Live data from Hacker News

Facial recognition: It’s time for action

blogs.microsoft.com

141–150 of 281 posts

Re: Facial recognition: It’s time for action

#141

This is a laudable first step in advocacy for real regulation of a technology that already has huge impacts on privacy and civil society. I was in the room for one of the meetings with Microsoft's senior leadership as a representative of a Seattle-based civil liberties group. While our coalition would like to see MS go further, it was quite clear that they take their commitment to corporate responsibility and ethics…

> He also denied that Amazon had any responsibility for the negative impacts of their AI/ML technologies, or role to play in industry efforts to self-regulate. For a period of time, there was a lot of chatter about all developers having some kind of professional oath, like doctors. Many of the approaches that were taken have issues (preclude working on smart weapons program or legal surveillance). I wonder if what we…

Worth noting the Project Managers who are certified "PMP"s attest to a code of conduct that includes: "take actions based on the best interests of society, public safety, and the environment." It requires that PMP's report any unethical practices to "appropriate management". Pretty weak, but hey, it's better than nothing.

Re: Facial recognition: It’s time for action

#142
This document is very thorough; yet it misses a key point. IMHO, the primary concern here is not the algorithms that produce outcomes and regulating those but what happens to the resulting data streams as well as the raw input for the algorithms. Simply storing huge amounts of video footage means you can later run algorithms as they improve or become available. It's the act of storing and exchanging data that is problematic not running algorithms against that data. You might even capture data before algorithms are invented/available to process that data or use new algorithms against historical archives of data to extract new information.

What are the implications of the right to be forgotten on e.g. security camera footage that is stored for weeks or months or even longer. The raw data contains personally identifiable information, given the right algorithms and access. Mining and correlating information from raw data that so far is considered innocent changes the game completely. Somebody with access to isp data logs, cell tower logs, and security footage in buildings, on streets, etc. can start looking for patterns in that data and cross verify and correlate events between data sets.

Recent history in China teaches us that this is neither science fiction nor an imagined risk. China is quite openly implementing mass surveillance using all means available to them and they are already using it to control their own citizens.

IMHO the focus for legislation should be on legislating not the right to be forgotten, because that is inherently hard to enforce and impractical, but instead on ensuring data capturing parties stick to strict rules with respect to auditing and securing access to that data, retention, transparency of their policies regarding all of this, and making sure serious violations have consequences.

Additionally, any surveillance data used in a court of law needs to have an impeccable auditing record proving it was captured and handled lawfully. One critically important aspect here is also ensuring the data has not been tampered with in any way: algorithms to falsify information are also becoming a risk. Capturing data that may be used for privacy invasive analysis creates a duty to adequately handle and protect that data. This should not be optional.

The key to enforcing this is sousveillance: observing the observers. This should be both legal and common. In a world where there is multi lateral surveillance by multiple groups of people, companies, and governments, hiding undesirable behavior/actions is going to be increasingly hard and you can never be sure that nobody is watching whether you are a citizen, chief of the secret police, or a head of state. Surveillance is a double edged sword and abusing it might be observed by others. The 1984 type scenarios always assume a single evil government doing all the surveillance in secret. So, we should make sure governments themselves are equally exposed to surveillance in order for us to ensure that they do not abuse their level of access to surveillance data.

Re: Facial recognition: It’s time for action

#143

This is the first instance I've seen of the tech industry calling for regulation. I admire this and the idea that people running a corporation can understand that despite their best intentions, in the long run the corporation will act to maximize profit via legal means, even if an action is not in the best interest of society. And so in some cases we need to make certain things illegal. I would love to see a company…

Maybe I'm just reading into it, but this looks like: a) Anti-AWS (conceding loss of JEDI contract) b) Regulatory capture for the remaining big cloud players

I think you are close or exactly on target.

Re: Facial recognition: It’s time for action

#144
post #59
post #54

Earlier quoted context omitted.

My gym also uses facial recognition, but does it via a person sitting behind a desk checking that my member ID matches my face. I don't think many people are uncomfortable with this process, and this biometric method has been used for a long time.

Yes, but that person can't copy your biometric data stored in their brain, convert it to a standardized format, and distribute it to millions of other devices.

>and distribute it to millions of other devices...

Or just hundreds of other organizations and corporations.

Re: Facial recognition: It’s time for action

#146
post #121

Earlier quoted context omitted.

A car’s primary function is not to kill people. If you are an engineer and develop a tool whose primary purpose is mass surveillance, you should bear that ethical burden.

And yet, cars kill many, many more people (1.25 million in 2013, per WHO) than mass surveillance does. And parent didn't qualify his statement as to which products the oath would apply to: "Anything I build can and will be abused. I am responsible for my designs, for my products, and for the data I collect and store. If my technology is used for evil, I am responsible."

Mass surveillance does something a lot more insidious than car wrecks, it sets up a future where people are killed. It's like global warming.

Re: Facial recognition: It’s time for action

#147

Earlier quoted context omitted.

>> This is a laudable first step in advocacy for real regulation of a technology... Perhaps I'm jaded, but I don't agree at all. They're trying to get it regulated so they can be creepy without fear. One of the first "good" uses listed was finding 3000 children. "Think of the children" is a common rallying cry for evil. Nothing else mentioned was really relevant. The line IMHO needs to be drawn at anything that you'd…

That's a really good line in the sand, and relatively practical as well. Unfortunately, I don't think it will be put into the books with all the interests corporations would have in keeping it out.

Really?! I don't think it is a good line in the sand. Because even though we can draw lines around how an AI might act like a human in a certain case, recognize you as a frequenter of a store, when we connect that AI to the rest of the computer capabilities out there it quickly becomes something a human couldn't do. A convencience store clerk might remember several dozen, even several hundered frequent customers but it tops out somewhere. And after some time the clerk will forget many of those who stop coming in. But an AI with a database for recollection suffers from neither of those issues. But you might say the recall has nothing at all to do with what the AI is basically doing. We have to look at this much more wholistically.

Re: Facial recognition: It’s time for action

#148

Earlier quoted context omitted.

Microsoft knows how to talk the enterprise talk. BTW, Amazon competes against Alibaba for their main business, not Microsoft.

Just to clarify: Amazon's "main business" is AWS, not their online store. For many years their store operated at a loss. Don't get me wrong, amazon.com is a HUGE business, but it's not Bezos' breadwinner. https://www.zdnet.com/article/all-of-amazons-2017-operating-...

It only operated at a loss because they were plowing massive amounts of money into their delivery infrastructure. Revenue matters more than net income

Re: Facial recognition: It’s time for action

#149

Biometrics are creeping into everyday life. One of my local gyms this week switched to requiring fingerprints or you were barred from access. Another local gym uses facial recognition for entrance, although you can choose to have a member card instead if you ask for it directly, they don't list it as an option. Thankfully in the EU we have GDPR. It considers biometrics as a similar sensitivity to medical data, so unl…

One of my local gyms this week switched to requiring fingerprints or you were barred from access If this is a membership gym with contracts, wouldn't they have to wait until your next contract to impose such a change?

I'd say probably not, but it would likely allow you to cancel your membership early (and receive paid fees back, pro-rated).

This is actually a nice hypothetical for that idiotic vision of replacing law and the court system with algorithms. It's extremely unlikely that the specific case would be foreseen in a contract. There is a continuous spectrum of such changes, and it's impossible to formulate any specific rule that would capture them all.

Example A: The gym changes from keys to plastic membership cards. Would this be a breach of contract? I think most everyone would agree that no, it isn't.

Example B: The gym requires whole-genome sequencing (once), then requires a drop of blood every time you enter to check your identity? Breach of contract? -> Obviously.

For any two such changes, you can probably come up with yet another example that's somewhere in between. The closer they get, the more often you will find people disagreeing, yes. But that just shows how justice is a constant conversation not easily set in stone.

As for the specific case: European law really doesn't like biometric data, and it's unlikely they can get away with it.

(the following is based only on my knowledge of German and Portuguese law)

BUT, ) if they do, the pro-rated refund is the most likely outcome. It works both ways, though: if you move away, they also cannot require you to keep paying fees. It's a concept loosely translated as a "cessation of the foundational requirements of the contract).

Re: Facial recognition: It’s time for action

#150

Earlier quoted context omitted.

>Total citizen surveillance is coming, everyone's location history will be in a database and kept for years, just like phone call metadata. I am under the assumption that it's already here since whoever carries a mobile phone is already under surveillance since the mobile networks share info with the government, the license plate readers see who is traveling on the roads, and electronic financial records show your tr…

I use cash, public transport (which is awesome in Europe), almost always have my cellphone switched to airplane mode (going online via WiFi occasionally e.g. to check for new messages) and only turn its GPS on about 5 times a year for rather short durations of time and am pretty happy.

FYI, Google tracks you even on airplane mode. So the second you jump back on Wifi your location history is updated. With dead reckoning calculations using your accelerometer and other sensors they know EXACTLY where you've been.

Not sure if they do this on iPhone or just android, but my guess is they do both if you've installed google maps/gmail etc.

https://www.youtube.com/watch?v=S0G6mUyIgyg

Post reply on HN