degrees of separation from you.
Haha, oh sweet summer child. How do you think Cambridge Analytica got all that data? All you need is 1 friend with lousy security practices.