[London Riots] Help work out how to do facial recognition on the police photos
groups.google.com
groups.google.com
A college friend of mine got charged with inciting a riot by standing on a car and shouting "Don't burn our hood! Go burn some rich folks stuff! Follow me!" According to him they didn't trash his stuff, and that was worth the hassle with the courts.
If your shop or car got torched or your kids are afraid at night, this is probably a great idea. Leveraging public data (photos) and off the shelf technology to at least identify witnesses if not actual participants should be done. If a friend of mine was in that situation and asked for help, I would do everything I could. If a company asked me to consult on designing the solution they could sell, I would probably pass.
I've been working in security, identity and privacy for over a decade and this "ethical" question has loomed since before Orwell. Commercial packages are marketed to law enforcement, today. Instead of disengaging or blindly sending your leads to police, the ethical middle path is a publicly defined framework. Using the riots as the catalyst, there should be public/web/community effort for vetting the most incriminating images, aimed at shaping the rules of public disclosure, law and evidence around facial recognition.
If this makes you queasy, get engaged. Saying "that's bad" or "they're wrong" won't stop those driving the technology solutions forward. Advocacy can keep the situation a little more honest.
The police cannot use these methods, I believe, so if the public can do it for them to help narrow down inquiries, then surely that's a good thing.
I think it's important to point out that a system like this would be to close the net, not to be used as evidence.
Help your neighbours, not the police, then shit like this wouldn't happen. People are so ready to delegate responsibility for everything to technology and a "higher authority" that they forget their own moral responsibility.
As for using it to identify people for questioning, it is strictly against the DPA to collect this information privately without consent and supply it to the police without a data controller and disclosure policy.
You're effectively saying that we shouldn't bother to help bring people to justice.
Also, I would love to see further information about what you say about the DPA (any links?). We're not wanting to bend the law here, we want to work legally. If it turns out that this kind of work is completely unfesable by the law then we will be forced to abandon it.
Please don't turn this into a moral debate between you and myself, I appreciate that not everyone will see the use of technology in this way as a good thing. At the end of the day I'm trying to do something to help here, rather than moan and argue online about it.
Read this thoroughly, then register as a data controller:
http://www.ico.gov.uk/for_organisations/data_protection/the_...
You will be recording and maintaining a database of individual details. You need to provide access to this under DPA SAR regulations to individuals. If you misrepresent the individual, you can and probably will be sued.
Sometimes, doing nothing is better than doing something bad or dangerous.
Oh and if I find out this is going ahead, I'll be ethically required to report you to the ICO.
1. This will be misused.
2. But someone else will do it if you don't.
3. Okay I'll do it then.
Technology is not the solution - it's part of the cause. Everyone is automatically incriminated. Don't add fuel to the fire.
Nothing here compromises your privacy, and nothing will artificially incriminate you. Everything is already public information.
A system like this would be exactly the same as photos being released to the public by the police (which they have), and then random people ringing up saying "That person might be XYZ" (which also happens).
This would be a simple automation of the process to help filter down who it could potentially be (none of the results would be public). It would be up to the police to work out who should be pursued.
Also, I entirely disagree with your statement that technology is the cause. Riots happened before the Internet and social networks. People would be using phones, radio, and word-of-mouth anyway.
We need to stop being afraid of the potential uses of technology, we'll never get anywhere that way. Also, I am not claiming that this is a) the right solution, or b) socially acceptable just yet.
We need to tackle those issues, rather than turn away from the technology because of potential futures.
However, I also think it's important to note that I am not a lawyer in privacy. I am a developer who wants to help out. I'll leave the legality and policy behind privacy to the professionals.
At the end of the day I would have absolutely no problem with my publicly accessible profile image being used in facial recognition in these circumstances. Imagine if I was a potential witness of something? Is it then OK to use facial recognition in that case?
And what else than "potential witness" will you identify? None of these pictures could be used as evidence.