European Citizens' Initiative for a ban on biometric mass surveillance
reclaimyourface.eu
reclaimyourface.eu
This is not your regular online-petition. This is an European Citizens' Initiative. It is an official procedure and the only mechanism the European Union gives their citizens to directly put topics on the Commission's table without being mediated by their politicians.
The EU makes it extremely difficult to succeed even getting them to discuss something. Most ECIs attempts are striked off before they are even allowed to collect signatures. The fact that this initiative has been allowed to start collecting signatures is already a great success and means it may get somewhere.
Signature collection is certified by the German authorities (https://sign.reclaimyourface.eu/api/d/certification.pdf) and needs to follow strict data compliance rules (another hurdle).
Getting an ECI to qualify (1 million signatures or enough signatures in some countries) is very difficult, but achieving it sends a strong signal to EU leadership about what citizens worry about. Asking for your name and personal ID number is the minimum information needed to ensure the system is otherwise not abused, so that authorities can do minimal verification about the signers. Note that in the early days of ECIs, online collection was not even allowed. Authorities in each country are in charge of verifying the signatures from that country.
So please, if you are an European citizen and agree with the goals of this ECI, sign it and do something good with your data. You do not have to sign up for the newsletter or provide an email. Don't let 1 tree block the view of the forest.
If you want to read about the process and how it can be useful or useless, and what hurdles organizers need to go through, check the actual regulation: https://eur-lex.europa.eu/legal-content/en/TXT/PDF/?uri=CELE... .
(Genuine question) what difference does it actually make?
I don't mean in terms of "sending a strong signal" or "issue will be debated in Parliament", or "the Commission publishes a paper/gives a press conference/say they really care", I mean in terms of something actually changing?
> the Commission publishes a paper/gives a press conference/say they really care
That's not what the Commission does. After considering it, it can either do nothing, or introduce legislation. This would be an improvement on the current situation where it probably won't even consider it of its own initiative.
[1] https://www.europarl.europa.eu/sides/getDoc.do?pubRef=-//EP/...
All important votes are however anyway with electronic voting.
It's a pity, I support the initiative, but I fear they might get far fewer signatures as people who are willing to sign. Maybe their captcha service has decided not to support the initiative?
and if you pick for them not to email you, they try to trick you with dark pattern (all trust gone)
This website looks untested with Firefox and an ad-blocker, which really is not uncommon for people worried about privacy.
And that's not even starting about it being a European initiative for European citizens and hcaptcha being a U.S. service.
It's already bad that it want's your complete name and address. Yet another data set with me in it that will get hacked and sold at some point. And, without knowing what else it's going to demand on the second page. What if it suddenly asks for stuff I don't want to give on page 2 (copy of passport or something)? Now I have already given my name and address, and that is already in that database, so if I quit at that point I've just put my personal info in a database for nothing.
I get why they make it so hard to participate as a citizen though, the EU isn't exactly democratic.
(source: work on hCaptcha)
One of the reasons I'd wanted to remain in the EU is that, where privacy regulations are concerned, I trust the EU more than our own government.
Interactive ad billboards with a camera in them? Not much I can do about those except deface them with a sticker. CCTV? Can't do anything about that.
I'm not against security cameras per se, but I want them watched and judged by human beings, not algorithms (and ad billboards should not record me at all).
except every hotel, every flight, ever trip outside your borders... you make it sound like it's OK for your movements to be identified as long as it's outside the borders of your original country?
I've stayed in hundreds of hotels throughout the UK, and never been asked for ID. I've flown hundreds of domestic flight legs, and on the non-budget airlines (budget ones use name change fees and paid changes to tickets as a major revenue stream) I've never had to show ID, and nor is it required. Going overseas, it's only needed for entering the country (and a cursory glance from the airline to assure themselves you actually have it, due to the high penalties they're charged for a returned passenger).
I imagine therefore a lot of this is down to individual countries - in much of Europe they seem very keen to scan passports and ID documents at hotel check-in (often required by local legislation). I always felt this ironic given the (populist) view the UK is a surveillance heavy country, yet it was much of Europe that was being far more invasive in this regard in my experience.
Handing over your actual passport is not required, and the last I've heard the only places where these are actually demanded are pretty shady or just downright ignorant. I haven't had a problem handing over copies anywhere in Europe though. The hotels do need your ID's document number, and a copy suffices for this. Most only jot down the actual number and immediately hand back the copy. Rarely someone might ask to see the actual passport as proof that you have it, but I have never been requested to hand it over (and you shouldn't).
Having a "non-ID" culture is a nice thing though - in the US, people need to show ID to board even a domestic flight. Having an app to help redact ID is a nice idea, but in my view is a fairly poor solution to a non-technical problem. If you didn't insist on having these places collect ID info, you wouldn't need the app. For proof of age, that's a good scenario where you likely do need ID (today), but in future should be able to use attribute-based authentication to pove this without disclosing anything.
Biometric passports store a literal JPEG of your face, fingerprint, or iris on the chip, and it's up to the software on the entry gate/computer/phone to make the comparison between what's on your passport and your challenge. Even if both the original info on the passport and challenge data are sent to a central server for processing (or even if they are compared against the info in a centralized database), it's still being used to identify an individual. Besides that, the moment and circumstances of this identification are clear and regulated: a border crossing, a police stop, etc.
This is quite different then using a network of CCTV cameras to look for particular individuals... or keeping track of how all individuals move through an area with CCTV footage, so that you can analyze behavior (or look for individuals after at a later date).
As an initiative against mass surveillance, entering all your personnal information on a website isn't the smartest thing.
weird
with the difference that the bank is relatively trusted entity backed by shitton of formality
meanwhile crypto exchanges seems to be more shady orgs with 30 yo CEOs
This originates from what was at the time the least controversial part of the Patriot Act. If you want to be able to exchange cryptocurrencies to a Visa/Mastercard, the service needs your ID, regardless of where you're from.
If you select Netherlands they’re at least informed enough to not ask for the Dutch equivalent, the BSN. It would be against the law for them to ask, process or store it.
If you try the form for different countries, in a lot of cases they don’t ask for that particular identifier, because they legally can’t, and ask for address information instead. That’s still a little creepy, but a whole lot less.
>>"By itself it doesn’t help in that context since residents get one too."
At least in my country that's not true. The resident but not citizen number is different.
- Select the country, get redirected to the sovereign identity auth platform
- There you can log in/provide the details in the sovereign run platform.
- The sovereign run platform validates and sends out a unique anyonymized hash for the user which the platform can store to keep count.
This can be used for other validation purposes as well which are not limited to just petitions and the data returned by the platform can be scoped to the requester sort of like Oauth.
To make it even better for privacy, you can introduce the concept of an application identifier which will be unique for petition/form etc. The hash will be unique with the application identifier scope, so outside platforms can't correlate individual identity through multiple petitions.
Any idea why they would treat Poland differently? Austria, Belgium, Bulgaria all also seems to ask for a document number and not an address.
Where I'm from you never submit your national ID number (13 digit number given to each citizen once, never changes), but you do submit the "number" of your national ID (9 numbers and letters, changes when you move places or every 10 years, whichever comes first) when signing any petition.
Depending of your country they ask for different data. For instance, for Finland they ask the physical address but for Belgium only the national ID number. I suppose that there is not such number in Finland or it's illegal to ask for it.
There is a link in the form to the relevant regulation. So, the website looks legit. Of course, that doesn't mean that it's legit but my gut feeling it's that they are.
Some key facts:
- "ECI signatories: your full first and last names, country of residence and date of signature. Depending on the signatory’s nationality, we will also collect a combination of the following data: residence (street, number, postal code, city, country), date of birth, national identity document type and national identity document number." This seems to indicate that the data requested is dependant on the country you live in. So blaming the organization is a bit unfair.
- "Your data will be stored by the group of organisers for a maximum retention period of one month after the submission of the initiative to the European Commission or 21 months after the beginning of the collection period, whichever is the earlier. It might be retained beyond these time limits in the case of administrative or legal proceedings, for a maximum of one month after the date of conclusion of these proceedings." They will remove your data whatever happens.
I've signed the petition and handed over my the equivalent of PESEL. I did that because I understand that if we want to enact change we have to be more than a signature on an online form, we have to be a living breathing person and not just another email-address in a database. They can sweep gme_diamondhands_6969@whatever.com under the rug rather easily but along with data that proves that I'm a citizen that becomes much harder to do.
[1] The direct link to this ECI: https://europa.eu/citizens-initiative/initiatives/details/20...
It still does: see, e.g., the "No Profit on Pandemic EU" initiative [1]. Not sure why this one does the signature collection on its own domain, it sounds suboptimal.
It's usual to ask for addresses, at least in the UK, and if the petition is aimed at being submitted according to a legal process there may be requirements that signatories be residents or constituents.
Sure faking addresses is not much more difficult than faking names but then I suppose there's also a trade-off with complexity and cost and they also ask for ID data.
The only impact is for real people, that will have to disclose additional private information.
There isn't even a contact or birthdate field (Sweden)
anyway, this is 50/50 for me.
i can see the issues, but i can also see the positive effects.
regardless, this tech has been in use for a while now and crimes still happen, terrorism still happens etc. nothing has really changed.
but i think the big potential changes might come from being a bit more pro-active and identifying individuals with issues and providing the necessary help. for example at risk youth or anti-social behaviour. if you could pre-empt that or quickly identify the people involved then this should be a great way to make society a better place.
automatic fines when anti-social behaviour occurs via face recognition.
here’s another one: identifying individuals with potential diseases via cctv and providing pre-emptive care.
and the last one: identifying at risk youths via cctv and providing support. in real time.
the tech is not the problem. it’s how we use it.
right now we use it for ads and the occasional terrorist. but the potential for good is huge.
There'd have to be better hypothetical examples than the ones mentioned to justify this assessment. Judging by these three, the potential for good is marginal to nonexistent, and this is with no technological feasibility or cost assessment.
The huge potential for evil is obvious. Just because I'm criticizing examples, I'll come up with one: tracking suspected homosexuals and all of their contacts, in order to find more. You might say that's unfair and a thing of the past, but I'd answer Hungary and Poland.
where did i mention the police?
There is of course the fact that some police organizations will do so and try to hide it, but they will at that point be able to be punished when caught because they will not be above the law.
The Utah Highway Patrol is not placed to be above Federal law.
If the EU passes a regulation forbidding the use of biometric surveillance the Danish National Police will be very much under that regulation, in the same way that if the US government passed a law regulating highway stops of motor vehicles the Utah Highway patrol would be under that law.
There may be some EU agency that because of various things would be able to operate above the law on this issue, but not the national agencies.
the most common structural placement of your organization above the law is to have the organization investigate its own wrongdoing.
MIT repurposed a router to look through walls for people. Does that mean that 2.4 GHz routers are spycraft tools?
But yeah go ahead and check out some of these articles: https://news.ycombinator.com/item?id=22480444