White Castle collecting burger slingers' fingerprints looks like a $17B mistake
theregister.com
theregister.com
Which begs the question, if they asked and an employee said “no”, what happens? Are they fired? Banned from register work?
If an actual alternative has to be provided, that's a very sensible law. Biometrics can't be revoked, and every use puts them at risk, so making sure people aren't forced to let employers collect their biometrics is a good idea.
Edit: If I read it right, the "consent" is required in the pure paperwork sense, unfortunately. That means for employees it only prevents biometrics from being used covertly.
However, it still has value for non-employees, and the "written" aspect is particularly important here. A supermarket for example can't use biometrics to track people for advertising or theft protection purposes, because they'd first need to stop them at the entrance so they can sign a waiver. No cheating out of it with a small sticker "by entering these premises, you consent" in some corner.
This is like no-competes or binding arbitration agreements. If you decline to sign, your rights were honored, and you're free to find a job elsewhere.
At this point, what choice did I have?
The title insurance company was chosen by the buyer.
Illinois also prohibits employment discrimination based on opting out.
There are numerous vendors offering an Illinois-compliant fingerprint timekeeping system. That’s what’s so crazy about this.
You don't impose the death penalty for stealing an orange.
With corporations the point of a penalty is to deter, not destroy.
If White Castle goes out of business and thousands of people lose their jobs, how is that good for society?
Justice requires proportionality.
I agree it wouldn't be fair to White Castle if they were destroyed over this. But I'm not so sure it's particularly unfair when counted on the "workers vs corporations" scoreboard, or the one for "privacy vs exploitation".
I don't know if this actually the point like you suggest, but why do you believe this should be the point?
Original shareholders lose all their money, as the shares are deemed worthless (debt>>assets). Then new investors want to buy the remaining assets and have to pay the government (or other debt-holders) back for the debts (or the “fair market value” of the assets).
There is no guarantee that this process with oust management, but the new owners may not believe in the ability of the old management after they bankrupted a company. Realistically, companies sometimes go into chapter 11 knowing it’s not the end just to restructure debt.
Why would they lose their job? White Castle would declare bankruptcy, someone else will buy physical properties and equipment, and I would assume open a new restaurant(s) there.
PG&E is in an even tougher bind because the fix (burying the lines) might be prohibitively expensive.
The reality is "use of workers' fingerprints to access pay stubs and company computers". So it set up a fingerprint reader much like the one I use to unlock my MacBook, or sign in at my doctor's office, or open the turnstile at my gym.
I understand that according to Illinois state law this is illegal without consent, and so legally they missed having employees sign a form. But morally/ethically is there really any problem with this? This is just how iPhones and MacBooks work, for example. Really seems like perhaps Illionis state law needs to be updated to reflect the widespread use of fingerprint readers for authentication on computers, tablets and phones.
Reading the bill it even points this out.
Biometrics are unlike other unique identifiers that are used to access finances or other sensitive information. For example, social security numbers, when compromised, can be changed. Biometrics, however, are biologically unique to the individual; therefore, once compromised, the individual has no recourse, is at heightened risk for identity theft, and is likely to withdraw from biometric-facilitated transactions.
Also I don't see how compromising that hash is a problem in practice, if that ever happened. If it's salted it's worthless, but even if not, I don't know how you'd reasonably physically use it to hack into another fingerprint reader anyways.
When it comes to fingerprints you must assume that the attacker has the ability to control the scene and the ability to retry until successful.
The point is that reader has those preserved and stored somewhere, while fingerprints that a person just leaves about by going about their day are not. Just the fact that they are stored is an issue. Note, this is a response to the original question of 'pfft, a person leaves fingerprints all the time anyway'.
Again, the comparison is just not apt.
nb iPhone Face ID has additional protections, like each scanner using a different random physical pattern so hashes can't even be transferred across devices.
In other words, I am willing to buy an argument that Apple's implementation is better than some other implementations out there, but it does not apply to this case, because it was not Apple's Face ID that we are discussing.
Every month or so there's another horror story on HN about some company storing passwords as plain text.
Just because something can be done right does not mean it is done right.
https://www.theverge.com/2015/8/10/9126027/htc-fingerprint-s...
Similarly, a vendor of facility access control systems left fingerprint scans in an exposed ElasticSearch instance:
If an attacker had a fingerprint and wanted to figure out who it belonged to, they could hash it and compare the hash against a database of leaked names and hashes. Salting doesn't prevent this, unless the hash is intentionally slow, in which case the attacker would merely be slowed down.
Also, how much entropy is in a fingerprint anyways? If it's low, an attacker could generate every possible fingerprint and hash it to build a mapping from hash to actual fingerprint.
Since humans only get one set of fingerprints for life, fingerprints should only be stored and compared on secure enclaves on your own devices (like iPhones). It's way too risky otherwise.
This exactly!! QFT!
No biometrics should ever be used for shared or public devices! Biometrics are fine for personal devices that are always with us, and not shared by others, especially anyone outside our family/household.
I've made my peace with biometrics as far as unlocking my phone via fingerprint. My threat model is such that a fingerprint lock is often safer than pecking in a long password. (Because I'm often surrounded by shoulder surfers.)
So yeah, if a restaurant is forcing employees to scan fingerprints (or retinas or DNA or saliva or what have you) on public or shared devices for purposes of clocking in, or payroll, or whatever, then that is wrong and a perversion of biometric authentication. The company would be much better served by a correct application of security techniques.
And yes, if this means going back to passwords for awhile, then so be it. Passwords are a good first-line auth measure for shared devices that are not open to the public (let's assume that this restaurant's devices were only physically accessible by employees in the back office or something.)
Another idea is to let the employees authenticate using their smartphone. My bank has something set up with this. You install a smartphone app, it authenticates you, and it vouches when you set foot in the bank so that the teller already has your account pulled up. Then, in terms of biometric locking for the smartphone, knock yourself out; the company has no need to collect the data, just interface to an app.
You essentially have N different hashes and require at least N - M (M < N) matches.
Presumably they would have checked if their policy was legal before implementing it too. The problem is that they haven't really earned the presumption of diligence in this matter.
This feels like pearl clutching to me. While it's probably technically true that having your fingerprint leaked increases your risk of identity theft by some non-zero amount, in the overwhelming majority of the cases it's effectively zero, because for the overwhelming majority of people the only place they have their fingerprints enrolled is on their phones. In the event you somehow acquire stolen fingerprint image data, it will be very difficult to use those to perform identity theft at mass scale, because you need physical access to phones.
>and is likely to withdraw from biometric-facilitated transactions.
What "biometric-facilitated transactions" are these? Aside from fingerprint unlock on phones, I'm struggling to come up with cases where fingerprints are used to secure sensitive information.
I don’t think this happens a lot.
Note: I don't actually recommend you do this - it opens you up to the very real dangers which you're claiming don't exist.
Very easy. Though, it's more difficult to get a specific person's fingerprints. Frankly, this is a terrible argument. Fingerprints require an escalation from the digital world to the physical.
Physical security keys are great for exactly this reason. If you want my account, you must break into my home. That fundamentally changes an attacker's calculus.
“The building isn’t on fire currently so there’s no need to move the gas can away from the fireplace.” Isn’t a compelling argument.
Phones have become people's defacto computing device, that they link to all kinds of personal, private, and governmental accounts. Medicare, councils, state accounts, bank details, taxes, private chats, private images and videos, work accounts, work documents, work chats, group memberships, on and on. Think of any sensitive information possible, someone is storing it on their phone. Most people have their phone as the center of their information technology worlds.
If access to that isn't concerning then there isn't much else that could change your mind I don't think.
Those people are foolish. Putting all your eggs in one basket and then whining about the consequences is a sign of bad character. Besides that it’s pretty irrelevant to the topic at hand, which is whether fingerprint readers are an acceptable means of securing digital transactions. In fact you seem to be suggesting they are, by proxy.
Since everyone has a phone now, that means technologically illiterate people are using them for whatever their authority figures tell them to. They trust those entities, and perhaps they shouldn't, but that is the reality. Any policy that doesn't cater for the reality is bad policy.
Smoking is a historical example, at one point doctors, movie stars and media all told you smoking was good for you. Now, decades later, health policy has to take into account that people smoke. Maybe one day down the line there will be regulation on companies as to how they influence people to use their devices, but for now we accept that people put sensitive info on their phones.
1. Biometrics can't be revoked, so if your gym leaks your fingerprint images (linked to your name), that's a mistake that in practice simply cannot be fixed. You just can't use that finger for sensitive biometrics ever again. People should not be forced to take the risk.
2. It's hard to distinguish between biometric surveillance and "good" uses of biometrics, and they can fluently blend into each other. The law draws a rather clear line and has to enforce it.
Should a company be allowed to use biometrics to make sure you don't let your brother sub in for you? Preventing fraud like that is a noble goal, but how far do we want to allow pervasive biometric surveillance to go? Should stadium owners be allowed to ban people? Should they be allowed to ban all employees of a law firm they don't like? Should they be allowed to surveil everyone's faces with a biometric system for this purpose?
The lines between "perfectly reasonable" to "Black Mirror dystopia" are fluent, and the way there consists of many steps that individually seem reasonable (preventing crime is good, right?) and yet the outcome is something we don't want. This is why the law exists, this is why it also hits some "legitimate" uses, and this is why consent (if implemented meaningfully, in the voluntary, GDPR style sense, not in the "you have to sign here or you will be excluded from normal life" sense) is such a powerful tool: It generally lets the harmless stuff happen and prevents the dystopia.
Fingerprint scanner systems don’t store photos of your fingerprint. They store information that can be used to match against your fingerprint within their own system, but they can’t be used to reconstruct your fingerprint.
Regardless fingerprints are really bad for security because they can be detached from the finger or recreated from things you touch. They are probably slightly better than nothing, but with such low resolution, I suspect that if we let 100 random people try to unlock my laptop with their finger... someone would get in... but I could be wrong.
For identifying a fast food worker at a cash register, they are (functionally, not legally or morally) a good fit for the problem, because they are hard for a coworker to replicate, and not likely to lose. For applications in which you need to protect against high skilled attackers, they're not as great.
b) what they actually store varies, and I'm sure some systems do just store the picture (your passport does, for example), some likely don't store it in the database but happen to have a temp folder somewhere with everything they scanned, and some claim they don't store it and then store it under advanced military-grade 512 bit RSA encryption with the key stored next to the images.
The software quality of biometrics systems is among the worst I've seen. Worse even than embedded/IOT stuff.
Do you have an example of this happening?
My right index and left ring finger are similar enough in their prints that either will work for the device.
It's optional on the devices you mention. It's not a requirement. In the court case, there was no way for an employee to opt out, short of quitting.
My company (about 2,000 employees) issues iPhones to its employees. You are given a choice of face scanning or fingerprint scanning device. You do not have to use either method: you can choose a suitably long PIN, instead.
If you choose to use biometric access, HR send your a 15-page document to sign, and you have to take an online course about biometric privacy.
I think if more companies did that, society wouldn't be so casual with giving away their biometric data.
Sounds like legal has experience with this issue.
Fast food sign-in is the perfect low-stakes use of fingerprints. There's some real baggage from when they were harder to gather and how they're used in law enforcement as to why they're considered sensitive, but they're really not. Getting the law and society to agree will take some time, though, and there's a ton of reactionary forces trying to hype up the threat.
In public, biometric auth is better than passcode auth for this reason, because other people (or security cameras) can watch you enter a passcode on your phone.
Besides, fingerprints can be changed. With a blowtorch.
All three indicates a type of person that should be protected from random idiocy of an employer. It is not often that I praise IL for anything, but the biometric law is one of those few instances.
They constantly tell me to simply things because “these guys aren’t very smart”.
To the point that (on top of other problems) they’re creating foolishly simple logins…
I thought about finger print reading but the legal questions make me second guess it.
I see how it's convenient but personally I wouldn't use biometrics here, sounds like an obvious avenue to get your biometrics leaked.
MacOS unlocking is different like others have pointed out already.
It doesn't even take a billion in revenue a year.
White Castle isn't Google or Facebook. It's a relatively minor burger chain.
The IT person who decided to adopt it would have needed it to occur to them to check with legal. And I can imagine that for most people it wouldn't occur to them. Any more than you'd think to check with legal about whether a password should require at least one punctuation character.
I'm not defending White Castle here but neither do I think it's anywhere close to "reckless". I think it was just a normal day to day IT decision that nobody thought anything of.
In other words, there was probably no criminal intent here nor recklessness. Just ignorance of a relatively unknown statute, that sure you should pay a reasonable fine for. Not a big deal.
No law is truly obscure anyways. because they’re all written down for your corporate lawyers to check when you start business. White Castle operates in many states with over 100 years of corporate history. The idea that they couldn’t be bothered to check the laws of all the states they operate in before making changes is not only foolish but if true illustrates a greater sense of recklessness. If you operate in Illinois, you should check the laws in Illinois.
Like I said, an IT guy decides to install fingerprint access for computer access for franchises nationwide. They're not an expert on biometric security, they just thought it was a good idea.
As laws go, this one is not exactly common knowledge. Even corporate lawyers in a state aren't aware of every statute in every area of law -- they have specific areas of expertise. Hiring a biometric security lawyer is not something you do unless you know you have a reason to, if you're just a fast food company. It's not like lawyers review every tiny action by every single employee and contractor. It's easy to see how things like this slip through the cracks.
If an IT guy is making a change to accessing payroll that affects 10k employees… it’s corporate lawyer time. I would never touch a payroll system or related (eg time tracking) without labor lawyers at a minimum. This wasn’t a casual IT guy plugging a usb fingerprint sensor into a computer in the break room of a mom and pop sandwich shop. It was across an entire national chain and they were transmitting and storing prints with multiple third parties. They totally had contracts reviewed and lawyers involved already.
By now (maybe not in 2008) everyone should know that if you touch personal data or god forbid medical/biometric at all you should get a privacy lawyer review. It’s 2023 and even Facebook asks for consent. At my previous job we’d schedule a lawyer call before started logging new data or updating schemas in a database. Only takes 15 minutes to explain, and a business day for preliminary research on the lawyers part.
White Castle started requiring consent in 2018 co-timed to when a major employer in the state was sued for the using fingerprints for payroll. So someone must be paying attention to something, just not soon enough.
Especially considering we are talking about a sandwich shop, not Google or AWS.
Subway has revenue of around $10B and is selling itself for $10B.
It feels to me that providing your print to begin with without coercion fulfills consent. I understand that the need to keep one’s job can be seen as coercion but I am confident the percentage of employees that actually objected at the time was negligible.
Maybe: requiring fingerprint to access your pay is effectively coercion.
Reasons the employees might not consent but still go through with the fingerprinting.
- Every other employer mysteriously started doing the same thing as their owned by the same franchise owner and/or their friends.
- There are no other employers.
- You live paycheck to paycheck and can't just quit a job.
- Commuting to a different site would increase your gas bill.
- The extra .25 that BK pays is necessary for you to live.
That's an extreme, but you get the point. When the law says get consent, it clearly means there is none implied by participation. Even if the employee signs a paper on their own volition granting consent, your inability or refusal to obtain that consent makes you a violator of the law because as far as you know and can prove in court, your finger print collection was being done without you specifically knowing about that employee's consent. It is your state of mind and intent that is a violation of the law .
Another example would be medicine, even if you took medicine knowing possible side effects, the maker of the medicine is still culpable if they don't follow FDA rules.
You can't say consent was implied when the law is telling you a definition of what viable consent is in a specific way. You can't just ignore the law and make excuses or blame the employees. On their part, they only have to prove that fingerprints were taken and consent was not. If you are they can just quit, then the entire point of the law is sl they won't have to and instead punish the company.
This comes across as a pretty privileged take. For many fast-food workers, a few things are true:
* They have no money or other job opportunities
* They have a legal requirement to work (parole, child support, rehab)
* The local franchise operator is influential and owns multiple franchises
* Already owed pay (and already spent pay) are locked behind these barriers
* The average fast food worker doesn't have education or resources to challenge them
It absolutely is coercion, and another arm of corporatism.
Have I got news for you, poor people are people. They’re not the hapless imbeciles you make them out to be, they are just as capable as you and I, and they have just as much access to information as you and I.
We live in a literal world of plenty for unskilled jobs. They exist everywhere and they are screaming for workers. We literally don’t have enough unskilled workers to fulfill the need.
If you can work fast food you can work in a shop, you can deliver packages. The person who HAS TO work at White Castle or they die simply does not exist. Figment of the imagination.
Eh. I don't really want to make it sound that way, but, well, if they are screaming, they are screaming for cheap workers.
<< This is like the infantilization checklist.
Can you elaborate a little? It is possible that I am misunderstanding your point.
Not everywhere is San Francisco. When you get to rural IL, there's not endless jobs. There's hardly any. Many people working fast food need the flexible schedule, or can't speak English well, or any other of a multitude of other reasons. Also, the complaint is from 2008, not this temporary strange job market that has recently developed.
If what you say is true, and it's so easy to find gainful employment elsewhere, why is anyone working at these places to begin with?
Oh? When's the last time you worked a minimum wage job?
> you make them out to be
That is false. The only one making a claim of "hapless imbeciles" here is you.
Indeed, privilege-based analysis is often used to get recognized as human groups that are often treated as less than that.
1. https://www.ilga.gov/legislation/ilcs/documents/074000140K15...
2. https://ilcourtsaudio.blob.core.windows.net/antilles-resourc...
> the intent, the willingness to cause harm, the result of the interaction, and the options available to the coerced party
If the intent is to get people to hand over sensitive data knowingly violating the law and putting people at risk because it makes things easier for the company, I think there's a case to be made that it is coercion. White castle employees aren't exactly known for having a ton of "options available" either. I doubt very many employees have dreamed of working there because of their passion for steamed meats or love for the company. Seems like more of a "when I have zero other options" kind of career move to me.
Informed consent? Absolutely not. People here are arguing that the poor white collar employees and execs of White Castle couldn't possibly be expected to understand the nuances of installing fingerprint readers. So how could minimum wage workers, many of them minors, be expected to understand the issues at play?
Perhaps the person didn't know Illinois had a biometric privacy law? Imagine you're company has been making you do something you hate for years, then you discover it's illegal. You'd absolutely want to sue, and to have lost that right because you waited is unjustified.
B. The service that shall not be named is probably infiltrating more journalistic output than we think without us noticing. So attractive when you're overworked... (also notice the short paragraphs the article and the service share)
C. As for the lawyers... they don't want "annihilative liability" and are doing everything they can to prevent such an outcome.
"White Castle's Fingerprint Fiasco: Slider Chain Gets a Wake-Up Call in Illinois"
"Bun Intended: White Castle Gets Grilled Over Biometric Privacy Violation in Illinois"
"Hold the Mayo, But Not the Biometrics: White Castle's Slippery Slope in Illinois"
"From Crave Case to Court Case: White Castle's Fingerprint Foible in Illinois"
"White Castle's Biometric Burglary: Slider Empire Slammed with Legal Woes in Illinois"
It would if you asked, it seems.
He would have to have his mind blown beyond belief. He was born in 1880. https://www.whitecastle.com/about-us/our-history
Gotta say those are some good burgers, regardless of the biometrics case.
> what White Castle's lawyers described as "annihilative liability"
sounds like something that should very much be on the table more frequently when large companies have repeated egregious violations of law as is alleged here.
In this case, they’re alleging every finger scan violates consent while White Castle says they should settle with the initial scan violated consent -once per employee.
If the initial suit was for a more modest sum and a more modest allegation, White Castle may never have even considered admitting fault. I agree though, that we need laws with teeth so big companies can’t consider it a cost of doing business. The 17B number could wipe out many businesses entirely. Maybe they should. Chapter 11 protects the economy and jobs by ensuring the organization could still run, just with shareholders losing out.
There’s no real option to say no. Biometric auth is a condition of employment. If you can’t say no it’s not consent.
The punitive judgement would in no way protect citizens from future abuses. It’d just make every company spend more on lawyers. I don’t disagree with protecting people from having their biometric data collected without consent, I just don’t think another page of incomprehensible legal bullshit in your hiring packet does anything to protect anyone.
Again it’s not consent if you can’t say no. If it’s a condition of employment many vulnerable people cannot say no.
For a company over 100 years old with 10,000 employees? I suspect the answer is their compliance department.
It doesn't work well for me: I always must make multiple login attempts and inevitably an employee must intervene and approve. I miss their previous system which used a simple bar code.
This is outlier example, but why should any corporation that created an environmental disaster not pay what a complete liquidation of assets would yield, if that is less than the cost of remediation? Asking for a friend in the railroad business.
Option one is what I would call a reorganization: the rights of equity holders are terminated, and creditors (which would include beneficiaries of civil judgements) get some fraction of what they are owed, through a combination of keeping some portion of their existing claims, receiving cash received from selling new stock, and receiving some amount of new stock. Crucially, the business keeps operating when this happens, it's really just reorganizing the capital structure, not doing much to actual business operations.
Option two is a true liquidation: the business stops operating, all of its assets are sold, and the proceeds distributed to creditors and then the corporate entity simply ceases to exist.
The original debate about the "corporate death penalty" arose from how Arthur Anderson was treated in the wake of the Enron scandal. In that case, AA was criminally indicted. A criminal conviction is a huge problem for a public accounting firm, because convicted felons can't be CPAs or audit public companies. Indeed, it was ultimately convicted and barred by the SEC from auditing public companies. But it actually collapsed far before that, basically immediately after the indictment, as all of its clients saw the writing on the wall and dropped them. This was an option 2 liquidation.
Personally, I would only consider an option 2 liquidation the "corporate death penalty". In the case of your friend in the railroad business, it's probably not the socially optimal outcome because you would actually get more money for the victims through an option 1 reorganization than option 2 liquidation. In general that's why option 2 should be sparingly applied: it reduces the resources available to compensate victims, and inflicts collateral damage on employees, vendors, and customers who mostly didn't do anything wrong.
In addition to option 1 and option 2, some people also consider simply indicting a corporation as the "corporate death penalty" because of how in the case of Arthur Anderson, the criminal indictment did pretty much immediately cause option 2. I think that that position is not really consistent with the facts, however. There are at least 54 publicly traded companies that received criminal convictions between 2001 and 2010; 37 of them were still around in 2013, only 5 failed, and of the 5 it doesn't really seem like the conviction had much to do with their demise[0].
[0] https://scholarship.law.upenn.edu/cgi/viewcontent.cgi?articl...
In the corporate case it has the positive effect of punishing a management structure that allowed/enabled the injury.