Live data from Hacker News

Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

wired.com

191–200 of 407 posts

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#191

Earlier quoted context omitted.

> yes, you're going to have to trust them with a copy of it. No. They could have you compute a fingerprint locally without uploading the image itself, preferably through some audited open source software, without auto-updates. They only don't do that because they want to guard their image hashing as corporate secrets.

No, Facebook's side needs to verify that the image is you, and that you're not just hashing a photo of the McDonald's logo.

Presumably it’s both; hashing like this is fairly trivial to break if you can access the code.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#192
post #135

Earlier quoted context omitted.

What do you have against identifying friends' profile images, of all things? Facebook already has them.

If one of my friends identified me in a photo to facebook, I would not be happy about it. I generally ask everyone who knows me not to upload photos I'm in to facebook at all beyond what's already there.

Exactly, the point it validates and updates the current status of friendship you have. Further it informs facebook who are the people you really know opposite to your "facebook friends" .

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#194

Earlier quoted context omitted.

Excuse me. The issue is biometrics. "We'll delete the picture" =/= "we'll delete the control points and features extracted from your pics".

Is there any precedent for recovering individual training items from a model trained on 100m+ examples?

[deleted]

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#196
post #174

Earlier quoted context omitted.

That's so ridiculous it could have been written by The Onion. Facebook has absolutely no businesses to store nude pictures of their users.

They don't. They store a perceptual hash, which can't be converted back into the original photo.

So you hope. But you have to upload your picture first. If they were serious about this they would allow you to compute the hash locally and then only to upload the hash.

Note that they explicitly state that a human will look at the image and then hash it. So they are storing it at least for a while. And you will not be able to verify whether they really delete it or not.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#197

Earlier quoted context omitted.

What recovery? You're uploading your pic via your account. It is already associated with you.

As I understood it you are making the argument that they will have information about you from uploading this picture even if they delete the actual picture. I'm genuinely asking if it is possible to recover an individual training example from a model which is shown vast amounts of data. I'm only aware of being able to recover stuff like this - https://ars.els-cdn.com/content/image/1-s2.0-S08936080173020... which is h…

I think there are two separate questions being raised. My understanding (EDIT: my understanding of the concern being raised in this discussion) was not that they would try to recover individual readings from a trained model, but that they would run a model on your face to extract features, then save an array of features that defines your face. Only those features are needed to identify your face - after data extraction the photo is no longer needed.

This article talks about how those data points are extracted using a different method.

https://medium.com/@ageitgey/machine-learning-is-fun-part-4-...

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#199

Earlier quoted context omitted.

No, Facebook's side needs to verify that the image is you, and that you're not just hashing a photo of the McDonald's logo.

they can verify that after they have found a match. if there is no match you gave them no data of interest. if there is a match then they already have that image anyway and you didn't make your privacy situation worse, except maybe telling them that you claim that is you, now allowing them to associate more images was you, but that's probably an acceptable tradeoff if there is actual revenge porn of you out there.

It's not a simple hash. From Alex Stamos: “There are algorithms that can be used to create a fingerprint of a photo/video that is resilient to simple transforms like resizing.” That doesn't make it clear that they are making use of the powerful classifiers that Facebook has, but it's clearly not md5, either.

Regardless, I think your point stands.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#200
post #78

Earlier quoted context omitted.

There was a thread about this on HN -- too lazy to look it up now or repeat some of the longer comments about it. But going into this assuming that FB has no ill-intentions, FB's proposal seems by far the best solution in a world of ugly and terrible solutions. For starters, it's intended for victims of revenge porn, which is a fairly extreme category and one in which the harassment is distinctively aggressive and vi…

https://news.ycombinator.com/item?id=15651710 https://news.ycombinator.com/item?id=15648080 https://www.google.com/search?q=ycombinator+fb+revenge+porn > too lazy to look it up now People doing this frustrates me greatly. You had to type 30 key strokes. ⌘+t "ycombinator fb revenge porn" ↵ and paste the results back. How many people are going to read your comment? Maybe 10% of them want to read those links. You spared…

Now do that on mobile, with a slower, cramped keyboard, and poor multitasking. Not everyone matches your system.
Post reply on HN