Live data from Hacker News

Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

wired.com

251–260 of 407 posts

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#251
post #92
post #70

Earlier quoted context omitted.

Hmm, this wouldn't help you defeat the system at all, unless I'm missing something. What you need is a model to generate photos of your face.

FB is most likely trying to ward off spammers with this idea. Generating unique faces per spam-bot is easy now, for sophisticated spammers, then for every spammer in a few months. The poster is trying to say that this FB effort won't work well and is already only adversely affecting the most stupid and trusting.

Good point, I was only considering the case where FB uses this technique to verify an existing user's identity using facial recognition (which seems like a "logical" use case).

I missed the part where they said they might use it for account creation as well (which makes less sense and seems like a pretty baroque, intrusive and ineffective captcha).

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#252
post #249

Earlier quoted context omitted.

> presumably an attacker will just use the local process to observe and develop a method to defeat it. If they can do that then the whole method fails anyway. Besides, I think the set of your average revenge porn idiots intersected with those that are capable of defeating the hashing scheme in order to do their dirty deed is going to be exceedingly small.

> If they can do that then the whole method fails anyway. i'm not that sure. the memory of any application can be observed, which means the process of fingerprinting - whatever it is - can be observed. executing the process enough times with a range of inputs will provide a load of analyzable data, via recording the transformation of bytes. this is (loosely) why basically all software can be "cracked" and drm methods…

Fair enough, but when weighed against the risk of a FB employee going rogue and making copies of those files or FB 'accidentally' forgetting to wipe your images I'd take my chances on this uber elite perv and would not upload my stuff to FB.

This all of course besides the best defense against all of this: do not create such images in the first place and do not allow others to create them.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#253

Earlier quoted context omitted.

To correct your correction I'd like to add that far from every European country is a member of the EU.

He is saying that that law applies to EU citizens even when they are not located in the EU. Much more difficult then determining which country the user is connecting from. Not sure if this is the law though

And UK citizens, even if Brexit happens.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#254
post #181

Earlier quoted context omitted.

The GDPR penalties can reach 4% global (i.e. sum all related companies) annual turnover per infraction . If anyone ever found out Facebook had a widespread violation, Facebook would be likely be dissolved.

Are there any instances of otherwise financially sound major global corporations being dissolved as a result of EU fines / regulatory action? I suspect if the rubber hits the road in this situation, FB would prevail.

Not dissolved, but the EU have shown themselves to be willing to tackle the tech behemoths, as Google recently found with their EUR2.4Bn fine https://www.theguardian.com/business/2017/jun/27/google-brac...

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#255

Earlier quoted context omitted.

Sexting is quite common about young adults and so is the subsequent sharing of those photos. Being able to stop that from happening is incredibly valuable. I am just surprised Facebook didn't instead look at a way of running these image hashing algorithms on the device instead.

There is a much better way to stop it happening.

And that would be what, exactly ?

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#256
post #183

Earlier quoted context omitted.

That only applies to Europe. The question is whether the data is valuable enough to Facebook to spend the time to add `if (europe)` to their code.

It applies to Europeans, even if they're not in Europe, and even if they don't identify themselves as being in Europe.

How exactly does the EU propose to apply its laws to people dealing with Europeans outside the EU?

Being European doesn't automatically subject everyone you interact with to EU laws, especially while you're outside the EU.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#257
Instagram did this same bullshit to me when I signed up for an account to to follow some photographers.

'Please provide a clear photo of yourself holding your government issued ID, and a piece of paper with the following code handwritten on it'.

No, fuck that for a joke.

There's this growing trend of everyone wanting your photo and some ID, and then you have no way to verify that information is being kept securely or used for appropriate reasons.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#258

Earlier quoted context omitted.

It really does seem like something an elite private club would do to get a laugh out of fooling the proles while smoking a cigar and browsing the pictures.

It's more like oblivious high-paid product managers and devs who can't fathom why people wouldn't trust Facebook or that Facebook might not be a purely beneficial organization.

I think you've completely missed the point here.

Teenagers who have naked photos in the possession of their peers need a solution for preventing dissemination.

And so if you're in this situation trusting Facebook is by far the lesser of two evils.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#259
post #144

Last paragraph of the article: "The new authentication scheme is the second in recent weeks that relies on photos. Earlier this month, Facebook asked users to upload nude photos to Facebook Messenger, as part of an effort to prevent revenge porn. Facebook said it would use the nude photos to create a digital fingerprint against which to compare future posts." Wait what? I had to check whether today was April 1st.

Can someone explain if / how this prevents someone from just changing a single pixel and thus circumventing the hash? Are they using some kind of probabilistic hashing? Or are they just relying on the offenders to not be so clever?

To be fair the type of people who are sharing naked photos via Facebook aren't likely to be all that technologically sophisticated to enough understand hashing.

Pedophiles would be using something encrypted and anonymous anyway.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#260
post #241
post #189

Earlier quoted context omitted.

Not everyone uploads their face to facebook over and over and over again.

But most do.

Most humans don’t even have a facebook account. Did you mean “most people in my observable social circle and subculure”? Just because many of my generation willingly give their identity away does not mean this behavior is normal or that this is an excusable form of exploitation.
Post reply on HN