Clearview’s App Used by Justice Department, ICE, Macy’s, Walmart, and the NBA
buzzfeednews.com
buzzfeednews.com
He's a good model for the future of AI, where superintelligence's goals conflicts with basic human values.
Nothing special. Cognitive dissonance is alive and well in the filthy-rich through to the dirt-poor. As we can see - your level of personal agency will be the determining factor in how much the world suffers from it.
Unfortunately we silo our processes in virtual-mental-machines at the expense of good ideas cross-pollinating terrible ones.
>>In addition to Mr. Ton-That, Clearview was founded by Richard Schwartz — who was an aide to Rudolph W. Giuliani when he was mayor of New York — and backed financially by Peter Thiel, a venture capitalist behind Facebook and Palantir.
More generally, Peter Thiel is not a good person.
He'll donate $10 Million to EFF and get a badge.
You freely put photos of yourself on the internet and they use them. Don't like it, don't publish it. This is 95% of what's going on here.
Gawker took private information on Peter Thiel that he did not want public, and had not made public.
Hulk Hogan was worse - "at trial he claimed that the videotaping was without his knowledge or consent"
I think it's great a company is doing this openly. Do you think the TLA aren't? We also know private Russian companies have been doing this for years. This is a good move towards privacy.
Apropos of that, courts have long held that billionaires have reduced rights to privacy due to their “overwhelming influence on public affairs and events”.
That’s why Thiel backed Hogan’s lawsuit (and to my mind, interfered unfairly), and was not able to sue Gawker.
Best Buy, Equinox Gym, Rite Aid Pharmacy, Home Depot, Kohls Department store?
What is going on? What possible use cases do these companies have that require facial recognition searches?
"Clearview is an after-the-fact research tool. Clearview is not a surveillance system and is not built like one. For example, analysts upload images from crime scenes and compare them to publicly available images."
Do you imagine Rite Aid and Equinox Gym which are not exactly bastions of technology are developing sophisticated Minority Report type systems?
(https://consumerist.com/2016/11/23/three-return-scams-retail...)
(https://consumerist.com/2017/04/18/man-steals-11000-in-stuff...)
Using Home Depot as a retail example, more and more, when you walk into their stores you may find cameras with signs boldly stating that "you're on camera" in aisles, at self-checkout registers, and at customer service desks (i.e. return desks).
These are meant to be a basic deterrent, but can also be used for investigation related to returns abuse/fraud. Many retail stores have allowed customer returns without a proof of purchase.
In some cases, they provide cash refunds, below a certain dollar amount. Most stores now issue gift cards/store credit, which can still be resold on card exchange marketplaces, ebay, etc for most of the card value ~90%.
Seems to me that I need to use a spare bag to cover the camera, or wait in line for a human next time I go shopping.
At some tipping point I could see HIPAA-style mandates come into force for general data.
It is a very different set of behaviors than pre-HIPAA.
Same with GDPR, you very clearly see large corporations at least asking: "Do we need this data?" and there's a patchwork of state privacy laws (CCPA being the most prominent) that are in effect.
Case in point: Illinois has really stringent biometric data laws that include facial recognition and I would not be surprised at all if they were right now preparing for legal action against Clearview for violations.
Took effect this year.
Law enforcement's use of this style of abusive technology will never be curtailed or in any way reigned in, but seeing as American law enforcement has never abused their power in the past, I'm sure that will continue to not be an issue.
That would be helpful, but let's not forget that HIPAA isn't exactly some sort of gold standard. It's reasonably weak and full of loopholes.
To get a trademark, the mark you're registering has to be actively used in commerce. There are other laws that come into play if you're using someone else's likeness in commerce.
The entire purpose of trademark is to prevent consumer confusion (for instance, to prevent one company from using another company's logo on their products).
Another wrinkle is that in the US the copyright of a photo belongs to the person who took the picture, not the person who appears in it (unless an assignment of copyright was signed).
So, if you posted a picture of yourself that you didn't take then you probably aren't the copyright holder, which would mean that you aren't the one who would have the right to recourse for any misuse of it.
I also wonder if one might be able to use the DMCA process against Clearview.
> "The court determined that a copy of a program made from a hard drive into RAM for purpose of executing the program was, in fact, a copy under the Copyright Act."
see https://en.wikipedia.org/wiki/MAI_Systems_Corp._v._Peak_Comp...
Anyone visiting the profile will have a copy of said public photo in there cache. That in itself doesn't trigger a copyright act because the photo is licensed for that act.
Reusing the image would trigger copyright protections as the licease granted to facebook doesn't cover that. It would be the same as downloading a trial program with images. You can use them in the game, you can make calculations on those images (they are this big, they are classifed as tree, face, etc) but you can't include them in your game.
I understand why a company collecting this information is annoying / frustrating, but it was also inevitable, was it not? EDIT: Example, LinkedIn just got told by a court that they must allow crawling. A quick crawl of profiles and photos would yield a beginning of one of these types of databases, etc - one it's on the web, you have to assume it can be used for facial recognition.
Either way I am happy that people are recognizing the import of what they post online - even if it's just a picture.
How do we know they were inputting pictures of suspects?
Could have inputted people they have a beef with, ex-girlfriends/boyfriends, ex-spouses, online dating profiles, annoying non-criminal activists, citizens/politicians that threaten police budgets, etc.
To flip the question: how many databases like this haven't been abused?
When a corporation or government claims new powers over citizens/customers, the burden of proof falls on them to show how they can't/won't abuse it, rather than on the little people to show that it's been abused.
Perhaps I am merely surprised this creates so much outrage / surprise in this community. The folks on this website (we) have created so many platforms for sharing personal information publicly on the internet that it of course makes sense that people have been scraping it for years and it's likely stored somewhere and will be used for non-original purposes at some point because of course. As you say, how many data sets have not been abused?
Users have published this data themselves, on purpose, on web platforms meant for sharing.
I don't think this can be put back in the box. I'm not really sure how you regulate it in any effective way. There are some laws on the books and some corporate penalties but I don't see how you stop this if the model works using public data short of making the data so noisy and useless that it stops being effective (which may have to be the end result)
Difference is that we've had hundreds of years to reach consensus on home windows, but barely a decade for social media. Laws are not keeping up with society's expectations, which in turn aren't keeping up with technology.
Also Clearview itself has been found breaking the law repeatedly.
https://techcrunch.com/2020/02/14/class-action-suit-against-...
The really clever ways to abuse this kind of data haven't even been invented yet. We are still fumbling around with these technologies. Most of the currently visible examples of data misuse are "high tech"/"on the internet" variation of the scams and abuses humans have always done.
Current data misuse is a minor concern. The larger concern is that these databases will probably sill exist 20/30/50 years from now when someone invents a really clever way to abuse data. While it isn't possible[1] to predicting how technology will be used in the future, if the trends in technology over the last few decades suggest that this clever new abuse of data will be difficult for the average person to understand, highly disruptive to existing institutions, and the damage will cascade across the interdependencies[2] we've been adding to everything.
> Building a large list of potential suspects ... sounds very useful
Increasing the number of "potential suspects" is a terrible idea, because most of those suspects are innocent. Adding people to the suspect pool lowers S/N (actually-useful-targets/"potential suspects"). The ideal (magic) tool would produce a minimal list that simply identified the actual criminal. Adding more people to that list makes it less useful.
Also, see the Base Rate Fallacy[3] and the Birthday Paradox[4].
[1] https://en.wikipedia.org/wiki/Connections_%28TV_series%29#Co...
[2] http://geer.tinho.net/geer.blackhat.6viii14.txt (section 10, "Convergence")
[3] https://www.schneier.com/blog/archives/2012/05/criminal_inte...
Is it the government use of the tech, or the fact that the company exists in the first place that is upsetting?
Liability!
(with the option of avoiding that liability by explicitly not allowing yourself access to content/personal-data, aka a common carrier)
As Dan Geer said in my previous [2] (section 2, "Net neutrality"):
Hello, Uncle Sam here.
You can charge whatever you like based on the contents of what
you are carrying, but you are responsible for that content if it
is hurtful; inspecting brings with it a responsibility for what
you learn.
-or-
You can enjoy common carrier protections at all times, but you
can neither inspect nor act on the contents of what you are
carrying and can only charge for carriage itself. Bits are bits.
Choose wisely. No refunds or exchanges at this window.
While he was talking about ISP spying, the general principle can be adapted easily. Inspection (or building databases of the results of other people's inspections) must be tied to liability for the problems and negative externalities produced by that inspection (or database).Obviously this is a high-level description that ignores the messy details that are important in any actual plan. There is room for negotiation and modification. The goal is to create a situation that disincentives creating tomorrow's problems, just like we do for other types of hazardous technology. Data and spyware needs to be seen as toxic that requires special handling, storage, and disposal procedures.
> This is very informative.
Dan Geer's keynote - "Cybersecurity as Realpolitik" (video: [5], transcript: previous [2]) - is incredibly informative and should be mandatory viewing/reading for anyone interesting in trying to create the "least worst" Grim Meathook Future that technology is pushing us towards.
I also recommend Dan Geer BSides DC 2018 keynote[6][7] as an addendum/update to "Cybersecurity as Realpolitik". In both talks he provides a very concise description of the core problems that are defining our future.
We have to soon choose what we want to happen when stolen data is,
for example, not just exposed but also put on a blockchain from
which it cannot be erased. Put differently, assured data deletion
is far harder than permanent data retention, yet many civilized
goals, including but hardly limited to a right to be forgotten,
require the sealing of records or their outright destruction.
Which do we give up, the slick usefulness of immutability or
information crime being unmitigatable? What does consent of the
governed mean when a technology trumps a Court Order?
[5] https://www.youtube.com/watch?v=nT-TGvYOBpIUseful and sensible can be two very different things.
Total surveillance, down to every private space, could be useful to prevent crimes and save lives in accidents, that still doesn't make it sensible.