Facial recognition technology: How to opt out at the airport
cntraveler.com
cntraveler.com
I recently showed[1] to my daughter (10) as teaching her python, how easy it is to build some basic facial recognition using modern libraries and models.
I had it running with one of her pictures, and i just asked her to come in front of the computer for a second to check something out, and she was completely shocked when the video put her name below her face, and my name below my face. She was shocked, a bit curious, and a bit revolted.
On the next day when I took her to school, I just showed the amount of cameras on the way, and in the mall. At first she thought that its not an issue, as every camera only sees locally around it, so they cant connect her journey, but then she realised someone can own many cameras.
I think we need to invest much more into adversarial machine learning[2] and possibly form some sort of organization to fund it. (I hope it will be called move-78 as Lee Sedol's hand of god move against alpha go)
[1]: https://github.com/jackdoe/programming-for-kids/blob/master/...
Or that the cameras are insecure, effectively public, and a motivated person or state could do the same.
https://www.theatlantic.com/technology/archive/2014/07/makeu...
its a screenshot of detecting me despite the paint, and i tried whole bunch of colors and etc to trick it that my eyes are not where they are, and it did not work, I think it was easier in 2014, seems you really need to hide your eyes now, and its gonna be quite annoying for bald people like me haha
anyway, i updated the book as well, with the link
thanks!
Covid masking with sunglasses and a cap make someone effectively anonymous.
Masks are a big finger to the NSA.
https://github.com/jackdoe/programming-for-kids/blob/master/...
and glasses + mask as well
https://github.com/jackdoe/programming-for-kids/blob/master/...
and this is https://github.com/ageitgey/face_recognition completely out of the box, no tuning or anything, just copy pasted the example
Start talking 100 million faces + public cameras and it’s difficult. Where AI really stands out it having a specific face and looking for that in days of video footage. But, even then you want to train for false positives.
That just becomes an ever-escalating arms race. We need to invest in political and social systems that regulate the use of technology, not imagine that we'll overcome the dystopian use of technology by applying yet more technology.
as political changes are incredibly slow, in the meantime we need to make it harder to collect
you know very well no data will be deleted, in the modern 'data is money' mode of operation
its not even on purpose, its just hard to delete from petabytes of hadoop garbage
Encryption, for example. It denies the government information, evidence. There's nothing it can do about that. So will it criminalize encryption itself? Will it presume guilt if you refuse to decrypt? Will it ban free computers that run software not signed by the government?
After enough iterations, we'll either end up with an uncontrollable population wielding ubiquitous subversive technology, or an omnipotent totalitarian state that defeats any attempt at subversion before they can develop.
I hope for everyone's sake that the governments will discover their own limits before either outcome.
"Reamde" has multiple cool ideas (the miasma, basically our dystopian internet information sphere we live in today), but one of them is people walking down the street with glasses that have some kind of light device that shines on your face to confuse facial recognition.
look what we have built
this is the internet we made
for our children
I remember in early 2000s how I used to download some programs[1] to pay me to watch ads. I didn't pay content creators anything, didnt donate, I didnt have money, but I could've spared some.
I just didn't do anything to stop it.
It is pointless to argue about legislation at this point. We have to assume governments and corporations will have this data. The only mitigation is to limit the overall power of governments and corporations.
We need to build an expectation of public privacy concept where everyone has the right to go about their public lives with only human levels of tracking, recognition, and memories. That is being seen and remembered a short while is acceptable, having every move recorded and attributed to me is not.
This is an oversimplification of a complicated story, but a great example is when the NSA stopped doing mass phone / text analysis because of the additional regulatory burdens imposed by the USA Freedom Act. The NSA contends that the data is still useful, but also that the difficulties of complying with the law make it not worth it.
How could I, as a private citizen or owner of a property be prevented from selling photos/videos with timestamps and geostamps?
How could a company be prevented from buying and aggregating that data (even in other jurisdictions)?
How could an end user be prevented from buying aggregated data as the cost plummets?
Do you really think the NSA is not buying all available data sets?
If your goal is to restrict the transfer of some other kind of data, copyright is already a legal and practical framework that had tackled the same problems, and offers solutions.
The government has pretty wide reaching powers.
The same people who sold browsing data to advertisers have this technology.
Most ideal: make personal data a massive business liability, such that personal data is rarely even collected, let alone stored. This is much more possible than people believe (even making exceptions for current regulations like KYC). Does the local pizza place need to know anything more than my order, where to deliver it, and that the money arrived in their account?‡ Does a hotel or airline need anything other than a confirmation code to hand over the room key or seat? And yes, this may kill off or force pivots from businesses that exist today solely to spy on us—that's the point!
Only okay: personal data isn't shared or sold to third parties. Businesses can collect data on their own users, but it can't leak beyond the corp firewall or else big penalties come into play. Only okay because leaks are almost mathematically inevitable, so there will be constant lobby pressure to relax regulations, or enforcement thereof.
Not good: personal data can be collected, retained, and sold by basically all companies, and the penalties for unintentionally disclosing those data are just slaps on the wrist. At least it can't get much worse though, right? Right??
Businesses will adapt to any set of regulations—it's up to us citizens to demand the laws we want.
‡But what about remembering your favorite orders, or saving customers time by not entering their info for each new order? One options is to let them bookmark the page, so their device can get back to it easily.
We saw how eager people were to install Google Analytics on their websites. They don't care what they do to their users.
Of course finding the political will to restrict things like security cameras is a different matter, but I don't think it'd it'd case that we couldn't write effective laws to prevent this.
You would make it a crime to violate the rules but administered like and possible to sue in civil court for victims. The crime would be on the owner/operator of the camera and special provisions would be added for storage providers.
Yes, we can imagine some set of laws that would make the aggregation impossible. I don't see how they could be effectively created and enforced.
What bunker do you live in?
Because of this, the current battles that many anti-surveillance activists are fighting is in procurement and vendor/contractor policies, mostly at the city and county levels. Lots of West Coast cities and counties (Santa Clara, Oakland, Seattle, San Diego) have enacted all kinds of new bureaucratic hurdles on any public funds used to pay for surveillance. These include requiring RFPs with open competitive bidding, public hearings, testing and certification that it actually works with an acceptable false positive rate, and approval in a public vote by the city/county council.
The Nation has a good overview of this shift in tactics, which is also opposed by some progressives who take a more abolitionist stance to surveillance and say that they don't want it to be legitimized if it passes all the bureaucratic hurtles: https://www.thenation.com/article/archive/mass-surveillance-...
Imagine this possible near future: Many property owners have installed smart doorbells and security systems with cameras. The data is being fed into aggregation systems and sold, just like clicks today. I can subscribe to an app on my phone for a few dollars a month (below the limit required to get formal approval in most organizations) that shows me where a face has been seen.
How will this not happen?
If a police officer can look up a suspect on Facebook, why couldn't he use one of many other services that are aggregating data?
Anyone can personally purchase whatever they desire.
A single man can record videos yes, but they can't record millions of videos and aggregate them into a searchable database. For that you need larger groups of people and a significant amount of infrastructure. You could absolutely limit the ability to do this without having to outlaw cameras or social media or anything like that.
Are you making some blanket assumption that laws can't have an impact on private businesses? Because that's clearly not true.
Databases of aggregated ALPR data exist and have economic value. Facebook exists and aggregates data. Can you elaborate on what kind of law you think should exist to prevent that?
Most laws depend on the concept of intent already so its not like you would have to outlaw security cameras or anything to enforce.
Do you have any good links that provide more info on this?
Why is this the only mitigation?
By the way, who is going to limit the overall power and who is going to limit the power of those limiting the power and why? :)
At the end of the day it's people making decisions. The best way to have them making better decisions, is having more of them having a view of the world that reflects reality.
More reality, less bullshit -> better outcomes. Pretty simple.
I don't like the surveillance state, in particular the ubiquity of cameras in public open spaces where there's no compelling reason. I don't like the networks of private cameras people have attached to their front doors, all fed to Amazon and Google (and the state, most likely). If we're going to have cameras anywhere, though, the airport is the place I have the least problem with.
We're way past opting out, whatever that even means in this scenario.
Random surveillance video in an airport probably can't be used to update records because you have lower confidence of a match absent the other known factor that confirms ID. Moreover, masks/face covering is a norm that will also help subvert ambient face ID and model updating.
The data won't stay in the airport—the updated id-face model will be used in places where we expect or should expect more privacy of identity.
We as a society could decide to limit the legality of this. As individuals we can opt out and likely make a small but meaningful difference in the recency and fidelity of our collected and shared biometric data.
You say, "I don't like the surveillance state, in particular the ubiquity of cameras in public open spaces where there's no compelling reason." You are assuming there is no compelling reason because you do not personally know what that reason may be. Someone, somewhere, thought they had a compelling reason to go through the expense and hassle of developing and installing the surveillance system. It wasn't just "IDK, it's kinda neat".
It's clear from the gaping, empty space between our understanding of these systems and the desire of institutions to have them that something must be filling it. Whatever that "it" is should not be hidden from the public and communicated clearly, and not just hidden in a TOS-like document locked in a room with a tiger in the basement.
Most of the airport security theater is voluntary. Full body scans are also voluntary. Most soy boiz are too lazy to opt out.
A lot of defeatism in this thread but I for one will opt out, just like the body scanners.
Will this become a great way for camera shy people to pollute any paparazzi shots of them?
Anyway was just a thought experiment on how to automatically opt out while “sticking it to the man”, so to speak. Maybe I should look into EUrion constellation marks instead!
As always
While I would have preferred a non-biometric approach for everyone, I'm hoping that moving some of the burden to exit control 1. lessens the workload of immigration enforcement domestically, and 2. encourages a very slow transition towards more seamless international transfers given that US airports usually weren't built for this, although a lot more work would be needed here.
That said, I think it’s mostly just “we can check if needed” and it’s not matched up automatically though that might have changed? I know if you’re an immigrant and you check your I-94 record with USCIS is usually wrong and missing data.
This is always what gets me: people will willingly walk into their own demise. I just don't get it, it's quite depressing frankly
Others critical points are at the temperature scanning at the entrance and at the passport check. I don’t think you can avoid those.
Of the few options we have, one is normalizing wearing recognition-scrambling makeup/masks. Another would be to get stickers of eyes, brows, and noses, and place them in random places around your face.
It'd be interesting to see some studies of the effectiveness of the different methods.
We're looking at the wrong end of the problem. We need to limit what consequences can come from being recognized. Like an "you can only be hassled once a year" policy for cops.
Meanwhile, watch the Hikvision Corporate Channel and get over it.[1]
In some of Asimov's science fiction mystery short stories there was something like this [1]. Police had technology called a "psycho-probe" that could essentially read your mind, with a slight risk that doing so would cause permanent severe brain damage. Because of this risk the law was that a person could only be probed once.
That had some interesting consequences.
First, if someone who had never been probed was tried for a serious crime juries were reluctant to convict.
Second, a lot of criminals tried to get charged with crimes serious enough to get probed. Confess to a crime you didn't do in hopes of getting probed, cleared, and gaining immunity from probing for any future crimes you do. Even if you actually have to do a serious crime to get probed, it could be worth it to do so and serve your time to get that immunity for when you resume your criminal career when you get out.
[1] Definitely in at least one of the "Wendell Urth" mysteries collected in "Asimov's Mysteries" [2]. I'm sure probing is a big part of "The Singing Bell" and I think it was at least mentioned in "The Dying Night".
What's left is to create a culture where the abuse of surveillance is heavily stigmatized. There are a lot of laws that could be passed to minimize the time that data is stored and how it is shared. The government is the only entity with the power to make rules to stop this, and the government is the entity that controls the spy agencies (who are the most frightening abusers of surveillance power) and could reign them in. But privacy advocates are almost always maximally skeptical of government power so they reject out of hand to work "in the system" as it were, to make changes.
Hint: I'm talking about 5G and its big surveillance application, an open secret.
Edit: Forgot to mention this was pretty crude 10 years ago. I'm assuming op is talking about a practical application for something similar.
"Device free", "localization", "identification" and "mm wave antenna arrays" are some useful keywords for checking this stuff out on Google scholar. Some other alternatives for "device free" are "passive" and "adversarial". I think I remember one paper where they were identifying dozens of people at once with like 95%+ accuracy. I could be getting the details wrong on that one but it was along those lines.
For the high level overview though, you can just read the 5G industry whitepapers and it pretty clearly spells out that there are privacy implications and I'm sure that these kinds of applications are exactly why.
Remember, higher frequency = more information density = finer resolution. Which is also why these radio waves can't travel through as much stuff... They simply interact with more; more stuff is opaque to them, and as such they carry information about more interactions in their image.
https://www.google.com/search?gs_ssp=eJzj4tTP1TcwNirOiTdg9BJ...
in the US*
I thought this might be some China thing since the domain is cntraveler, or indeed a US thing since it seems also in line with both HN and the kind of stuff US airports do, but the title isn't quite clear so one has to click...
I've been fortunate in being able to avoid flying for years now.