Live data from Hacker News

Apple is sharing your facial wireframe with apps

washingtonpost.com

61–70 of 152 posts

Re: Apple is sharing your facial wireframe with apps

#61

Earlier quoted context omitted.

> What if I don't want to have my face scanned, but nevertheless need to pick up somebody's lost-phone/detonation-device? Shall I just wear a mask? Well...yeah. If you're out in public and your face is visible, you don't have a reasonable expectation of privacy.

What does this have to do with "out in public"? I have by law, custom, and common sense an expectation of not being 3D-scanned in a gas station bathroom, even if I pick up the phone that the previous visitor had dropped on the floor.

In most countries you have no right not to be photographed (by anyone) when in public (by definition being in public is not being in private). I fully support this with the exception of the homeless (and I think it does somewhat support the right to cover your face in public if you wish).

Re: Apple is sharing your facial wireframe with apps

#62
post #25

The FaceID camera is infrared and can see in the dark [1]. According to the Post "Once you give it permission, an active app keeps on having access to your face until you delete it or dig into advanced settings. There’s no option that says, “Just for the next five minutes.”" So a random developer can (kind of) look at us when we turn the light off. Not only that, those cameras work also in the sunlight. You can go on…

"Once you give it permission, an active app keeps on having access to your face”

Isn’t the definition of an active app, one that is open and in the foreground?

The minute the phone sleeps, or the app is put into the background, access becomes more at Apple’s discretion.

I’d expect an app running in the foreground to be able to keep using the camera as long as needed..

Or is your point more: allowing once allows it every time the app opens, with no option to repeatedly prompt?

Re: Apple is sharing your facial wireframe with apps

#63
post #12

Earlier quoted context omitted.

> I'm honestly less worried about Apple than others. That's a pretty low bar. Yes, Apple at least gives lip service to security which other companies don't even bother to do, but Apple has had some pretty major security screwups lately (three in the last few weeks). You might be less worried about Apple than the competition, but you'd do well to be somewhat worried about them nonetheless.

Two other issues I'm worried about with iOS: - MAC address tracking (RTS packets thrwart MAC randomization[0], not immediately clear if WiFi is fully off[1]) - All-or-nothing access to photos on the phone (append-only for apps that request it) Discord in particular is bad for the photo permission, as I don't trust China's Tencent with access to all the photos on my phone (which can include lots of frequent location i…

In iOS 11, there is a new permission that an app can ask for, which grants write-only access to the photo library. [0]

"To protect user privacy, an iOS app linked on or after iOS 10.0, and that accesses the user’s photo library, must statically declare the intent to do so."

[0] https://developer.apple.com/library/content/documentation/Ge...

Re: Apple is sharing your facial wireframe with apps

#64

Earlier quoted context omitted.

Two other issues I'm worried about with iOS: - MAC address tracking (RTS packets thrwart MAC randomization[0], not immediately clear if WiFi is fully off[1]) - All-or-nothing access to photos on the phone (append-only for apps that request it) Discord in particular is bad for the photo permission, as I don't trust China's Tencent with access to all the photos on my phone (which can include lots of frequent location i…

Does Tencent not have an extension that pops up in the sharing sheet for images?

Just checked again: not for Discord. No idea about other apps owned by Tencent.

It's notable Discord was developed as an American startup, and it's not clear what Tencent's involvement is. Regardless, for me it's too much access for a chat app to have in exchange for the convenince of sharing a photo from my phone.

Re: Apple is sharing your facial wireframe with apps

#66
post #54
post #50

You know how some F2P games will allow you to watch video ads in order to e.g. earn extra in-game currency, activate a point multiplier, etc? As it stands, you can start one of these ads and then turn your phone upside down, or look away. How long until an advertising provider makes use of the attention API and makes it so that you can't look away? Seems bleak.

As far as I know there's no "Attention" API. It also seems intentional that Apple has omitted an eye-tracking API as well (even though it seems like that would be trivial for them to add from a technical perspective) Is there anything stopping them from doing this with the front-facing camera on existing phones?

Apple would probably reject apps that ask for camera access just to track user attention, and even if they didn't, asking for camera access in an app that doesn't have a reasonable reason to want it is a huge red flag and will get the app uninstalled by a lot of people.

Re: Apple is sharing your facial wireframe with apps

#67
post #7

I'm honestly less worried about Apple than others. They've at least made some measures to prove that they are willing to go some distance to protect privacy, even losing ground to competitors in voice recognition. Now thinking about co's like Facebook that not only has access to far more imagery of faces tied to sentiments and moments but have shown time and time again that privacy is a secondary concern AND that the…

> co's like Facebook that not only has access to far more imagery of faces tied to sentiments and moments but have shown time and time again that privacy is a secondary concern

It's only a secondary concern in the sense that they're trying to find new and innovative ways to violate it. If it weren't for that, it wouldn't be a concern for them at all.

Re: Apple is sharing your facial wireframe with apps

#68

Earlier quoted context omitted.

> What if I don't want to have my face scanned, but nevertheless need to pick up somebody's lost-phone/detonation-device? Shall I just wear a mask? Well...yeah. If you're out in public and your face is visible, you don't have a reasonable expectation of privacy.

What does this have to do with "out in public"? I have by law, custom, and common sense an expectation of not being 3D-scanned in a gas station bathroom, even if I pick up the phone that the previous visitor had dropped on the floor.

You don't have anything of the short by law. And not even by custom. It's just that such technology wasn't available in a popular device before.

Re: Apple is sharing your facial wireframe with apps

#69
post #65

Something alarming occurred to me: Apple has to be saving all of the faces of people who come into Apple stores and do the Face ID demo. There's no reason for them not to do that, they'd be leaving good data on the table otherwise.

On the contrary, Apple explicitly would never in a million years want to do that. That's a massive liability with no upside whatsoever.

Google and Facebook and other such companies treat personal data as an asset and try to collect as much as they can.

Apple treats personal data as a liability and wants to have no more than they need to operate.

Re: Apple is sharing your facial wireframe with apps

#70
post #25

The FaceID camera is infrared and can see in the dark [1]. According to the Post "Once you give it permission, an active app keeps on having access to your face until you delete it or dig into advanced settings. There’s no option that says, “Just for the next five minutes.”" So a random developer can (kind of) look at us when we turn the light off. Not only that, those cameras work also in the sunlight. You can go on…

App developers aren't given raw access to the IR camera though.
Post reply on HN