Live data from Hacker News

Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

wired.com

211–220 of 407 posts

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#212

Earlier quoted context omitted.

> Apple doesn’t backup TouchID or FaceID data to the cloud We only have Apple's word to go by.

No, we don't. https://hackaday.com/2017/08/18/apples-secure-enclave-proces... Yeah it may be a binary dump, but it's now decrypted and understandable.

Serious question: can its firmware be upgraded through future device updates?

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#213
post #83
post #31

Earlier quoted context omitted.

> and it's obvious why. Because most countries don't have crypto-secure identity verification, which means Facebook would still need something like this? I suppose they could contract out to Experian (or other local providers) and ask you to answer some questions from your credit report, but I'm not sure that's really a good solution either.

I thought it was clear enough that I mean't that it's obvious why [Facebook will never implement it even in countries where it already exists]. It's not in their interest to do so, because it's not in their interest to protect the privacy of their users.

Just because you could only think of a sarcastic reason why Facebook doesn't want to do it doesn't mean that other reasons for it don't exist. That's precisely what the GP is saying—FB needs to come up with systems that work for literally the whole world.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#214
post #185

Earlier quoted context omitted.

Hash your copy of the nude image client side, and upload the hash only? Seems like a way better idea to me.

A hash would only match an identical file, right? It sounds like image recognition is used here to catch derivatives of the original file, which a hash wouldn't catch.

I think it would be easy to create multiple hashes (reverse, flipped, etc...) and upload them all and look for matches. Provide the users with image recognition signature creating software (which is exactly what they are going to do) and let the users do it, vs uploading extremely personal and potentially embarrassing images to strangers on the internet.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#215
post #181

Earlier quoted context omitted.

Or indeed care about the law enough to bother before they're fined for doing it. After all you'll need to prove they didn't delete the data first!

The GDPR penalties can reach 4% global (i.e. sum all related companies) annual turnover per infraction . If anyone ever found out Facebook had a widespread violation, Facebook would be likely be dissolved.

I wish US corporate laws had teeth, it's only the criminal ones that apply to every day citizens that do.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#216

I was recently locked out of my FB account. The only way to unlock it was to identify my friends' pictures. Apparently sending me an e-mail was too much trouble ... Haven't been able to log in since, as I refuse to partake in that sort of bullshit. Can't say I miss it.

What do you have against identifying friends' profile images, of all things? Facebook already has them.

FB doesn't necessarily have the names of everyone in all those photos.

I wonder if they would ever do something like show you three photos of friends as the captcha, but they only know the answers for two of them and are using the third to get you to give them info they didn't already have without you knowing.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#217

Earlier quoted context omitted.

Or indeed care about the law enough to bother before they're fined for doing it. After all you'll need to prove they didn't delete the data first!

Someone in Europe should make a privacy complaint just to keep them on their toes.

You mean to step on their toes.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#219
post #151

I used to think richard stallman was just a paranoid lunatic... Well, the more time goes by, the more i think he was just 100% right. It's time to be much much more careful and radical with the path technology is taking us. It's time we all invest a bit of our time to provide real open and benevolent alternatives to facebook, google, amazon, and all the rest, because they're steering internet toward an orwelian night…

There are existing social media alternatives to facebook, such as: gnu social; postActiv; mastodon; diaspora; hubzilla; etc.

Re: Facebook’s New Captcha Test: 'Upload a Clear Photo of Your Face'

#220
post #78

Last paragraph of the article: "The new authentication scheme is the second in recent weeks that relies on photos. Earlier this month, Facebook asked users to upload nude photos to Facebook Messenger, as part of an effort to prevent revenge porn. Facebook said it would use the nude photos to create a digital fingerprint against which to compare future posts." Wait what? I had to check whether today was April 1st.

There was a thread about this on HN -- too lazy to look it up now or repeat some of the longer comments about it. But going into this assuming that FB has no ill-intentions, FB's proposal seems by far the best solution in a world of ugly and terrible solutions. For starters, it's intended for victims of revenge porn, which is a fairly extreme category and one in which the harassment is distinctively aggressive and vi…

> ... it's hard to think of an implementation that wouldn't create a potential disaster that justifies doing anything special for revenge porn victims. > ...Having the user hash on their own requires either an external app or website.

What? Why can't the hashing take place in the FB Messenger app on your phone? Why does the picture need to be uploaded to FB's servers? That just goes to what Troy Hunt was saying earlier today in his testimony to Congress about how corporations are collecting data that they shouldn't even want to have. They should collect only the hash from your phone, not the picture. The hashing should be done locally to your device.

Post reply on HN