Texas sues Google for collecting biometric data without consent
nytimes.com
nytimes.com
Building a local profile of faces observed on a single person’s property isn’t problematic for me. In order for the police to search it, they have to issue a very specific warrant for a specific addresses’ surveillance data. Its also anonymous by default - while you have the face, the data is local and isn’t attached to any “network” of facial recognition software. Its not being used to track people moving from house to house, or business to business, to build a “model” of their behavior to manipulate them. It’s specifically “what footage do I have locally of this face?” which can be extremely helpful when securing a home.
This is in stark contrast to what I worry companies like Google do (Facebook has been caught doing it): building shadow profiles of non-users that track behaviors across all places their face shows up (surveillance footage, personal photos of other users, etc.). This is a network of information consolidated into a single point. You have no reasonable expectation of privacy in public, but I do believe you should have a reasonable expectation that people aren’t stalking your every move across many properties and aggregating that data into a single source law enforcement can get access to with a single warrant.
> “what footage do I have locally of this face?” which can be extremely helpful when securing a home.
How? What mechanism of security is strengthened here? Almost certainly your only use case for this data is handing it over to the police to apply their facial recognition systems to it. Which they have because of homeowners like you, I guess. It's the same surveillance apparatus as in your google case except more manual and less efficient. If it shouldn't exist at all, a bad version of it also shouldn't exist.
“Alarm if any face other than these 5 are detected on an indoor camera between the hours of 10pm and 8am”
“I want to review all footage of the nanny from the past week since they spend time alone with my children”
“Show me all footage of myself inside the house in the last 15 minutes because I have no idea where I set my keys down”
“I just heard a window break at 2am, which cameras are detecting motion so my wife can avoid them to get the kids out while I do the opposite to buy them some time”
It doesn't matter whether it's a paternalistic police state or literally you, dad, sitting in the seat of the panopticon. It's bad for the psyche of everyone surveilled in this way and it shouldn't be done. The fantasy that you'll use this in an emergency is the same one gun owners use to justify their decisions, and just as likely to come true.
> The fantasy that you’ll use this in an emergency
Knowing how many people are in my home and where they are at 2am seems like information that would be extremely helpful. You’ll need to share data to backup your stance that I’m doing home security wrong. I’d love to learn how to do it better.
Let’s not derail this into a conversation about guns, we can save that disagreement for another day.
While I’m on the side of less surveillance in general, I don’t think I like this logic: it seems to me that the crucial point that distinguishes the systems of the last couple of decades from what came before is convenience. “No expectation of privacy” means very different things when someone needs to physically follow you around or even make a lucky guess as to which CCTV to look at compared to making a query from the comfort of their desk. It’s one thing for a passing cop to memorize your license plate number and then have to thumb through paper files in order to know that’s you; it’s another for them to have a full map of every car and owner name on it. (I don’t think the latter extremes are available in most countries yet, FWIW.) The bland “expectation of privacy” wording seems to miss this sliding scale of effort for a given amount of tracking.
I actually half suspect that this argument is wrong for some dumb reason I’m missing, because I don’t have a source for it (even though it seems to be in the air somehow) and even supposed experts like EFF lawyers don’t seem to be making it. But I haven’t yet found that reason.
> It’s one thing for a passing cop to memorize your license plate number and then have to thumb through paper files in order to know that’s you; it’s another for them to have a full map of every car and owner name on it.
Those are the exact same thing if you're a person who cops are following around already, memorizing your number trying to get you for any offense they can. The difference is for many people, particularly people overrepresented on HN, the police are not generally taking much interest in your routine activities and trying to use them against you. But this isn't a relationship with policing that everyone has.
All these abuses were already here, they just weren't applied to everyone. The expanding of these capabilities is what makes them devastating, you're right. But the earlier iterations weren't actually less bad, they were just less likely to be applied to us.
Counter point. My security system is not easily taken offline (resilient against cutting power for 2+ hours, cameras are all PoE, hard to find the drive storing footage, etc.). If the state enters my home COINTELPRO style, or gets the wrong house, I want footage of that encounter under my control when it’s time to go to court.
I think this line of thinking lines up well with my original comment. We shouldn’t look at this technology as an all encompassing shift towards centralization of power. There are uses that gives power back to individuals. This power is a good thing on an individual level and dangerous in aggregate.
All of my security cameras are isolated on my network. They do not exchange packets with the public internet. They can not phone home to the manufacturer.
If law enforcement has footage from my surveillance system, it’s because they have a warrant or because I willingly handed the footage over to them after someone made a bad decision on my property.
Yes, that was the assumption I had in mind while writing that.
So basically to prevent police being able to do this you have to prevent hosting non-end to end encrypted photos.
That’s a significantly reduced service capability.
Hopefully a court would reject that warrant as being too broad, but either way the compute to do this would be really expensive for any not-large company, or even a large company if they regularly get these requests.
The police have already used such geo-fenced warrants before.
https://www.theguardian.com/us-news/2021/sep/16/geofence-war...
And I get how this comment will be taken, but it would be good for all the HN libertarians to introspect and think a bit on whether they really want to get their "stronger enforcement of personal internet privacy standards" via "extended use of state power against political enemies".
Seems like both of those are slippery slopes. I know which one I personally fear more.
https://about.fb.com/news/2021/11/update-on-use-of-face-reco...
Texas police departments have also been trying to partner with camera manufacturers like Ring or Google, to access their customer records [0].
I must be missing something here, then. Either that, or this is just another political stunt directed against "big tech", while it ignores the bigger picture.
[0] https://www.dallasjustice.com/ring-cameras-and-police-survei...
Seems unlikely to apply.
1. "one-party consent" applies only to "wiretap" laws i.e. audio recording. It looks like a lot of this case is about photo and video data.
2. "one-part consent" refers to people in conversation. That definitely doesn't apply to Google here.
From what I understand, recording video or audio outside in the public where there's no reasonable expectation of privacy is a-okay.
This may put the ring cameras in an interesting position. They're attached to your home, yes, but they're looking at the public street.
In other words, I highly doubt that anyone wanting to enter my home would object to Google scanning their face, but I cannot say the same about the police collecting information on them.
It may be the stick in a carrot-and-stick negotiation for sharing that camera data with Texas LEO. A lawsuit like this can be dropped by the prosecution any old time, and there's no particular requirement that all reasons the suit was dropped be publicly stipulated.
Second, in cases like the Nest camera or Google photos, presumably most of the people it's scanning don't match anything. It sure doesn't feel like a violation of privacy or consent for a computer to say, "I tried, but nope, face/voice not recognized".
Third, everyone being recognized has previously been identified by the user, whether someone tagging their friends in Photos, family members on Nest, or household members for Assistant. If I'm OK with a friend uploading an image of me to their own Google Photos, I don't see why I shouldn't allow them to run a facial detection algorithm to organize all the photos that contain me.
Now if Google were using all of this to build up a database of all the faces in the world matched to identities (as other sketchy companies have already done), then this would all be a problem. But there's zero evidence of anything like that, and that's not what this case is about. This isn't about misusing Street View or anything.
So it's hard to see this as anything but a political stunt? What's Texas's goal here -- to remove the helpful features that alert us when a stranger (as opposed to family member) is at our door, to distinguish voices in Assistant, and find photos of a particular friend in our photo library...? These are all genuinely useful features.
This is Paxton's incompetence for those unaware:
> Six of the people indicted last year on allegations that they were involved in a scheme to force teenage girls to “exchange sexual contact for crystal methamphetamine” are now free.
[1] https://apnews.com/article/elections-texas-presidential-elec...
[2] https://www.texastribune.org/2022/09/15/ken-paxton-securitie...
[3]https://www.texastribune.org/2022/09/26/texas-attorney-gener...
Your brain isn't memorizing billions of people's faces on the scale that Google is. There's a difference. It's a false equivalency.
If Google is learning about 10-20 people per account, and that data never gets combined, then what's the problem?
Google also processes billions of people's e-mails. But they're segregated per-account. So there's no problem. What makes someone's face any different from an e-mail they send?
Again, this lawsuit is not about Google aggregating anything. It's entirely about information that users voluntarily choose to supply, that is used for features desired by those users, and that remains segregated per-account.
Doing things at scale isn't a crime. Can you point out which law google broke?
The law in question:
Whether that's relevant to the law is what the courts will have to decide.
The wider question is, if this can be avoided at all. But I think we should at least try, because this kind of data can so easily be misused and at one point in time we were already aware of that, but forgot in recent times.
It's important to point out the important difference, which is that fingerprints are considered uniquely identifying for practical purposes, and are commonly used to identify individuals by automated security mechanisms and by law enforcement, whereas faces are considered uniquely identifying for practical purposes, and are commonly used to identify individuals by automated security mechanisms and by law enforcement.
>Mr. Paxton said in a statement. “I will continue to fight Big Tech to ensure the privacy and security of all Texans.”
It's obvious pandering to the masses. This is about Mr.Paxton trying to get some attention.
Not a fan of mass surveillance, but my gut says this is the wrong person to fight this fight. His motives are questionable, and it shows in specifically targeting private business and not working to "ensure the privacy and security of all Texans" from government and law enforcement.
He targeted Google, when Amazon, Facebook, etc. are doing the same. Also, less known companies like Palantir, roam free, just because they don't have the political baggage like Google do.
Worst of all, Paxton doesn't seem to have any issues with police departments having access to Nest or Ring accounts.
https://support.google.com/photos/answer/6128838
My google photos has a "photo group" for every person I studied in college with (from a series of photos I took at a dinner with everyone present). It even has barack obama, which it recognized off a shirt a friend was wearing. I tagged none of these poeple.
Let’s say it was done without any kind of special face recognition but was done purely by some funky nearest neighbor algorithm in high dimensional space. Would you still object?
The end result is the same, grouping things by commonality on different axes, one of them being faces. If the underlying algorithm didn’t even know what faces were, would it may a difference?
No. It does not "recognize" a face. If you take a few pictures of another Google user, it won't say - "Hey, here are all the pics of John". It will just allow you to lookup all pictures that match a face. Its clustering and not recognition.
It would be great if they could actually stop Google and everyone else from doing face recognition on random people in photos without them knowing or having any way to stop it.
> Google Photos app, which allows people to search for photos they took of a particular person;
All Google Photos does is group pictures by matching faces in pics to allow you to click on a face and lookup all pictures which have that face. It does not "recognize" who the picture belongs to.
> Google’s Nest camera, which can send alerts when it recognizes (or fails to recognize) a visitor at the door;
All the processing happens on the device locally. It will only "recognize" by name if you name a face. This is a premium feature and the tagged names are wiped when you stop the premium subscription.
> voice-activated Google Assistant, which can learn to recognize up to six users’ voices to give them personalized answers to their questions.
Users have to enroll their voice to access this feature.
On the other hand, it might be the case Texas passed an ill-thought-out "Don't collect biometric data" law that makes it illegal to do anything interesting with privately-taken photographs for personal use without the express consent of every individual in every photograph.
Except they're not. They just match faces to itself and the user has to tell Google photos who it is. Google Photos isn't running faces against a database to ID people, it only matches like faces within your own albums.
I'm sure Texas law enforcement wouldn't mind if cops could operate in neighborhoods with less worry about what people's Ring cameras will show them doing.
Texas's ban is in the business and commerce code; it's a ban for the commoners but not the government. We should be looking at attempts to exercise it with suspicion and concern.
CCPA gets you a lot of the way there (indeed I suspect you can request to have Google delete all your biometric data under the "right to be forgotten" clause), but I think CCPA doesn't prevent collection/processing of data without an agreement in place as the GDPR does. (Basically, GDPR requires you to have an agreement in place before storing any of my Personal Data, since it's that agreement that then binds who you can share it with, and how. If I don't use Google, then Google can't process my biometric data. I wonder if they get around this by approximately everyone using Google in some capacity, and having a "I also agree that you can process my biometric data" term in the ToS?)
Interested in any lawyers' opinions on the above; my read of e.g. https://www.bakerlaw.com/webfiles/Privacy/2018/Articles/CCPA... is that Google cannot (i.e. would be forbidden to) do biometric recognition on people that have requested for their data to be deleted.
Where I'd like to see CCPA go further is that it doesn't strongly restrict transfers of data; under GDPR you explicitly approve a set of Processors and Sub-Processors, and must be informed when that changes. CCPA does seem to restrict sales of data, but doesn't tightly control where it is shared without sale.
I fear that all of these half-baked state privacy laws are going to force a move for overriding federal legislation, at which time the surveillance companies will lobby hard for all sorts of loopholes that effectively neuter the protections, and the totalitarian status quo will be set in stone.
It's unfortunate the Internet surveillance industry wasn't nipped in the bud 15 years ago, now Surveillance Valley is held up as a bastion of "innovation" and most of the people who should know better are happily on the take.
There are probably good parts of it that can be lifted, but it may tilt too hard in the direction of personal ownership of other people's perception of you.
In any case, we can be confident that nothing will pass at the Federal level that would make credit scores illegal.
Your assertion that the GDPR affects "personal ownership of other people's perception of you" is blatantly false. From the GDPR: "2. This Regulation does not apply to the processing of personal data: ... (c) by a natural person in the course of a purely personal or household activity". It explicitly excepts regulating personal activity, and instead focuses on commercial activity - ie companies. Companies do not have some inherent right to keep surveillance records on individuals. And this often referenced idea that company behavior is merely individual behavior scaled up is utterly fallacious, starting with the fact that companies are formed precisely to shield liability by diffusing responsibility.
And sure, the corporate lobby is extremely powerful in the US, so I agree I'm dreaming to think that any law would ever hamper the credit surveillance bureaus - they already bought their regulatory capture with the indemnifying "Fair" Credit Reporting Act. But still if we're talking about what ought to be, then a law that would allow me to opt out of their keeping surveillance records on me is sorely needed. I for one would be happy to live without them.
The consequences of malicious compliance must be considered for every law passed. That's fundamental to the process of law, because humans react to incentives and are often selfish (or at least, self-focused). There was very little carrot attached to the law and plenty of stick, so people pushing right up to the edge of what the law allows was completely anticipated.
Can't blame people with goals opposed to the law for legally bending the law to reach those goals.
I like thinking about what ought to be, but I sure get burned too often by people passing laws in that direction who haven't paid sufficient thought to what is.
Malicious compliance within the letter of the law should be anticipated, yes. But malicious noncompliance is still illegal, like these GDPR-inspired faux-consent popups. The framing of consent in the GDPR is precisely because of how the cookie law played out.
I find it curious that your nick is "shadowgovt", yet you're arguing against attempting to regulate a shadow government. Are you like a shadow government enthusiast or something?
The crux of the song is shadow governments do not exist. It's just people doing their best with the incentives before them.
FWIW you can hand wave away the existence of overt governments with the same rationale. Identifying and naming emergent structures is how we make sense of the chaos.
I didn't think this was true off the top of my head, and a quick dig supports that:
The GDPR doesn't have anything to say about cookies, aside from that they count as Personal Data. (It's quite readable, you can verify this for yourself: https://gdpr-info.eu/). GDPR is about what happens to the data you share with a company, what they are allowed to do with it, who they are allowed to share it with, what your rights to delete that data are, and what the penalties should be if they leak/misuse your data.
That outcome should have been obvious and the fact that it wasn't does not inspire confidence in the people making these laws.
So tired of governments using people as a means of attacking corporations only to not provide the people with relief. Otherwise, it needs to be criminal. But, they can't unless a specific individual is found to have broken the law, but that's what the layers of separation and plausible deniability are for.
How does any of this benefit the people?
RCW 19.375.010 (1) ... "Biometric identifier" does not include a physical or digital photograph, video or audio recording or data generated therefrom...
GDPR is great, however phone companies still collect biometic data and claim that it's "necessary" (It's not) They do so and claim it's neccessary, when it's the copy of the passport that is necessary. Additionally forcing the collection of it otherwise you can't get a phone number is not exactly consent. That's coerced.
This is the case of Telefonica in Spain (Where I went to the store and they didn't warn me but coerced me into going through this with a store rep right there) This is also the case in Sounder apartments where they want pictures of your id and of you to rent from them. https://www.sonder.com/
[1] https://www.fox26houston.com/news/nearly-28-million-licensed...
Texas did not intentionally give away their data, it was exposed due to an attack from a third-party.
Google is willfully collecting cross-referenced location, image/video, and personal profile data.
Texas did voluntarily give their data to a third-party, the insurance software company Vertafore, who then inadvertently exposed it publicly.
Anyways, where's the limit? Is it just megacorps at 1000000x the scale that can't do it? Can a tiny company do it at 10x the scale? Can I personally do it at 1x the scale?
2. This Regulation does not apply to the processing of personal data: ... (c) by a natural person in the course of a purely personal or household activity
Once something is done commercially, it inevitably scales in frequency and continuity.
(No; if anything, it'd be a job-creation program at that point. ;) )
Most of human civilization has been a pattern of small communities where everyone knew everyone. The privacy granted implicitly by anonymity is relatively new (and, I'd argue, whether it's a net benefit for society is a largely open question... A lot of harm is done by people who quietly go off the rails because nobody knows who they are).
I find that hard to believe. Teotihuacan (first example that came to mind) already had 100,000+ inhabitants around 1 to 500 CE, and according to Wikipedia it was only the sixth largest city.
Regardless, I don't see why it's particularly important what cities were like during "most of human civilization" when discussing electronic suirveilance.
There's some sense to that approach; people don't want to trust that the only thing keeping Google from doing the cross-correlation is their own corporate ethics. I ultimately think trying to ban the intake in that way is bailing the Titanic, but I think I see where they're coming from.
I have tens of thousands of photos in my google account, and thousands with my wife. Right now, google can show me photos of me and my wife. Is the idea that I'm supposed to ask for some kind of consent from my wife before I'm allowed to ask google to show me photos of me and my wife, but I can go through my account and just select photos of me and my wife?
I still won't vote for the fascist criminal but I'm glad he's finally doing his job.