Live data from Hacker News

Google Sued Under Illinois Biometric Information Privacy Act

lexology.com

31–39 of 39 posts

Re: Google Sued Under Illinois Biometric Information Privacy Act

#31

We have a large client/customer in Illinois who has decided against using our voice sdk in their iOS/Android app because of the fear of getting sued for BIPA violation. It's not that they think we're creating voice prints without consent, it's just that their legal team has warned them that if they get sued, it could be very costly to defend. We even changed our privacy policy to note that "biometrics" are not obtain…

What about using truly on-device options that aren't connected to cloud services at all? Picovoice, DeepSpeech, etc.?

Re: Google Sued Under Illinois Biometric Information Privacy Act

#32

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

so they can't identify you, until they identify you and get your permission to identify you?

Re: Google Sued Under Illinois Biometric Information Privacy Act

#33

Earlier quoted context omitted.

Let's assume for a moment that the photo was taken in public. Normally, you don't have much expectation of privacy in public spaces. Generally, a photographer is free to take photos in public and use those photos as they see fit. Why is Google's use of your photo different than the photographer's use of the photo?

Why is Google's use of your photo different than the photographer's use of the photo? The law doesn't protect your image, it protects your biometric information. To extend your flawed analogy, a photographer isn't allowed to take a gigapixel photograph of someone in public and then use the data from their fingerprints or iris to uniquely identify them.

Would the photographer be allowed to identify using your face? This is pretty commonly done in newspapers.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#34

We have a large client/customer in Illinois who has decided against using our voice sdk in their iOS/Android app because of the fear of getting sued for BIPA violation. It's not that they think we're creating voice prints without consent, it's just that their legal team has warned them that if they get sued, it could be very costly to defend. We even changed our privacy policy to note that "biometrics" are not obtain…

What about using truly on-device options that aren't connected to cloud services at all? Picovoice, DeepSpeech, etc.?

[deleted]

Re: Google Sued Under Illinois Biometric Information Privacy Act

#35
post #32

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

so they can't identify you, until they identify you and get your permission to identify you?

> so they can't identify you, until they identify you and get your permission to identify you?

No; by default they (should) have no right to my personal data unless I explicitly opt in to it—and they shouldn't have a right to find me to ask me to use it, either.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#36
post #10

If a friend clicks a photo of me and uploads it to Google Photos, IMO, it's not okay for Google to use my face to train models without explicit permission from me. Unfortunately, as is often the case with technology, laws have not kept up with the lastest developments, and likely will not in my country for several more decades. Welp.

Just to be pedantic in the spirit of HN. Google isn't training models w/your face from your photo library. The way face recognition works is that Google would collect a dataset somehow and label that for the various feature and train a model for face recognition. Usually this is done with a carefully curated dataset that would be sure to include various ages, genders, ethnicities, lighting conditions, angles, and cam…

Google can guess that these 3 faces are the same, but it doesn't know for certain that they are

uCaptcha V3: “Click the people you know.”

Re: Google Sued Under Illinois Biometric Information Privacy Act

#37
post #20

Earlier quoted context omitted.

I have to point out that his exact argument has been made and rejected by the courts in multiple cases already. > Shutterfly maintains that by excluding data derived from photographs from the definition of “biometric information,” the Illinois legislature intended to exclude from BIPA’s purview all biometric data obtained from photographs... As Shutterfly acknowledges, if biometric identifiers do not include informat…

Interesting. My plaintext reading of the law interpreted "scan of face geometry" as a full 3D mapping (i.e. photographic plus infrared rangefinding), and I stand corrected on the intended reading of the text.

That is an argument which no one has tested in court yet. But it seems unlikely to succeed as the law doesn't specify any requirements on how “biometric identifiers” such as face geometry are collected. And indeed the courts appear disposed to allow the phrase to cover any extraction of face geometry data regardless of the technological means by which it is done.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#38

Earlier quoted context omitted.

Let's assume for a moment that the photo was taken in public. Normally, you don't have much expectation of privacy in public spaces. Generally, a photographer is free to take photos in public and use those photos as they see fit. Why is Google's use of your photo different than the photographer's use of the photo?

Why is Google's use of your photo different than the photographer's use of the photo? The law doesn't protect your image, it protects your biometric information. To extend your flawed analogy, a photographer isn't allowed to take a gigapixel photograph of someone in public and then use the data from their fingerprints or iris to uniquely identify them.

That sounds like a distinction without a difference.

I look at a photo, my brain tells me the photo is of "Bob", he's caucasian, male, with brown eyes. I enter this information in a spreadsheet.

Google algorithm looks at a photo, algorithm tells me the photo is of "Bob", he's caucasian, male, with brown eyes. I enter this data in a spreadsheet.

All Google has done is automate a process we were already capable of doing manually.

Edit - in my mind, the problem/question is people using photos commercially (or granting Google the rights to use commercially) photos they don't have legal rights to use that way. This would mostly apply to photos taken in private places. Photos taken in public can usually be used commercially by default.

Re: Google Sued Under Illinois Biometric Information Privacy Act

#39

Earlier quoted context omitted.

Let's assume for a moment that the photo was taken in public. Normally, you don't have much expectation of privacy in public spaces. Generally, a photographer is free to take photos in public and use those photos as they see fit. Why is Google's use of your photo different than the photographer's use of the photo?

> Let's assume for a moment that the photo was taken in public. This is a wrong assumption to make. What if the photos were clicked in my house? In a private gathering?

If it was taken in private, you have an expectation of privacy and the photographer is already legally prohibited from using the photo for commercial purposes. The photographer already should have obtained a commercial release.
Post reply on HN