Meta to pay Texas $1.4B for using facial recognition without users' permission
texastribune.org
texastribune.org
Meta should also be forbidden from using any features derived from this data, or open source any trained model from the data. 1.4B settlement is too small compared to the long term gains of a company
Meta agrees to $1.4B settlement with Texas in privacy lawsuit over facial recognition - https://apnews.com/article/texas-attorney-general-meta-settl...
> At the time, more than a third of Facebook’s daily active users had opted in to have their faces recognized by the social network’s system.
In general, when I come across some sort of opt in I get offered a choice between allowing something to work and it not working and having some sort of a sub optimal experience. I can't even try before I buy either because once I have consented, the data/image/whatever is already "released".
Most opt-in choices, unless coerced by laws, will be heavy handed nudges at best.
I'm an IT consultant and stand more of a chance than most at making an informed choice but please don't wave "opt in" as some sort of laundering procedure. I am deliberately juxtaposing with money laundering.
I can’t tell you how many newsletters and other BS I unknowingly “opted-in” to, for example.
It's way too easy for companies to mislead consumers about what they are agreeing to.
Much better would be a compromise, that describes both why and what. Though, that will be a lot of text which isn't good either. Hard problem.
The worst was back in the day when Chevy used some bogus primer for their trucks. They refused to say it was their fault owners paint was coming off their trucks sans any rust. A class action was started and then over the course of several years, the government and owners finally won.
What did the owners get? Coupons for $100 off a paint job at the local Chevy dealer.
So not only did the owners not get anything to help them fix their problems, they were forwarded to a local dealership where the dealership could then take advantage of them again and charge them thousands of dollars and essentially make all the money back they were paying the attorney's and government.
That’s what small claims court is for.
It's a quandary. You can ignore it, but that encourages criminal behavior. Or you can pursue it, but proving your case beyond a reasonable doubt is time consuming and difficult. Often, there is no money to pay the lawyers in advance, so they expect to be compensated for the risk of getting nothing.
If the lawyers worked for free you might get double or triple the settlement, but it's hardly better to get $300 off a paint job than $100. The cash equivalent is probably only $30.
The only thing that seems fair to me is if the settlement is held in trust and disbursed with minimum friction to anyone eligible. If Chevy wants to give those people a $100 voucher for thirty bucks if they show their eligibility for the action then go ahead!
Civil cases aren’t generally required to be decided beyond a reasonable doubt but merely with a preponderance of the evidence. It’s more that court in general is often time consuming and difficult.
> they expect to be compensated for the risk of getting nothing
It depends on the lawyer and the case, e.g. most class action suits the lawyers charge nothing up front but take a cut of the damages.
Look at the award from Equifax data breach settlement… The CFPB fine was about $0.66 per person. The class action award averages to about $2 per person.
Could your bank plaster your personal info on a billboard for two years, but make it up to you with a nice paper cup of coffee? (How would you even prove damages?!?). Don’t get your hopes up — that coffee would be too expensive…
Would $1000 be fair for you? Multiply that by 150 million…
Same with the airbag recalls.
The problem is worse than lawyers’ cuts… Proper restitution isn’t even possible (orders of magnitude greater than company’s assets).
At the individual level, a $10k automobile can do far more damage to people and property than just $10k…
But, As a society, we often fail to punish companies that do more harm than good.
No, the cash equivalent is probably $-200 or so.
The problem is that the individuals affected didn't get anything of value. They got a $100 off coupon at the dealership for a paint job there. Which means the dealership is just going to inflate the price by at least that much, and dealerships are already known to have higher prices than competing businesses anyway.
If they had gotten a $100 voucher for a paint job at any paint business, or better yet a $100 check to spend as they wish, then this would have cost GM something at least. But instead, they stood to profit from the "payout".
Gotta remember the quote from Zuckerberg during the early days, when someone asked him how he got all that private data. He said, and I quote, "People just submitted it. I don't know why. They 'trust me'. Dumb fucks."
This is no better than theft, and it will be defended exclusively by people who have never created a single thing of value in their entire lives.
https://www.reuters.com/legal/transactional/texas-fights-goo...
https://arstechnica.com/tech-policy/2024/07/meta-to-pay-1-4-...
https://investor.fb.com/investor-news/press-release-details/...
> In 2021, a judge approved a $650 million settlement with the company, formerly known as Facebook, over similar allegations of users in Illinois.
Indeed the concept of the infinite growth may well explain the Fermi paradox through the concept of a "light cage"[0]
https://pureportal.strath.ac.uk/en/publications/the-light-ca...
"Put simply, for large companies, criminal penalties may be just another cost of doing business—and quite a low cost at that."
source: https://scholarship.law.upenn.edu/faculty_scholarship/2147/
The only way to stop this type of behavior is to throw execs in jail and take their personal assets off them.
One more infraction with the same consequences and the company has no money left.
That sounds pretty effective to me?
Their annual income is approximately 100x larger.
You go into your quarterly earnings call and say "we're conducting illegal business practices which expose us to up to $75B of risk" and see how the investors like that.
You don't get caught every time you speed, but the fine certainly is a deterrent against doing 100mph everywhere.
Obviously everything is NOT okay, otherwise the company wouldn't be getting fined in court for breaking the law.
VCs know just as well as we do that Facebook's business model (privacy-invading targeted advertising) exists because law has not caught up to technology yet. That's starting to change, as this settlement shows.
If Meta suffer many more of these legal settlements which wipe >1% off the annual profit then investors will start to divest. The value of the company will fall.
Keep in mind this was a settlement amount which suggests the legal liability was actually a lot higher than $1.5B
So I think my statement is supported: fining corporations works.
Its called a legal provision or legal reserve. they need to set aside money for the eventual expense of the setlement. This is going to eat right into EPS.
And, any material change in provision will be discussed. Plus, any investor worth their salt is going to be poring over FS disclosures, including any legal provisions.
Admission of fault has nothing to do with FS. Its purely an insurance topic
> The company announced in 2021 that it was shutting down its face-recognition system and delete the faceprints of more than 1 billion people amid growing concerns about the technology and its misuse by governments, police and others.
Getting fined for doing something illegal just really means its legal for a price.
If the expected fine for X is larger than the expected profit, companies will not do X.
Which is the same reason that "higher penalties" wouldn't work either. The problem is not that the penalties aren't sufficient to deter, the problem is that the right hand doesn't know what the left hand is doing, so even if the lawyers tell them "you must never do this" they've got thousands of independent chances to screw it up. One person who doesn't heed their training and oof.
The actual problem is that these companies are too big. Mistakes will always happen, but one mistake by one team in a huge bureaucracy shouldn't affect a population the size of a major country.
I think that definitely happens, but I'd guess it's the smaller part of the equation.
Empirically, large companies seem to have little problem following this incentive.
The corporation cannot repeatedly violates nor make a policy that violates the same thing over and over. The punishment would be increased exponentially...
We all know individuals who explicitly do the same w.r.t. speeding on the highway, driving in the HOV lanes, etc.
So it seems to me that there’s a fundamental human trait (“what can I get away with” ??) that warrants thinking about as well.
Idk, I suspect many "crimes" like jaywalking and speeding are more around, this rule errs too hard on safety, but I know I can do this safely, and if it's not safe enough I'll get to pay the consequences (fines, accidents, dying). That's nothing like violating the privacy of other people for profit and no real penalty (actual jailtime for those involved, not just a --fine-- tax on the profits)
The analogy here is that people, like corporations, are frequently very bad at assessing where the appropriate line for safety actually is, doubly so when the appropriate line personally inconveniences them. Some rules are perhaps too stringent, but frequently, the guidelines are akin to safe working loads, with safety margins built in, rather than do-not-exceed limits. Anyone who has to understand either of those things will tell you that if your operational envelope exceeds the safe working limit, you will eventually fail, catastrophically.
It's certainly true that traffic fines are not similar to corporate fines in the sense that you don't lose your chemical manufacturing license after committing 15 points worth of chemical safety infractions, but for other kinds of infractions, the fine for people is also frequently just part of the cost of doing the thing.
All of that said, I 100% agree that company leadership should see jail time for a variety of infractions, with a sort of inverted burden of proof as it pertains to determining who is at fault in an offending organization: you can only pass the buck down as far as the highest person who you can prove beyond a shadow of a doubt deliberately hid information from those above them.
This seems like it's apples to oranges. The people choosing to do these things aren't doing so because they consider it to be a cost of business, expecting that they'll generate more in revenue, but because they think the likelihood of being caught and the gravity of the offense are relatively low. This practice of disregarding regulations because the fines can be factored as a cost is fairly well confined to large corporations.
(I guess someone being paid per mile driven from advertising decals on their car would get a business benefit from the speeding; they may even factor in the probability of being caught with the amount of the fine to determine their speeding decisions. That's nobody I know, though.)
edit: I do not see any reason to not apply "license of cooperation in [state/country]" void in case of continued breaking of laws.
> In 2011, Meta introduced a feature known as Tag Suggestions to make it easier for users to tag people in their photos. According to Paxton’s office, the feature was turned on by default and ran facial recognition on users’ photos, automatically capturing data protected by the 2009 law. That system was discontinued in 2021, with Meta saying it deleted over 1 billion people’s individual facial recognition data.
> The 2022 lawsuit
> We are pleased to resolve this matter, and look forward to exploring future opportunities to deepen our business investments in Texas, including potentially developing data centers
Each statement makes it increasingly harder to view it as a fine than a tax. An offence that lasted 11 years and got prosecuted a year after it ended can be explained in no other way than being an excuse dug out of the ground to make a ransom
> “Wherever I'm going, I'll be there to apply the formula. I'll keep the secret intact. It's simple arithmetic. It's a story problem. If a new car built by my company leaves Chicago traveling west at 60 miles per hour, and the rear differential locks up, and the car crashes and burns with everyone trapped inside, does my company initiate a recall? You take the population of vehicles in the field (A) and multiple it by the probable rate of failure (B), then multiply the result by the average cost of an out-of-court settlement (C). A times B times C equals X. This is what it will cost if we don't initiate a recall. If X is greater than the cost of a recall, we recall the cars and no one gets hurt. If X is less than the cost of a recall, then we don't recall.”
Recalling a hundred million cars at the cost of a hundred billion dollars because there is a 0.5% chance that one person across the entire hundred million could die is the wrong choice. Otherwise all products would have to be recalled continuously, because nothing is perfectly safe. Example: Many cars have been sold without lane departure warning systems, even though that could cause some people to die. Should they all be recalled?
The equation above is how you calculate the cutoff for whether to do the recall. What would you propose that they do instead?
My flippant quote from "Fight Club" isn't a great starting point - let me flush out my opinion a bit.
I believe that the types of judgements we're talking about here are not ambulance-chaser-type awards for a claimant proportional to the injury but actually punitive in nature towards the business entity itself.
GiantTechCorp isn't paying Alice 40 bucks because she's injured by losing her data, they're paying 10 billion as punishment to not do it [get caught] again. If the punishment doesn't incentivize the company not to reoffend, we need to change it until it does.
This is my fundamental issue.
1% net profits as a punishment? Please.
Maybe every state should sue, so it would be $70B. Of course that still doesn't make a dent when Meta's market cap is $1.174 T. It's a rounding error.
What could that mean: Meta or whichever company breaks the law, loses ownership and rights to anything that is the result of the crime.
If it's a model, Meta can not use that or any other version of the model that utilized data illegally acquired. And that model becomes property of the victims.
Securities fraud also essentially offers that: all money made out of the fraud and gains on that belong to the victims.
California's Unfair Competition framework also dictates essentially payment of the proceeds of the "unlawful activity" and taking actions to undo it.
Again this is already an existing relief for certain crimes or civil torts committed by individuals.
We just have not legislated to apply it to you know the other "persons," the companies.
Asset forfeiture isn't something we should be cheering on.
Why not just act ethically in the first place?
Regardless, you are missing the point. It is a straightforward calculus that if you craft enough complicated and vague privacy laws, companies are bound to violate it, no matter what they do or how hard they try. All you have to do is craft a set of laws in which any company can always be interpreted as in violation of one.
If I was a state, I would go out of my way to craft these vague, overwrought laws so I could have a reliable source of an extra few billion dollars here and there whenever I needed it. If I was a regulator or legislator, I'd do it for the career clout of "going after the big bad guys." And no one will ever complain, because "big companies are evil and capitalism has never done anything for humanity," so the Overton window can only ever move in one direction.
And this is how we end up with the undeniable technological stagnancy of the EU, where they completely missed the www and mobile revolutions, and will certainly miss the AI revolutions. How many Industrial Revolutions can you miss out on before you fade into irrelevancy, having lost a meaningful portion of your financial/economic/military/technological power? I guess we will find out.
If what you're suggesting were true we would have seen large numbers of EU unicorns based around gathering private data before GDPR that have somehow disappeared ...and we didn't.
GDPR wasn't brought in through calculus to shake down brave data innovators, striving to "make the world a better place".
GDPR came in reaction to large foreign entities taking the piss, stalking us with creepy adverts and dark pattens, refusing to take no for an answer.
These fines should be exponential in nature, and aggressively so. The 4th-in-a-row fine of this nature should basically take everything they earned in the whole year. Let's see how quick and efficient they suddenly become once there's actual consequences.
That, or Zucc and his cronies should be getting jailed. I'm fine with either option, or preferably both.
I hope it only restricts business, because I have an awkward amount of face blindness and would love to have an app that could put names to them. I wonder if the maker of such an app would be liable for my use of it in Texas.
Without that, I don’t think it could work. Does your need for an accessibility device trump my right to privacy?
> At the time, more than a third of Facebook’s daily active users had opted in to have their faces recognized by the social network’s system. Facebook introduced facial recognition more than a decade earlier but gradually made it easier to opt out of the feature as it faced scrutiny from courts and regulators.
Your device would effectively give anybody the right to demand identification from random people in public places which would probably have a lot of negative consequences.
Without some very strong, EU-type rules around how you have to ask, it's just another thing lawyers will know to add to the terms.
outlier, presumably. i remember when newspapers had good copy editing.
The fact is that many things buried in EULAs and whatnot are not really enforceable nor constitute consent. Some things have to be agreed to more explicitly than putting them on page 50 of your fine-print.
It's especially problematic when companies start doing something you didn't directly sign up for or couldn't have expected to happen when you did. I don't think that many people who signed up for a social network in 2015 expected that their photos would later be scanned. It might surprise people even now.
> The company announced in 2021 that it was shutting down its face-recognition system and delete the faceprints of more than 1 billion people...
You can make infinite copies of data and do contortions around the definition of deletion, like "soft deletion", "anonymization", etc.
I enjoy the rapid progress of LLMs. ChatGPT and Claude are already a critical part of my daily work. But I don't like the current situation where VCs and start-ups use unpermitted data to train the models, don't respect content creators, and take advantage of the lack of regulations.
Interesting to see that while meta at least publicly scraps the feature, a similar one on iOS Photos is not even an opt-in – you can't turn it off.
Network effects mean you can't realistically say no.
Do the math before being generically cynical?
so where's that money going to wind up?
I as an end user of an app shouldn't have to go through every feature, how it is implemented and if that meets my personal privacy bar. Sensible defaults are important.
Arguably that's what Texas is doing here. Requiring permission to apply facial recognition feels like a very sensible default.
There's a lot of money to be made exploiting the most intimate details of our lives. Nobody "needs" that money, but they sure don't want to leave it on the table when the government isn't going to stop them from violating our privacy and then stuffing their pockets with our cash.
Prices can be set according to the data companies have on you and the assumptions they make using that same data. The price you're asked to pay for something when you shop online isn't always the same price your neighbor would be asked to pay for the exact same item. Lots of potential here too when restaurants don't publicly disclose their prices, but insist that you use a cell phone app or scan a QR code just to see a menu. Your prices don't have to be the same as the person in line behind you for the same foods. Physical retailers have been trying to get this going for a long time.
"For example, ZipRecruiter, an online employment marketplace, indicates that it could increase profits by 84% by experimenting with personalized prices" (https://link.springer.com/article/10.1057/s41272-019-00224-3)
Fast food chain Wendy's tried to move the needle closer to personalized pricing (aka discriminatory pricing) when they said they were moving to surge pricing and you'd never know how much a burger was going to cost you until you'd already waited in line at the drive through and were told what price you were getting. They backed down due to consumer backlash, but their desire to squeeze every last dime possible out of you by leveraging big data and algorithms is still there.
Hotel/airfare/travel industry has been doing this for a very long time already (https://www.cnet.com/tech/services-and-software/mac-users-pa... and https://millionmilesecrets.com/guides/are-airlines-raising-y...)
Health insurance companies want your data so they can charge you more for not moving enough, or because people in your zip code were logged eating more fastfood, or because you've been spending too much on alcohol at the store.
https://www.propublica.org/article/health-insurers-are-vacuu...
https://www.ama-assn.org/practice-management/digital/insurer...
A lot of the tracking we see is explicitly trying to assess traits like intelligence, education level, and mental illnesses including dementia and bipolar disorder.
Here for example is a pizza shop that will "create a profile about you reflecting your preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, and aptitudes." You know, just normal pizza shop stuff! (https://pie-tap.com/privacy/)
Companies and scammers alike can easily target uneducated and low intelligence individuals, and machine learning algorithms can detect when bi-polar people are in a manic phase, or what time your ADHD meds usually start to wear off, or when someone with alzheimers starts sundowning and they can jump at those chances to hit people with ads, scams, and manipulations when they think their target is weakest/most confused/most impulsive. Even without a diagnosis your mental health is a huge business opportunity for the person willing to exploit it (https://www.politico.com/news/2022/01/28/suicide-hotline-sil...)
The data being collected on you is increasingly used for really big things like if you get a job, or if your rental lease agreement gets approved, but it's also used for really trivial things like determining how long to leave you on hold when you call a company (https://www.nytimes.com/2019/11/04/business/secret-consumer-...)
Companies aren't collecting huge amounts of facts about you and your life because it's fun for them. They pay a lot of money to purchase, collect, store, maintain, backup, and scrutinize all that data, and they do it because it's making them money. Almost always, their increased profits come at your expense.
A distinction without a difference? A company that can raise their prices for you because they know (or think) that you can afford the price hike isn't safeguarding them, it's just screwing you out of money. How would you feel if you got an awesome 20% raise at work, only to find that the next day the top 10 things you most frequently buy at the store were all suddenly 20% more when you went to pay for them. Why shouldn't a loaf of bread cost a percentage of your total income?
> if someone refuses to hire me because they found out something unsavory about me from a data broker, then they're really only hurting themselves.
I could agree that it might not be smart for them to lose candidates based on random crap dug out of a background search, but it happens and however dumb it is for the company, you would still be out that job. They'll never tell you why you didn't get hired. You just get ghosted.
> If someone tries to charge me more because they think I can afford it, then they're going to lose my business or get bad PR on X once I realize I'm being treated unfairly.
All the recent inflation shows that companies can get away with arbitrarily raising prices a whole lot as long as they all do it around the same time. Have you been boycotting them all recently? I've gone out of my way to avoid eggs associated with Cal-Maine Foods over price gouging (https://www.newsweek.com/egg-producers-accused-price-gouging...) but it's not been easy. Not every brand I see in stores advertises itself as being related to them. Boycotts are growing more difficult thanks to the massive consolidation of our food industry (https://www.theguardian.com/environment/ng-interactive/2021/...).
Most of the time when you end up paying more because of big data you'll never be told that. All of this is almost totally hidden from consumers. You'll just be charged more or get a bill that seems higher and you won't be told why. You're very likely already paying more for some things because of big data. Same with store policies. You ask a store what their return policy and they'll tell you one thing while the next person who asks gets told something different. You can't feel cheated or even like you're being treated special because your good consumer score is so high because you don't even know there are multiple policies in effect depending on who asks.
I'd be willing to bet that a lot of people on twitter have complained about companies like comcast, at&t, tyson foods, facebook, 3m, monsanto, etc, but what has it accomplished? Many of the most wealthy and powerful companies in the US are also the most hated by the public. They don't have good reputations to protect. They just don't have to care if you like them or not.
> The best you could probably argue is that preventing corporations from having knowledge about people will protect the most vulnerable members of our society who can't fight or fend for themselves and are willing to tolerate being treated poorly.
It would protect all of us. No one can "fend for themselves" and everyone is being treated poorly. You have been being treated poorly already. You will continue to be treated poorly until it hurts a companies profits to treat you badly. Right now, they're not just getting away with it, they are looking for ways to screw you over even more than they are already and in new and innovative ways using resources unlike anything you'll ever have. It's highly asymmetric warfare where consumers are divided into buckets and ultimately conquered.
This is how the California economy works and it's something that I like, because if I'm allowed to have more money, then I can use my brain to figure out a way to not be scammed out of it like everyone else.
As for the rest, I don't think indignant agitators online who stir up fear are really representative of public opinion. Yes corporations tend to be slimy, but that's because people are slimy. I don't want to live in a society that takes away my freedom just to prevent the worst of us from exploiting the weakest of us.
Well that's pretty antisocial in general. Sure, you have worded this in such a vague way that it doesn't really provide for meaningful discussion. But, I'd just as obtusely respond that the entire point of society is to prevent the worst of us from exploiting the weakest of us.
It just really seems besides the point to flaunt your own individualism as a response to social questions, as if the issue was whether or not you in particular felt it was appropriate for you.
No, and I didn't say that it was. Reported revenue was just the data Meta has made available. Unless I've missed it somewhere, they don't explicitly state exactly how much profit they made last year. I think it's reasonable to assume that it was several times more than the 1.4 billion dollar fine though, which is really the point. If Meta/facebook makes even just tens of billions in profit, 1.4 billion could easily be a sustainable penalty. The more years they are hit with a fine that size, and the more other states start demanding their cut of the action too, the less sustainable it becomes, probably, but for all we know paying this 1.4 billion fine (over several years) to Texas could actually be (or end up being) profitable for meta.
How much money did they make off the data they've been collecting and abusing since 2011? How much money will they make in the future from what they learned by abusing that facial recognition data for nearly 15 years? If it ever amounts to more than the fine, or if other incentives make it justifiable to shareholders then Meta is better off for having broken the law.
They state this in their financial reports and it is readily available on financial news websites. I’m not sure how you found revenue without also finding net income (aka profit).
Type “meta profit” into a search engine and click the first result. This immediately gave me the answer in Bing, DuckDuckGo, Google, Kagi, and Yahoo.
Google takes me here (https://economictimes.indiatimes.com/tech/technology/meta-po...) where it's the same story
You mentioned Kagi, so I thought I'd try asking kagi's AI search: "how much did Meta make in profits last year"
That gave me:
According to the available information:
In 2023, Meta Platforms reported annual revenue of $134.902 billion, which was a 15.69% increase from 2022.12 However, the information does not explicitly state Meta's profit for 2023.
The closest relevant information is that in 2022, Meta's total operating profit declined from $46.8 billion in 2021 to $28.9 billion.3 Additionally, in Q4 2023, Meta reported revenue of $40.11 billion, which was a 25% year-over-year increase.4
So while we don't have the exact profit figure for 2023, the available data suggests Meta's profits were likely substantial, though potentially lower than the previous year's $46.8 billion.3
For FY2023, it was $39.1 billion.
https://www.washingtonpost.com/technology/2024/07/30/seante-...
They'll react by lobbying for fines while also lobbying to limit the amount of those fines. They love the fines. Fines are something they can budget for and can let them violate the laws as long as they are willing to pay the government a fee/toll/bribe. Without fines they might be held meaningfully accountable for their crimes. The last thing they want is to face a risk of ending up in prison the way that you or I most certainly would for repeatedly ignoring the law.
For event tickets, you are not even made aware there is an “agreement “
If it was just a tactic it could at least have a sensible (though evil) explanation.
Just like ad hominem framing tells more about you than me.
It is usually whatever company isn't friendly enough to the current government.
In Canada, it is any company that dares to compete with the telecom companies.
How about by not breaking the law?
They could start by not breaking the law...
https://www.cambridge.org/core/journals/perspectives-on-poli...