TSA now wants to scan your face at security
washingtonpost.com
washingtonpost.com
1. Border crossing rules
2. Photo ID with an ID indexed to a background checked record as one of the rules
3. YOU are the one crossing the border, already declared and known, so there is no new information for authorities
By contrast, driving, taking a bus or train, or flying A to B domestically, an ID check feels like incremental "papers please".
I cannot recall if this was only for international flights. Also, I believe I've seen this in Mexico, again, outside of Global Entry.
I have to assume that this is a joke. If you speak to a manager, you'll be subjected to more bureaucratic abuse and risk missing your flight, just to have your concerns dismissed because there is no enforcement mechanism.
It's very hard for me to imagine not being outraged that the government is tracking you even more because you want to seem smarter than randos on the Internet.
Even within the framework of "reasonable expectation of privacy," the test outlined in Katz v. US leaves no room for the concept that an expectation will ever truly be "settled." To show a reasonable expectation of privacy, an one must demonstrate an individual, subjective expectation of privacy, and also that this expectation is something society would find reasonable.
So gee, does society find it reasonable to expect that you can walk through an airport without having your photo taken and analyzed by the government, and possibly stored in a database where it can be abused by internal or external actors? Viewed in the context of past behavior, perhaps not. Viewed in the context of a government that is suspicious of big tech surveillance even as it collects ever-more data on its citizens, and jurisdictions like the EU passing ever-tighter regulations like GDPR to safeguard privacy, then maybe society's expectations of privacy have shifted compared to where they were in the 2000s/2010s.
The US government is acting within well-established legal guardrails if they were to carry out the same tasks in a highly manual fashion. If it carries out the same tasks in an automated manner, the substantial legal issues remain exactly the same: there's a change in efficiency, an increase in data capture, and improved accessibility to authorized parties, but the fundamental act of capturing images, cross referencing them to a database of known persons, and logging movement activities remain basically unchanged. I don't see how you could argue that this harms the notion of privacy in itself any worse than it already was already being harmed, and I don't see how one could construct a sound legal argument that the introduction of automation itself somehow introduces additional damages.
It's simply a bad faith argument to compare a detective watching a single individual to every single person in a large international airport, because one must have a causal justification for their actions while the second simply performs it's programming, endlessly.
If we're going to become endlessly surveilled and tracked, we as a society should at least has the smallest bit of dignity and complain about it. If we all let our privacy be eroded so tacitly, we go down like dogs.
We also don't really know where the resulting data is stored, or who will have access to it, or which people will abuse this information in the future, whether they are corrupt officials or third-parties who steal the stockpiled data, or what creative applications they will find for that data, or what harm the general public will ultimately suffer. These were good what-if questions on Slashdot in the 90s, but after decades of tech growth and abuse in the public and private sectors, these are now important ethical concerns that must be addressed in order to safely allow government security services to automate more and more of their jobs.
How is it more difficult to audit when software is involved? If anything, it makes the possibility of immutable audit logging and rule-based alerts for potential misuse much easier to implement than with manual processes. There's a reason that high levels of automation (and associated software-enable audit capabilities) are strongly preferred in regulated business functions (e.g. financial reporting).
Further, the fact that the general public might not know how data is stored or its access is controlled doesn't prove the point that these things aren't being addressed adequately by institutional controls. In any case, that's a matter of governance that has no link the the fundamental legal questions concerning privacy that you've brought up.
If the government says “we’re not using this checkpoint stuff to spy on you or anything nefarious like that, and we’re definitely not putting together a massive database of the IDs and photos of people going through our checkpoints” I have to take them at their word because national security gets broad carve outs from transparency tools like FOIA.
Their word is historically not worth much. Government leaks data all the time. It is actually still not that great at security controls in a practical sense, at least insofar as deterring major breaches of privacy is concerned. That’s why LOVEINT happens. That’s why TSA went and posted a picture of the master key that unlocks all those stupid approved locks on the Internet. That’s why stuff like the OPM breach happen. All of this is stuff that isn’t SUPPOSED to happen, but does, regularly, because in reality government (like everyone else) has little ability to control what will happen to information once it ingests it.
And that’s just the dangerous stuff that happens without any intent on the government’s part. Whether they’re misleading Congress about the scope of warrantless wiretapping, wildly understating the implications of metadata analysis, or sabotaging cryptography by purposefully advancing backdoored algorithms, or just plain wiretapping political activists without cause to wage campaigns of legal harassment, the various agencies of the USG have a time-honored history of outright lies where privacy is concerned. So no, unfortunately, even if there exist “institutional controls” that could solve these issues in theory, we can safely say they definitely have not been implemented.
These issues are extremely relevant to your right to privacy, because rights are a balance of interests. If the government gets this big new way to abuse people, then they need big new protections against that, or they are going to get abused. Our concept of privacy has to be bigger now than it was when automated surveillance wasn’t a thing, because the stakes went up. By a lot.
Everything you say (and present) can and will be used against you.
Your exact appearance will be scrutinized possibly even years later in a way that no TSA agent could possibly remember, if someone decides to accuse you of a crime that involves transport like trafficking. "On such a such a date, our expert witness looked at the TSA photograph and nervousness detection program and the AI detected they were anxious and possibly intoxicated when passing through TSA. Your honor, this nervous and intoxicated behavior was detected by TSA computers on X Y Z and A B C dates as well. Our analysis shows traffickers disproportionately exhibited this behavior, which was listed as supporting evidence on the search warrant affadivit 6 months ago after which a roach was discovered in the defendants ash tray..."
Do they already do this elsewhere, e.g. with Global Entry? Sure.
https://www.tsa.gov/travel/security-screening/credential-aut...
I know, this is some kind of privacy intrusion but if you are traveling by plane, you have already no privacy left anyway.
And the fact that privacy is currently a gone thing in air travel doesn't mean we should keep adding tech that cements the status quo, we could also move back to more privacy-conscious options of course. It's badly needed IMO.
A photograph of your face at the pharmacy or post office taken for your passport is pretty much useless as that sort of evidence as it doesn't show your demeanor at the border.
They may not get a conviction but a warrant or arrest will turn your life upside down for at least a few days. And they can get that based on basically nothing (I read the affadavit of my warrant and the claim was 3rd degree anonymous hearsay that didn't list the officer or the dogs name).
I am still in debt to this day as debt collectors are chasing me after DHS billed me for their search made on the kind of shoddy "evidence" they obtain from any electronic and other device they have. Every tool they obtain just makes it worse.
My story is very similar to this Ashley Cervantes who was also taken to Holy Cross Hospital and billed for a search [0, 1], except in my case they got a warrant which was signed by the judge AFTER (MOST OF) THE SEARCH.
Like Ashley, nothing was found and I was billed afterwards. Ashley's case was even more shocking as she was forcibly and intimately penetrated by the doctor "in search of contraband" at the direction of DHS.
In my case DHS promised me they would bill it in their name, but they either lied or used the billing as a retaliatory tactic when I convinced (some) of the doctors to discharge me as the doctors had no medical basis on which to search me without consent. The bill itself was written by the private medical entities performing the search at direction of DHS.
[0] https://tucson.com/news/local/border/woman-sues-customs-over...
[1] https://storage.courtlistener.com/recap/gov.uscourts.azd.985...