Blur Tools for Signal
signal.org
signal.org
Here’s an example of AI being able to identify a blurred face: https://twitter.com/ak92501/status/1267609424597835777
Identifying an individual is not just about a face, but number of factors that are much more complex and very hard to account for in a systematic way.
—-
If Signal is really concerned about allowing individuals to control the information they leak, they need to prioritize releasing the feature that will allow users to use Signal without providing phone numbers; one of their staff recently publicly stated this is finally likely to become a feature. Not to mention stop repeatedly asking for the user to provide their name, access to contacts lists, etc.
Thing about downscale blur is that it's nearest-neighborish, so can be addressed with divide+conquer as blur effects stay local. You'd end up with a fairly large combination of potential tiles. Some wouldn't be viable faces, but we have classifiers for that already.
Entire combination trees can be culled that way to make the problem radically smaller, as long as you know it's supposed to be a face, so I don't know how hard it would really be. It's possibly pretty easy to come up with the N possible original faces with enough certainty to then match with potential targets of interest and make N small enough to use.
I’m saying with enough data you could potentially create a more predictive “magic sharpening” algorithm that didn’t strive to match a known original picture, but instead used that matching on divide & conquer subtiles of the original LR image against of a rainbow table of reduced HR tiles to predict a set of plausible HR images.
Basically if you can figure out with whatever context you have that the 4x4 brown smudge is very likely a brown cat, you can replace it with a brown cat. And if you know that, the orange/white/black smudge next to it is probably a calico, so stitch it in.
Of course the source image would have to be bigger than this, so it couldn’t be CSI-enhance icon to landscape, really more like a really good AI upscaler. You’d need a strong way to identify plausible scenes too. We can generate novel faces now, think this fuses the two concepts.
Anyway, if you want scarier panopticon stuff, you should look into gait recognition, which is way harder to censor.
> PINs will also help facilitate new features like addressing that isn’t based exclusively on phone numbers, since the system address book will no longer be a viable way to maintain your network of contacts.
Here’s another example of such research:
https://www.wired.co.uk/article/facial-recognition-systems-c...
>> “researchers said only 10 fully-visible examples of a person's face were needed to identify a blurred image with 91.5 per cent accuracy.“
Some methods can be used to find one of many solutions to the blur, where certain high frequency information is preferred over others because we know the end results looks like a human face, and not just any solution. But that only means you can get out many possible faces; if your reconstruction tool only gives you want it was simply over-trained.
[edit] You just updated your post. If you have tagged, unblurred photos of the face in your blurred photo, you can (as expected) constrain the end solutions further. WHat's not clear to me from the paper is whether or not the blurred face was tagged as well. Scenario S3 seems most likely the type of scenario encountered in surveillance programs, where the results are nowhere near 91% accurate.
This might be narrowly true (it’s hard to recover precisely the original image), but is not really an accurate summary in this context, if the only goal of reversal here is to recognize the face. Deconvolution will quite effectively undo gaussian blur. https://en.wikipedia.org/wiki/Deconvolution https://en.wikipedia.org/wiki/Richardson–Lucy_deconvolution https://en.wikipedia.org/wiki/Blind_deconvolution
In Photoshop, the deconvolution tool is called “Smart Sharpen”, and has a preset for a gaussian PSF.
Security as an accidental quality of a system is not security.
Image blur is not a gaussian process.
I'm legitimately asking. I'm really ignorant about this subject.
A hard 3×3 pixelization would be much more reliable, if less æsthetically pleasing.
Things that seem way easier to me:
A) blacking out the face entirely with a solid color,
B) if that looks ugly, replacing it with some kind of clip-art,
C) if that still looks ugly, replacing it with a gradient
D) if that still looks ugly, replacing it with a pre-blurred face from a generic set of buckets.
I sort of get the aesthetic argument, but I also really don't, because the way Signal is blurring faces is ugly, at least in the photo they show. It's not a seamless thing that blends into the background and looks way better than a solid color. It's giant squares, and the amount of blurring means that the contents are basically indistinguishable from a radial gradient to my eyes anyway. Am I missing something? Would a gradient really look any worse than this?
Is there some kind of use-case where blurs give aesthetically much better results than what we're seeing in the photo? Are the concerns I'm seeing below about de-masking just fear-mongering? Are blurs in general just pretty safe, fast, and easy to do? Moxie isn't stupid, I assume in situations like this he knows what he's doing.
With a static overlay, the method is simple enough that I can evaluate the security. With a blur, I don't know the difference between a good one and a bad one, so I can only trust the reputation of the author.
I like to be able to look at the output of an anonymizer and to be able to tell myself at a glance whether it worked.
iOS module:
https://gitlab.com/seclorum/groupie/-/tree/master/ios/groupi...
Main node.js app:
https://gitlab.com/seclorum/groupie/
Works on Linux and Darwin, just type 'make'. ;)
Suggestion for an algorithm:
* start with the blur
* sample the four colors at the four corners of the blurred region
* quantize them
* fill in the region with bilinear interpolation.
Then your whole region can only reveal these four quantized color values. If you only blur then you will have a harder time proving the leaked information content. * detect (or get the user to select) faces
* replace the pixels in the face bounding box with a generic face
* blur the bounding box edges
* do whatever blur you think ends up "looking nice"(From the examples in the Signal blog post, I don't think that grey gradient box is gonna be able to specifically imply white or POC faces...)
A side comment: AFAICT what the Signal developers have done is take code that was developed so that the phone camera could autofocus on faces, and and used that code to defocus faces. What a sweet hack.
Blurring is better than nothing but the best picture when it comes to avoid being traced is the picture that was never taken.
And even then law enforcement are already filming them (cctv + from the air) and tracking their phones, the last thing you have to worry about is a 100% blurred face that no amount of technical power would be able to process or match back to you.
picture B of a blurred individual from later on in the same protest, wearing the exact same clothes, commiting questionable acts, is circumstantially incriminating.
I'm not sure whether the large number of photos nowadays is a net negative, though. That's also what finally stopped Derek Chauvin.
You could definitely take signals code, and run it over the set of test images and find which output matches closest to the target image.
https://www.androidpolice.com/wp-content/uploads/2020/06/04/... is blurred by Signal. Suppose that you have all the photos that have been posted to Facebook, and that both of those women are on Facebook, and lastly that you have resources enough to run all of those through the Signal code. How would you match those other photos to the blurred part of this one?
To your eyes, maybe. To a machine, you have an array of pixels, each with different values which, using an algorithm, could be adjusted into something your eyes can resolve into a unique face.
That said, the whole point of my post was that humans are really bad at judging this. Many blur algorithms can be reversed because they just modify the color values of the pixels in a reversible way. You can't always tell by looking at a picture what data is still there, in much the same way you can't see the stars in an ISO 200 picture of the night sky. It's not until you open it in GIMP and crank the exposure up to max that you see just how much data is there that your eyes couldn't perceive.
But like others have pointed out, you can achieve (allmost) the same effect, if you remove enough information before blurring, or just drawing a smooth gradient, but this alone is harder to make it look as nice, as blurring the actual image.
They appear to use "com.google.firebase:firebase-ml-vision-face-model:20.0.1" to detect the faces.
The actual blur appears to be done here: https://github.com/signalapp/Signal-Android/blob/514048171bf...
Not sure what "ScriptIntrinsicBlur" stands for exactly, it appears to come from the android SDK itself: import android.renderscript.RenderScript;
EDIT: https://developer.android.com/reference/kotlin/android/rende...
It's a gaussian blur filter with a radius of 25px if I understand the code correctly.
EDIT: come to think of it, you can generate random noise using a palette from the color in the blur area (say, take four or five colors and mix them).
Applying convolutional blur for anonymizing is very very risky. Because you might end up with something either invertible or nearly so.
Thanks for digging.
https://news.ycombinator.com/item?id=23422993
In fact it almost seems like the actual blur used in the app is different from what they show in the article.
I wonder why Signal didn't do something like that...
It's okay for still images, but videos have a lot of information to leak. Just black everything out.
Note that if you blur the pixelated region, it'll be just as aesthetically pleasing as the reversible Gaussian blur.
Edit: Turns out it's a 25px Gaussian blur. There's some downsampling beforehand, but not much, and no color discretization. In other words, they use a bad blur, but compensate with a large security margin. I wouldn't be surprised if this was vulnerable to "if I have a thousand photos of faces and I think one of them matches the blurred face, I can figure out which one with high confidence", and they can get basically the same aesthetic effect if they heavily pixelate and discretize colors before blurring.
Is that actually a practical attack here? I can see it working if you have 1000 passport photo or mugshot frames photos, and a blurred photo with the same level/front-on framing. But is there a practical attack for non direct-facing-camera blurred pictures? (Assuming the scale of "locals at a local protest" instead of "Find Edward Snowden's blurred face from any BLM protest, no matter what the cost!!!")
But I've been surprised by impressive digital forensics before—what if you can determine lighting and orientation from the rest of the photo, and then simulate them on each passport photo/mugshot? I'd still feel much more comfortable if they pixelized and color-discretized before blurring, and I still think the aesthetic effect would be much the same.
2017: https://arxiv.org/pdf/1702.00783.pdf (Pixel Recursive Super Resolution)
2020: https://venturebeat.com/2020/01/22/researchers-use-ai-to-deb...
Edit: Most face recognition software works by down-sizing and blurring an image to faster detect face features. So in theory it is very easy to detect face features from a blurred image. A deblur tool can then use this information to better deblur a face.
Edit: The images in the Signal article don't look like images of blurred faces. They look like blurry images overlaid onto faces. If you don't blur the face, how can it be unblurred?
So the ridiculous „Enhance!“ one sees in TV show crime dramas could one day actually become true.
My understanding of facial recognition is that it operates on relative positions of facial elements. If you can "delete" this uniqueness from the source material by warping faces towards a limited handful of generic shapes, you make the video less useful to Government intelligence.
You could still blur the result, but you might be able to get away with less blur. Remember that it's important to see that people have faces otherwise they can be more easily dehumanised.
Of course humans are pretty good at filling in detail, so with a sufficient blur you can get away with surprisingly poor approximations of a human face.
A better blur algorithm (in that it can easily be proven not to be reversible and is faster to process) is to divide the area to be blurred into a small number of cells, (9,16 or 25) get the averaged colour in each cell and then apply an interpolation between those colours as your output. This algorithm is essentially O(n) where n is the number of pixels to be blurred. You can easily prove that the information in the image is at most 3 bytes (each colour) * 25 (number of cells) = 75 bytes which is not enough to encode a face however it may be enough to encode some limited details (such as skin colour, distinctive clothing etc.) so always better to use a black box.
Side note, even with a mere 25px image (effectively) of someone's face I'm not sure if it leaks as little information as you think it does. Just 33 bits would be enough to uniquely identify someone, let alone 75 bytes. Practically you wouldn't be able to recover more than some basic estimates of skin colour and distance between the eyes etc, but in extreme cases that might still too much.
Also I can't help but wonder, in a case like this where you've got the rest of the image, whether the pixels around the border of the blurred region are useful. There's going to be a probability that they're a similar colour to the outer ring of pixels that got blurred, and that might give you enough to start working inwards.
If you redact, say, a credit card number with a blur, and I know what typeface the number would have been written in, and have a reasonable guess as to your blur radius, it might not be infeasible to compare the blurred version of every possible credit card number.
If you redact an email address with a blur, brute-forcing every possible email address will be harder. But if someone (say) leaks information to you, and you merely blur out their address, it's not infeasible that someone else could apply the same blur to a known suspect's email to verify whether it was them or not.
Of course, with a large enough blur radius it's not an issue. Still, a non-zero amount of times, it's been done badly enough I've been able to mostly "reverse" a blur by just squinting and sitting back a few feet.
Always redact text with solid blocks.
I don't know how feasible this approach would be to human faces. I think Signal has blurred it such to make such an attack infeasible.
I also don't think it's sufficient; if you don't want someone to be identified don't take photos of them, full stop and/or period. Take the photo at the top of the blog post. Who on that day, had that a backpack with that type of strap, a blue mask in exactly that shade of blue, that haircut, and that exact BLM t-shirt, in that place at that time of day? That could be sufficient information for a "fingerprint", though maybe not deanonymisation.
Things like swirls can, though: https://thelede.blogs.nytimes.com/2007/10/08/interpol-untwir...
The belief that you cannot identify someone from a blurred face is an extremely strong assumption that is just begging to be demolished using some sufficiently advanced technology.
In particular, if you only need to go from a list of 10,000 candidate persons (thanks cellphone mass surveillance) to three or four candidate persons (shoot them all and let god sort it out) then I am think it is fairly that you could do so with more or less existent technology. (essentially, use machine learning to transplant faces from DMV photos into the scene and then redo the blur and select the most likely matches).
Think of it this way: if you want to winnow 10k candidates down to four people you need to extract less than 12 bits of entropy. It's not trivial because the scene, pose, lighting, etc. make all your measurements noisy and non-independent.
It's impossible to tell from the screenshot, but if they're smart, they should have an explicit degradation step before blurring (e.g. pixelate/lower resolution first).
You can reconstruct a plausible face by deblurring, ie. one that looks sharp and human. But if you want to identify someone having a plausible picture with a pair of eyes in a plausible position doesn't help, you need a fairly accurate assessment of the distance between the correct eyes, and that's susceptible to loss of information during blurring.
Based on all information out there, in year 2020, what is the most secure IM app?
What do you recommend to your friends if they care about privacy?
Matrix is interesting and I hope it will catch up eventually, but currently it is not E2EE by default and it leaks way more metadata than Signal. These point make it strictly worse than Signal for 1:1 IM.
The advantage of Matrix is in federation, but regarding privacy / security, it is still behind (much to my regret).
Other apps that could provide similar guarantees in theory are less used and have received less scrutiny, so more not yet exposed bugs and design flaws should be expected. Other apps have been relatively well studied, but have well-known design flaws that also make them worse than Signal (WhatsApp and Wire leak way more metadata).
Bear in mind, the server is open source only in name, the state of documentation and configurability is extremely hostile towards running it yourself, to the point that the only way to configure it to run correctly requires reading the code to find the type, size, syntax and everything else about every piece of configuration because none of it is documented or clear.
I did this as part of my day job, which included, at the time, documenting it. It's impossible for me to share that documentation I did on company time. As for doing it again, I'd have to check my contract and/or discuss it with said employer.
Matrix is significantly less proven, leaks a bit more metadata (at the moment) and has had a few incidents that make people cautious about trusting it for real activism -- but it's a more future-proof investment if you're not currently an activist, and some of the stuff they're working on (most recently around P2P and mesh networks) may be really valuable in the future.
Matrix is taking an explicit stance that concepts like federation and custom clients are not antithetical to privacy. It's yet to be seen whether they're right about that, but a lot of us want them to be right. We'd prefer to live in the world that they describe.
Apps like WhatsApp and Telegram also exist, and I guess some people like them, but I don't see any reason to bring them to the table since Signal already exists and is already the gold standard for privacy. The only reason Matrix is on the table is because Matrix is fundamentally different from Signal in ways that are worth caring about.
So in short:
- If you really need to make sure nobody reads your messages, use Signal. Hands down, not even a contest.
- If you're invested in the future of apps like this, and you have auxiliary concerns around federation, openness, and bridges that might outweigh your worries about potential vulnerabilities, then consider using Matrix.
Nearly all of these apps are better than doing something like encrypting an email. Email encryption is a minefield of insecure clients and foot-guns.
In addition I have a private mattermost server, which is heavily restricted in terms of firewall and users but this is reserved only for a very small selected group of people that I trust and I am 1000% sure that they know what they are doing.
Unlike Signal, it does not rely on a single server.
[0]: https://www.reddit.com/r/privacy/comments/gukg5z/threema_win...
Well gouv.ch might, but Crypto AG was an NSA front for decades so I wouldn't be so certain about the companies.
If I wanted to lure people in on the pretence of security and privacy, Being Swiss would be good bait.
Can someone explain the downvote? I am not complaining but are there security problems with it? Could you explain or highlight them?
Secondly, you were probably downvoted because you didn't add any content to the discussion other than a link.
Session goes a long way to fixing Signal's problems like its reliance on a centralized server and phone numbers but it's still very early days with an unproven product. Messages still get lost all the time and if you thought it was hard to find your friends on Signal, it's the Sahara Desert on Session. You'd be putting in months and months of fervent pontification to friends and family you've probably just managed to migrate to your other privacy chat platform of choice.
The new XMPP hotness is OMEMO. Conversations is a good mobile client that supports both PGP and OMEMO.
OMEMO is five years old, and supported by all major clients, so it's not very "hot" anymore".
OTRv4 is somewhat hot and new. It's not in wide use (yet) and it's unclear if it is enough of an improvement to take over.
No. OTR depends entirely on fingerprints for identity. The poster was referring to the difficulty of knowing for sure that you are really end to end. PGP has the advantage here in that you can be completely sure because you can exchange the keys yourself.
Keeps the aesthetics of the image but also removes the face entirely.
http://lelandbatey.com/projects/signal_blur_comparison/
Basically, I think they're using a constant blur size which fails to adequately obscure faces that take up a lot of the image because when a face takes up a lot of the image then the features of that face become large, which would require even MORE blurring to obscure. And they're not doing "more blurring" when the area which needs blurring grows, or at least they aren't doing enough additional blurring.
Is the blurring some type of encryption that the user can unblurr or is this a one way road? I am just thinking off some odd circumstance where say they realize they had a picture of a vandal somewhere. But I guess you can then be forced to unblurr everything by law enforcement which might be undesirable in some cases.
Slight off topic from the article, I was reading about the sting ray discussion here on HN yesterday. Signal supports some sort of mesh network communication right? Is that a work around for sting rays? Thanks.
As for the mask it'll do a little bit for CS and mace probably with eye protection but the goal is mostly protecting protesters by keeping them from being identified and retaliated against later. It's also way easier to make a buff style covering and it can be worn over many types of filtering masks.
Believe you’re talking about Signal using “domain fronting” - which is unrelated to stingrays; more information is here: https://signal.org/blog/doodles-stickers-censorship/
As for stingrays, here’s recent article on countermeasures: https://puri.sm/posts/taking-the-sting-out-of-stingray/
When peacefully protesting, I can't imagine why you would need to hide your face.
If not peacefully protesting and/or looting, such a mask has use for criminals, but I can't imagine that's the intention of Signal.
I think in free, democratic countries, you shouldn't be allowed to hide your face, so you can be held accountable for your deeds.
In non-free countries I can imagine you would need to hide your identity, but would Signal be able to distribute them there?
Questions, questions ;)
What is your definition of peaceful protest? What we see in the US now is definitely not within my range.
Thrashing stores, looting, torching vehicles.
When I think non free, I think of the CCP prohibiting peaceful rememberance of Tianamen square.
I don't know how much work goes into making a new Signal release but it terms of raw coding it's like two days of work.
In events like these, they likely have access to quite a few image sources that do not blur faces.
So, given an image with blurred-out faces, they can look in those sources for images showing persons with similar skin color, hair, length, and clothing to the person(s) they’re interested in, and from there find your face.
If they are willing to make an effort, even individuals may be able to do that, using photos that people who don’t blur faces upload to the internet.
Here’s 2018 990: https://pp-990.s3.amazonaws.com/12_2019_prefixes_82-86/82450...
There are many cases (such as the recent protests) where you might want to document something and it is infeasible to ask everyone else in the area to leave first.
* Recent advances in AI actually make this possible to an extend. The AI delves into it's massive memory and extrapolates a likely image/face.
I remember the Mueller report being printed out, inked over, and then scanned before exported as PDF just to make sure there's no software shenanigans. I really like this idea.
If you wanted to implement that in the field, you could purchase a Polaroid camera, ink over faces manually, and then use your iPhone and take a picture of that picture and destroy the film afterwards.
Nevermind the fact that in your examples, the physical originals can be stolen before you have a chance to redact/blur them, or your blurring done by hand isn't good enough and you can get the original by increasing contrast or whatever.
If you have your servers and employees where the government can reach you, you can be compromised, because ethics and morality go out the window when it's about your safety and that of those you love.
Analog is always safest, because it's what the world is grounded in. If you don't like inking over an image, then burn the faces of it using a blowtorch, or if you're worried the ink is still there, you can stamp out the faces using a hole punch.
I want to also clarify what gait recognition is, for those not that familiar with it a common misconception is thinking it is limited to analysis of how you walk. It is not; factors of gait recognition: height, weight, build and proportions, sex, age, clothes (including type—-dress, shirt, etc.—-shape and colors), emotions displayed, facial tics, unique mannerisms. The analysis of your actual walk/gait is incredibly deep and consists of hundreds of variables, too many for me to care mention here, I might blog about it if it is of interest to anyone, but a few examples: cadence, the angles of just about anything you can imagine possible to measure, spacing between feet, knees, arm swing distance, etc.
For anyone familiar with Haar-like features it should be easy enough to understand that with enough features within threshold you can id just about anything.
This is all yesterday’s tech, by the way.
My point, be very cautious of attending anything that might destroy your future. Do not think a mask or blurring protects your identity, that is extremely naive.
If you're afraid to be seen in public you have no future to destroy. It has always been possible to identify people with diligence if one is sufficiently patient. Given that you're 'working on a surveillance system' your post reads as little more than an attempt to intimidate people from participating in political activism.
The system I am working on is not for law enforcement.
I respect people standing up for what they believe in. I do not respect people destroying the property of others.
I see no harm in «educating» people. Even on HN I think there is few who understands fully modern surveillance capabilities. Knowledge is power, I believe information wants to be free.
Did I mention a specific event? No. Stop bickering, it is childish.
It took me less than a minute to do this with Gimp (and I'm very bad at Gimp).
It's a simple median blur over a random noise.
The last thing you want is to find photos or videos of yourself on a right ring YT channel because you will get doxxed, harassed and threatened.
The ones I recall like the bike lock incident in Berkeley was that the extremely violent get doxxed on the chans but not your average protester who isn’t smashing things.
Don't play the game of trying shift the focus on what the victim did do "deserve" fearing for their life. If someone, anyone at all, is threatened or harassed they are a victim. They can also be a shitty person but these don't cancel each other out.
The truth is that the people who get harassed and doxxed are fairly arbitrary and have more to do with whatever unlucky soul the host decides to pick on that day rather than any kind of rational process. Trying to figure out how internet bullies choose their targets won't get you a satisfying answer other than "people who look like an easy target to be make fun of."
Imagine having your face online, plus the resources of the police...
Although I suppose that if you're participating in a protest that's not really the same thing, the whole point is to be seen after all. And signal is generally used for private messaging so it's less of an issue. So overall I guess I agree with you, I guess the Signal devs feel strongly about the current events and wanted to do something to help.
Then why are they beat up, gassed and arrested ?
/s
I love Signal but it’s so klunky and broken. Telegram is much more fluid despite it being less secure.
And the Mayors in LA let the looting happen purposely.
It also informs you when people in your contact list are using Signal. It's probably not scanning through all of the phone numbers in Signal's database locally, so it is exfiltrating your contact list as well, exposing your network.
Personally, I'd prefer a model where I am not required to place even that much trust in the messaging provider.
They claim they do that in a privacy-preserving way with crypto magic but it's the inform-people-when-you-start-using-signal part that is a problem
If you can't tell if a contact has Signal, it would have to default to SMS - and when sending a Signal message (to either a phone number, or in the future, a non-phone identifier), there'd be no way to tell if you're sending it to someone with Signal, or sending it into the void.
Maybe that's a trade-off you'd be willing to make, I don't think it's cut-and-dry though.
I have been to numerous peaceful protests in the US, even been attacked by observers, and have never had to hide my identity.
Additionally, in a large crowd where most will not hide identities, this app is useless.
Only use case I can imagine is a one to many communication likely to be frowned on by authorities, which sounds like the coordination of illegal activity, such as violence and looting.
I wonder if any website where such techniques are popularized would consequently be considered an accessory to whatever illegal activity is being coordinated?
And even if not, as owner of such a platform, it would not rest easy on my conscience to know my site is being used to help coordinate activity that will hurt and harm a great many innocent people.
Look at all the cases of unprovoked, retalitory police violence over the last week.
I understand why people are scared and want to stay anonymous. The US might not be run by the Nazi party or the CCP yet, but do I want to bet my safety that it won't in the next ten years or so? Especially given the trend over the last years.
and the US is not nazi germany or the ccp. if it were, face blur filters would be the least of your concerns. this only makes sense in the context of conducting illegal activity in a lawful democracy
i just think we need to look at what we got compared to most places and times, and not be too quick to throw out the baby with the bathwater
Yes, it is.
On the other hand, in China, just for having Signal or the like on your phone is enough to earn a stay in their concentration camp and some involuntary organ donation before getting disappeared for good.
I would say there is at least a slight (very slight, mind you ;) difference between the two situations.
Given everything else they seem to be getting up to, why take the risk? Especially when Facebook will do the hard job if tagging folks for them. I certainly know of police keeping their own photographic records of peaceful protestors, so why contribute to the problem?
Also, why assume it's only the police a protestor might be worried about?
> On the other hand, in China
Don't care. Totally irrelevant. This is not a comparative exercise, and you can stop using it as a cheap deflection now.
> Law enforcement officers must monitor peaceful protests to identify individuals who might do harm and incite violence. Such individuals should be detained, isolated or interviewed to determine if they are a threat to the peaceful assembly.
From https://inpublicsafety.com/2016/07/preparing-for-protests-ci....
Here's one UK police branch that does it in the open: https://en.wikipedia.org/wiki/Forward_intelligence_team. It would be beyond naive to assume that police in the US don't do the same.
All of this is a side-show, though. If I take a photo at a protest, how do I know what harm would come from publishing any faces that I happen to capture? You seem to be making the argument that I, as a private citizen, shouldn't have a tool available to ensure that I'm not doing harm. Who does that serve?
The fundamental core of your argument seems to be that if people have nothing to hide, they have nothing to fear. That is, and always was, bullshit.