Live data from Hacker News

I got my file from Clearview AI

onezero.medium.com

181–190 of 237 posts

Re: I got my file from Clearview AI

#181

Bit of a rub that to request your messy, potentially erroneous, public profile, you have to give private, authenticated identification and contact information - basically the most valuable information they could want, dramatically increasing the value of your profile that you were so concerned about in the first place.

Came here to say this. Do any of the privacy laws allow for deleting your profile without proving to the company who you are? Could you have the government make the request on your behalf? Sending Clearview your license sounds like confirming your credentials in a haveibeenpowned-like honeypot. Seems irresponsible for the author to even suggest that to readers. There should be other ways.

Re: I got my file from Clearview AI

#182

Bit of a rub that to request your messy, potentially erroneous, public profile, you have to give private, authenticated identification and contact information - basically the most valuable information they could want, dramatically increasing the value of your profile that you were so concerned about in the first place.

Its probably because for clearview its the only way to know that it is indeed you who is asking for information on yourself.

I asked this in a sibling comment to yours but couldn’t the government, who issued your ID in the first place, make requests on your behalf to enforce the privacy laws they’ve created?

Re: I got my file from Clearview AI

#183
post #65
post #64

Earlier quoted context omitted.

Just for the record, the journalist who broke the story on Clearview noted that Clearview AI has specifically demonstrated it isn't fooled by thispersondoesnotexist.com: https://twitter.com/kashhill/status/1218542846694871040?s=20 You won't be giving them any info on you, but you won't be confounding them either.

True, but at least it prevents them from linking accounts. It is equivalent to no profile picture, which you might not want to keep up appearances.

You may be surprised to learn that your face is your least identifying trait online. You network of friends/followers/likes identifies you far more readily—even if you use a random username.[1]

Managing your privacy is a lot like CPU side channel attacks. It forces you to re-evaluate your fundamental assumptions about what information can be exploited.

[1] http://www.vldb.org/pvldb/vol7/p377-korula.pdf

Re: I got my file from Clearview AI

#184

Earlier quoted context omitted.

Because the general public doesn't care enough to raise a stink? Back when Snowden story broke, I tried explaining its significance to a handful of my friends - all I got was a yawn. These are not dumb people, they are smart professionals (non-IT). Even then, I failed to get the point across to them. It would require some serious education before the public wakes up to the dangers of private companies running amok wi…

> It would require some serious education before the public wakes up to the dangers of private companies running amok with their data. Exploitation is the best education there is. Everything is fine until it isn't. One day, companies and governments are going to start doing things with personal information that are unacceptable to even the average person. By then, it will probably be too late.

Case in point: The Nazis used census records to identify Jews. Who knows what pieces of personal information the next madman will consider relevant. They'll certainly have much more of it to choose from.

Re: I got my file from Clearview AI

#185

Earlier quoted context omitted.

What specific violation do you have in mind? Google has been fined $5B for various non-GDPR violations.

Have they paid any of it? FCC has fined robodialers in the hundreds of millions but only managed to collect a fraction of a percent.

The difference being jurisdiction. Google operates within the EU. Most robodialers targeting the US are not in the US.

Re: I got my file from Clearview AI

#186
post #141

So the difference between this an google‘s reverse image search is that google‘s matching algorithm is worse (probably because it doesn‘t include facial recognition)? Well, public images are public and I don‘t think banning such a service would prevent governments from implementing something like this .. the technological challenges are getting less and less.

You can presumably hold government officials accountable, but you can’t vote out the CEO of Clearview.

Re: I got my file from Clearview AI

#187
Nobody should be posting their private data (pictures or videos, for instance) on a publicly accessible site if they want privacy. Look, if you want your relatives, friends, and even acquaintances to see whatever you want them to, just do it through a medium that allows for private communication. It's just common sense.

Re: I got my file from Clearview AI

#188
post #64

Earlier quoted context omitted.

Just for the record, the journalist who broke the story on Clearview noted that Clearview AI has specifically demonstrated it isn't fooled by thispersondoesnotexist.com: https://twitter.com/kashhill/status/1218542846694871040?s=20 You won't be giving them any info on you, but you won't be confounding them either.

I'm not sure what is not working-as-intended here? Run facial recognition against computer generated face, got no matches. Surely that is the expected and intended result from both parties? Or is it expected to match against a different face?

They might have already scraped all of the faces on that site. They aren't generated on demand so you conceivably scrape the entire database of fake people and tell the algorithm to ignore anything matches them. Then, the algorithm would just treat any photos of a person that doesn't exist that it finds in the wild as it would if you have no profile pic. It might fool a person or an AI not trained on those pictures. Another option is to generate your own people that do not exist and use those images. This could work as long as Clearview isn't doing some sort of image analysis to look for telltale signs of AI-generated faces. You could start photoshopping fake faces onto your real pictures in an effort to blur the line between AI generated pictures and real pictures.

Re: I got my file from Clearview AI

#189

Earlier quoted context omitted.

Because the general public doesn't care enough to raise a stink? Back when Snowden story broke, I tried explaining its significance to a handful of my friends - all I got was a yawn. These are not dumb people, they are smart professionals (non-IT). Even then, I failed to get the point across to them. It would require some serious education before the public wakes up to the dangers of private companies running amok wi…

Is potential surveillance by government entities the primary reason you are against companies generally doing whatever they want with user data? Are there other rationales? Just like your friends, I personally don't particularly care either, but from time to time I have tried to understand the privacy crowd's obsession with this issue and the rationale behind laws like the GDPR and CCPA, as well as the desire for eve…

> Are there other rationales?

Yes. The fundamental issue is the total lack of respect for the user's consent.

People usually have no problem with volunteering personal information that is relevant to whatever activity they're trying to accomplish. For example, a company will need people's addresses in order to ship products to them. This is a voluntary, explicit and respectful process: consumers willingly and knowingly give the company copies of the information they need to perform the service and the company uses that information only for its intended purpose and absolutely nothing else.

The problem we face today is that businesses are collecting massive amounts of personal information indiscriminately, invisibly and without true consent. Web browsers hemorrhage personal information without them even asking and there's no way to stop it. Companies make apps that mine people's phones for every last bit of data they can get their hands on. Web sites put up annoying little banners saying they collect data and call it informed consent even though there's no way to say no. They bury some clauses in a terms of service nobody reads and say the user agreed to it by continuing to use site even though cookies were set and fingerprinting was performed on the very first visit before the user could possibly have known about much less read the contract.

Not only that, the information is being abused to do things people don't actually want. When people give a company their email addresses, they assume they will receive messages that are actually important. What happens is the company thinks it has every right to spam people with marketing and advertising emails or sell their data to other very interested parties. People give a company their phone numbers and next thing they know they're getting marketing calls they never asked for and can't opt out of.

And then there's the security issues. If someone has information about people in a database, there's always a chance it can be leaked even if every precaution is taken. The potential for harm is significant. Data should be considered a liability for companies. Knowing things about people should cost them money. They should have ample incentive to collect as little data as possible, limit the scope and frequency of the use of whatever data they collect as much as possible and delete that information as soon as it is no longer needed. What's happening today is the complete opposite of that: companies are collecting as much data as possible, keeping it forever and using it for whatever makes them the most money regardless of people's wishes.

These examples are relatively benign but the potential for harm is always there. What if companies start buying up personal information and using the data to profile and exclude candidates? No doubt information such as browsing history would condemn a huge number of people. What if companies find a way to deanonymize that data and link it to candidates?

Re: I got my file from Clearview AI

#190
post #112

Why is there no arrest warrant against the managers and owners of Clearview here on the EU? They are using PII of hundreds of millions of Europeans without written consent. That alone should mean billions of euros in fines.

Because the general public doesn't care enough to raise a stink? Back when Snowden story broke, I tried explaining its significance to a handful of my friends - all I got was a yawn. These are not dumb people, they are smart professionals (non-IT). Even then, I failed to get the point across to them. It would require some serious education before the public wakes up to the dangers of private companies running amok wi…

> Back when Snowden story broke, I tried explaining its significance to a handful of my friends - all I got was a yawn. These are not dumb people, they are smart professionals (non-IT). Even then, I failed to get the point across to them.

If you were unable to convince multiple smart people who you care about / respect, then perhaps it is time to at least considere the possibility that your position is incorrect?

Post reply on HN