Showing posts with label biometrics. Show all posts
Showing posts with label biometrics. Show all posts

Wednesday, July 03, 2019

Biometric Blues: Facial-recognition tech starting to be good enough to threaten privacy

Several recent items related to the use of facial recognition technology by law enforcement caught Grits' eye lately:
The rise of facial recognition and other biometric identification technology was an early hobbyhorse on this blog. I stopped covering the topic after civil libertarians lost all the big, related fights at the Legislature over gathering biometric data, particularly from Texans' driver's licenses. (Texas allowed DPS to gather Texas drivers' fingerprints and facial-recognition biometrics from their licenses then almost immediately began to hand the data over to the federal Department of Homeland Security.) But those were bitter, memorable battles, with the losses made more palatable only by the reality that, back then, facial-recognition tech simply wasn't ready for prime time and didn't work well enough to threaten privacy.

Today it's closer, but not quite yet there. But that utilitarian excuse for not confronting totalitarian surveillance tech will soon fall away. Even if facial-recognition is reliable, it's a bad idea as a generalized surveillance tool. So, arguments against it must ultimately rest not on the prospect of errors (right now, they have higher error rates when identifying racial minorities), but on the prospect of privacy vanishing, and a new form of high-tech totalitarianism rising, if the product were to ever work perfectly.

For more thoughts and background on the subject, here's an old blog-post series I wrote headed into the 2005 Texas legislative session:
Looking back, much of it still holds up.

Wednesday, September 17, 2014

Cops, prosecutors, raise white flag, vow to fight on warrants for cell-phone location data

I only saw two news outlets covering electronic privacy debates at the Texas Senate State Affairs Committee meeting yesterday:
The meeting was led by new Chairman Craig Estes who last session sponsored legislation to require a warrant for cell phone location data. See my own written testimony to the committee on behalf of the Texas Electronic Privacy Coalition. The key TXEPC recommendations, fleshed out in greater detail in the full written testimony, included themes familiar to Grits readers.:
  • Require law enforcement to obtain a search warrant to obtain historic cell-phone location data.
  • Require a warrant to install GPS tracking devices on vehicles.
  • Centralize use of 'stingrays,' aka, IMSI catchers at DPS the way the state does wiretaps and require a warrant for their use.
  • Limit data retention on innocent drivers for automatic license plate readers, limit access to the databases to trained, authorized personnel, and restrict sale of data.
  • Evaluate the Department of Public Safety's unilateral decision to take all ten fingerprints when drivers obtain or renew their licenses based on potential privacy violations involving personal electronic devices using fingerprints in lieu of passcodes.
A big highlight for me was expert testimony by Chris Soghoian, a tech expert now working for national ACLU whose dissertation (pdf) first broke open this issue and spawned my own interest in these location-data issues. Thanks, Chris, for coming down!

The hearing took a strange turn, as prosecutors and a detective from the Houston Police Department insisted that changes to state law last session meant law enforcement already had to get a warrant to access cell phone location data. I'm not a lawyer, but that seems downright bizarre since the bill to require a warrant for location data failed; only content, not "metadata" (as it has come to be called post-Edward Snowden), was protected in the language that passed in HB 2268.

The prosecutors' new stance is especially odd because two different Texas appellate courts ruled in recent months affirming no warrant is currently required in Texas to obtain historical cell-phone location data. The US Fifth Circuit Court of Appeals ruled the same way, creating a federal circuit split. (See a related, earlier Grits discussion.) Indeed, the portion of Sec. 5 in Art. 18.21 of the Code of Criminal Procedure that the Fourth Texas Court of Appeals decision in Ford v. State relied upon was not changed in the amendment to HB 2268 requiring warrants for content. I just don't understand how that claim can be justified.

A case summary of Ford on the prosecutors association website even recommended their members rely on the case for precedent in the future ("Because there is precious little caselaw that construes Article 18.21, this decision could turn out to be helpful to others on that basis as well"). And in Barfield v. State, police obtained cell-phone location with an administrative subpoena and Texas' 14th Court of Appeals in Houston upheld it being admitted into evidence. (The Department of Insurance testified that it, too gets cell-phone location data with only a subpoena.)

There appear to be no court cases supporting this novel view that Texas law already requires a warrant to access cell-phone location data. Its proponents could not even provide examples of local district judges suppressing location data, nor of any jurist denying police access to this information. All they offered were hypotheticals.

But no matter how often they kept repeating that the law requires a warrant now, your correspondent simply sees no evidence for the claim. Again, I'm not a lawyer. But attorneys for service providers like Data Foundry and Golden Frog also insisted that warrants are not required in Texas presently for law enforcement to access location data. And that was certainly the universal, contemporary understanding at the time the 83rd session ended. Just a weird debate to have.

The Observer piece by Eric Nicholson summed up the odd tenor of the event thusly: "The debate over whether warrants are currently required is a bit of a head spinner. (Cops are in the paradoxical position of arguing both that warrants are necessary to obtain cell-phone metadata and that they will fight efforts during the 2015 legislative session to require warrants for cell-phone metadata.)" To be sure, I hope they're right and I'm wrong. I want a warrant requirement for these records in Texas (and nationally, though your lowly correspondent can't do anything about that). But until the judiciary agrees a warrant is required, it's hard to buy what police and prosecutors were selling at yesterday's State Affairs hearing.

Go here if you'd like to watch the whole thing online.

MORE: I was interviewed this afternoon along with Rep. Bryan Hughes on the Texas Public Radio show The Source about yesterday's hearing and location tracking issues generally. Go here to listen to the broadcast.

Monday, November 04, 2013

On the folly of fingerprints as cell-phone security

Of all the biometrics for Apple to choose to use as security on its new iPhone 5, fingerprints seem like an ill-considered choice that makes phones less secure. After all, to a computer, fingerprints are nothing but ones and zeroes - data like any other transmitted to unlock the system. And unlike passwords, you can't change your fingerprints once someone else has hold of them.

So, in an era when National Security Agency surveillance seems to constantly make headlines, why choose a biometric where the government possesses databases with millions of Americans' fingerprints on file - of everyone who has ever been to jail, applied for security clearances, undergone background checks for licensing, etc.? Even if the government doesn't misuse it, Edward Snowden's example shows such information can potentially walk out the front door, on a thumb drive or otherwise. Indeed, as far back as 2005 this blog warned that "Biometric passwords risk gravest form of identity theft," and that was before the smart-phone boom.

The Texas Department of Public Safety at one point wanted to gather all ten fingerprints from drivers license applicants, but in the end settled for gathering only thumbprints and facial recognition data - information they promptly shared with the federal government through a state fusion center as soon as they began to gather it.  Even without fingerprints of every driver, though, the government has access to enough people's fingerprints to make their use as a security measure decidedly insecure.

Wednesday, June 12, 2013

Forensic follies, Williamson County jury pools, COINTELPRO, and other stories

Grits noticed several items this week that didn't make it into full posts but deserve readers' attention:

Lawsuit over constitutionality of truancy charges
Texas Appleseed is taking Dallas ISD to court. See a lengthier account from the Dallas Morning News, but it's behind their paywall. More from Alternet.

The Michael Morton case and Williamson County jury pools
Because of hometown publicity, a capital murder case was moved from Waco to Williamson County, only to find during voir dire that "About 10 prospective jurors out of 55 questioned so far either were disqualified or excused by agreement because of their feelings of distrust for the criminal justice system spawned by Morton’s 
exoneration," reported the Waco Tribune Herald. That's a pretty remarkable development among Williamson County juries.

Art in public spaces - like utility boxes
Grits has advocated allowing invited, artistic graffiti in blank public spaces from utility boxes to the backs of street signs to highway facades. That seems to be the idea behind what's going on here, with the twist that the artist is a Buddhist monk.

Ellis County may privatize jail
The Ellis County (Waxahachie) commissioners issued an RFP to privatize their county jail, we learn from Texas Prison Bidness. More background here.

Most TDCJ volunteers are faith based
Reported the Conroe Courier, discussing a bill by rookie state Rep. Steve Toth, "TDCJ currently has 20,047 volunteers, including 18,111 who are faith-based volunteers providing religious and other services in jails and prisons statewide"

'Breathprint' as biometric?
Interesting concept. Probably needs more confirming research and field testing before it's ready for use as a practical, reliable, court-worthy forensic method. Despite the statement in the linked article, I'm not yet sure I believe claims that breathprints can be uniquely identified. My understanding is it hasn't even been proven fingerprints are unique in the world, much less "breathprints."

Allegedly fake certifications may compromise 1,200+ DWI cases
Even if "breathprint" biometrics are legit, the technical application of breath forensics must be also be valid. A DPS supervisor in Conroe, "Glenn Merkord was suspended for 30 days this month for renewing certifications for machine operators who had not fulfilled all of the requirements for certification, according to a letter the Department of Public Safety sent Merkord notifying him of his punishment," reported the Houston Chronicle. Up to 1,200 cases could be affected.

Salvador cases keep coming
Nuther case overturned today by the Court of Criminal Appeals based on the Jonathan Salvador case, this one an eight year sentence. By my count, that brings the total to 20, totaling 159.5 years so far. Now that the Coty case has been decided, one suspects we may see many more, similar cases on the weekly hand down lists in the very near future. Salvador worked on nearly 5,000 drug cases.

From the COINTELPRO files
Interesting, timely history lesson from the Austin Chronicle about a time just a few decades ago when the American intelligence apparatus was turned on domestic political dissidents, focusing on events at UT-Austin.

Edward Snowden, NSA phone spying scandal and cell-phone location data
Bruce Schneier lists questions that need to be answered before anyone prosecutes Edward Snowden. Ed Hubbard, writing at Big Jolly Politics, has questions of his own. Interesting post from Fabius Maximus on the meaning of government and corporate protestations the NSA does not have "direct access" to private systems. The telecom providers like ATT and Verizon, incidentally, have issued no such denials. Finally, somebody started a petition at whitehouse.gov asking President Obama to pardon Edward Snowden. Go sign if you support it. If the petition gets 100,000 online "signatures" in 30 days, the White House will formally respond. As of this writing, it had reached 68,435 in just four days.

It should be noted, the issue of cell-phone "metadata" relates directly to the location-tracking legislation proposed by Rep. Bryan Hughes, Sen. Juan "Chuy" Hinonosa and Sen. Craig Estes during the 83rd regular session. In particular, as Grits reported from the conference at the Yale Law School on location tracking and biometrics, Verizon and Sprint use GPS coordinates instead of triangulation (like, say, ATT and T-Moble). The Wall Street Journal reports the NSA is gathering credit card data, too. That's an even greater invasion of privacy IMO than the pen-register/trap-and-trace data (phone numbers in and out) that's been more widely publicized.

Sunday, May 19, 2013

Nearly 200 Texas LEOs use license-plate-reader location tracking vendor

When George Orwell wrote the novel 1984 he was imagining future totalitarianism dominated by socialist governments. He never considered that technologies of control would be privatized in a capitalist system, but that's seems to be where we're headed. Via Privacy SOS:
Did you know that a private company which hoards detailed information about your driving habits also has plans to create the largest private sector law enforcement database in the world, by combining plate reads with commercial databases, face recognition technology and more?

Vigilant Video is a private corporation. It maintains a database called the National Vehicle Location Service (NVLS), containing hundreds of millions of data points showing the travel patterns of millions of people in the United States. The data in the system comes from a variety of sources including government agencies, other companies like tow truck and repo firms, and a fleet of company cars that drives around sucking up license plate information on our streets and in our neighborhoods
Grits went to look at the registration page for the service and found their clients on a dropdown list. Though they're not broken out by state, by my count, around 200 Texas law enforcement agencies are clients of Vigilant Video and use its vehicle location tracking services, as well as loads of federal customers. The Immigration and Customs Enforcement (ICE) office in Dallas was among their first clients when it rolled out last year and now many others, from the IRS to the Air Force, are on the list. Among Texas state agencies, the Department of Public Safety, the Attorney General, TABC, TDCJ, TCEQ, the Department of Insurance and UT-System police departments (individually and collectively) all subscribe to the service.

All the big city police departments in Texas subscribe to the service - Austin, Dallas, Fort Worth, Houston, San Antonio, and El Paso - as well as the corresponding sheriffs and district attorneys offices in those counties. But dozens of smaller jurisdictions use them, too, from Nacogdoches to Refugio, Denton to Del Rio, from Sherman to Sugar Land. Even some constables and school district police are getting into the act. Unfortunately, one can't tell how frequently they used the service without filing an open records request with the various departments for invoices from the company for its use.

This for-profit service demonstrates how outdated 20th century conceptions of privacy need significant updating in the wake of a swiftly changing technological landscape. According to Government Security News, the company plans to quickly expand its database into biometrics: 
Surpassing the challenges of a national LPR database via NVLS, our future roadmap plans an extensive integration between LPR data and public records, a facial recognition platform, and ‘leaps and bounds’ expansion of LEARN which seamlessly ties together all data sources. We are on schedule to provide the most advanced Law Enforcement criminal database loaded with billions of records -- a universal data system with one common goal in mind -- making it easier for Law Enforcement to ‘Catch the Bad Guy’.
Except, one might quibble, the overwhelming number of people whose information makes up their database aren't "bad guys." There are lots of uses for this data besides just that. For example, Grits could see such a database eventually commercialized for use by corporate marketers, or for that matter for more nefarious purposes.

Though most people don't think of it that way, location data is the ultimate biometric. One may have plastic surgery to throw off facial recognition systems or blot out fingerprints with scarring or acid. But there is nothing more unique about an individual than their location - where they are at any given moment - because two things cannot occupy the same space at the same time. A growing body of research shows that even a small number of location points can tell a great deal about a person and the license plate recognition function instantly attaches that location data to an individual (or at least their vehicle).

License plate readers blur the lines between public and private information, calling into question outdated Fourth Amendment doctrines holding that Americans have virtually zero expectation of privacy outside the home. In US v. Jones last year, five US Supreme Court justices agreed for the first time that long-term location tracking without a warrant can violate someone's reasonable expectation of privacy. But it will be years before the courts, on a case-by-case basis, elaborate the extent and limits of those expectations, particularly when mediated through a third-party vendor as in this case. The folks compiling this database know the courts wouldn't allow law enforcement to gather all this data on innocent people so their business model relies upon exploiting a court-created loophole to let a private vendor do it. They're still agents of law enforcement, though, even as contractors.

License plate readers are all-but-unregulated technology with enormous implications in the coming years for personal privacy. There should be strict retention limits on use of such data and prohibitions on government sharing it with private vendors, which appears to be from whence the bulk of their information comes.

Thursday, May 02, 2013

Surveillance cameras and signage

This morning I went to testify in the Texas House Homeland and Public Safety Committee for a quirky little bill, HB 3165, by freshman state Rep. Jon Stickland, which essentially has two parts: 1) It would require local governments to post signage at surveillance cameras that declare, e.g., "Warning, you are under Surveillance by the City of Dallas." (Could we amend that, I wonder, to require an exclamation point?) And 2) it would require local governments to post live feeds of all their surveillance cameras online. Quite a piece of legislation, that! Not something I was part of bringing forward but the bill author asked if I'd speak on it and having nothing else pressing on my agenda at 8 a.m., I thought, "why not?" What follows is a summary of my testimony.

First, I argued to the committee, requiring signage would increase the deterrent value of the cameras and therefore increase public safety. Studies in the UK, which as chairman Joe Pickett pointed out is the most surveilled nation on the planet, have found very little crime fighting bang for the buck from cameras. They are most effective for use on high-value targets and then only if they're monitored in real time. Indeed, I told the committee, if the goal is public safety and you had to choose between the camera and the sign, Rep. Stickland's sign would probably do more to reduce crime than the camera. Rep. Dan Flynn agreed, noting that banks he'd worked at routinely posted signs advertising cameras were watching without the cameras actually functioning, at least until federal law began to require them to have working surveillance units. Merely advertising cameras' presence was generally considered sufficient deterrence.

During Rep. Stickland's opening, Chairman Joe Pickett asked about cameras at the Boston Marathon bombing, wondering what would have happened if the attackers had seen one of Stickland's signs. I raised that example again, suggesting that it was possible the bombers, who after all were relatively young, would have moved to a spot where there was no signage. Well, what if there were surveillance all the way down the last half mile of the marathon route? Then the signs, if they'd been in place, might have served to move the bombers out of the area with the most people. You never know. Otherwise, I reminded them, because of personal cell phone cameras, businesses surveillance footage, etc., there were plenty of pictures from every imaginable angle. The difficulty was isolating the culprits.

Rep. Kenneth Sheets thought it unnecessary and potentially distracting to put such signs near traffic cameras. I replied that a sign saying their driving was being monitored by camera might make people drive better, but allowed that perhaps a carve out could be made for traffic cameras, especially if limits were placed on law enforcement uses like license plate identification, facial recognition software, etc..

In the bigger picture, I pointed out, though the bill author wasn't around to remember it, Stickland's bill amounts to pushback against a bad law passed in 2003 in reaction to 9/11 that made all information about surveillance cameras a closed record: Where they are, specs of the instruments, policies for how the images will be used, who has access to them, etc.. Rather than make the back-end records public about where the government has surveillance cameras, which is what we lost in 2003, Stickland's bill would put the information in your face everywhere you're surveilled, which is a lot of places! Still, in a real sense this bill amounts to an extreme antidote to the opacity regarding surveillance foisted on Texans after 9/11.

Technology evolves, I reminded the committee, and the uses of camera technology are changing rapidly. Both the government (especially the FBI and NSA) and the private sector (especially Facebook) are developing incredibly robust facial recognition systems. Today, remote biometric recognition is not just possible but rapidly improving. Faces, iris scans, even walking gaits can identify individuals via cameras. Once police begin to integrate systems it could make routine a brand of Big-Brotheresque surveillance that a decade ago was still relegated to the realm of futuristic movies. There are already pedestrian-level billboards in Japan and Las Vegas that analyze the biometrics of passersby to target advertising based on age, gender and other basic characteristics. The day is coming when such billboards will identify you via facial recognition, analyze your Facebook page and other public data, and target advertising to you individually.

It's one thing for private companies to use such tech to try to sell you something, but quite another for the government to use it for law enforcement purposes. In a world where that sort of invasive technology exists - where we can see the day coming when a person will be innocently walking down the street, spotted by a camera connected to a government database, identified via facial recognition or other biometrics and quickly have a Big-Data style background search run on them to discover any possible red flag, all automatically, via algorithm - people deserve to be warned. Whether Rep. Stickland's idea of physical signage within 10 feet of the camera is the best or most effective means is a matter one can debate. I've heard worse suggestions. But I do think the public has a right to know when their government is watching them.

The only opposition was from a fellow from the city of Austin who said they have around 900 traffic cameras and perhaps 250 surveillance cameras. They don't want to put up signs and I don't blame them. As Rep. Stickland pointed out, they would always have the option of removing cameras.

The idea behind having all the footage from government surveillance cameras online, as I understand it, is an effort to ensure the government isn't using the cameras for things they shouldn't be by letting everyone see what they're looking at. But local government and other state reps rightly complained that that could entail a significant fiscal note. It struck me that the same thing could be accomplished with no fiscal note just by reversing the 2003 legislation that made all that footage, the policies, etc., a closed record. That would be a a fine open-government substitute and would eliminate most of the fiscal burden on the locals that seemed to be the primary source of opposition.

Of course, this is one of those statement bills that's already deceased by the time it was heard. Short of an act of God, there's likely not enough time for it to make it through the process. But I was glad to see a Tea-Party affiliated freshman beginning to engage on these privacy and surveillance issues and must say I was surprised that the committee's concerns were more technical and practical than hostile to Mr. Stickland's purpose. With a little more time over the interim to clean the bill up and address some legitimate concerns of stakeholders, perhaps he could do some business in that committee next session with this bill.

See related Grits posts:

Sunday, March 17, 2013

Location Tracking and Biometrics conference: Roundup of Grits posts

Thanks to readers who donated for Grits to attend the March 3 conference on Location Tracking and Biometrics at the Yale Law School and especially to the Texas Civil Rights Project for a particularly generous contribution. It took two weeks, but today I finally finished the last two posts summarizing my notes from panels at the conference. Here they are all in one place for easy reference:

Biometrics and profiling: The door to the phone booth is now open

The next to last panel at the Yale Law School's March 3rd Location Tracking and Biometrics Conference was related to biometric identification and its implications for privacy in the hyper-connected world of the 21st century. Moderated by Wired magazine contributing editor Noah Shactman, the panel arguably was the creepiest of the day, with truly surreal implications for personal privacy. The panel featured Georgetown law professor Laura Donohue, Jennifer Lynch from the Electronic Frontier Foundation, NYU Ph.D candidate Travis Hall, a postdoctoral fellow from Carnegie Mellon named Ralph Gross, and Alvaro Bedoya, who is an aide to Minnesota Sen. Al Franken. Go here to watch it online, beginning at the 7:31:48 mark. Here's a summary from my notes:

Biometrics then and now
Shachtman opened the discussion by pointing out that the use of biometrics for identification dates at least to 2,400 years ago, when the Chinese used hand prints and thumbprints on official documents. In the mid-19th century, the British East India Company used them to authenticate documents and track prisoners (in the aftermath of the Indigo Revolt, 1859-1861). The first use of fingerprints in modern criminal case, he said, occurred in in Brazil.

The US government has funded biometrics research from ear lobes to body odors as potentially unique, personal identifiers, many of which can be used from a distance. Some 31 states (including Texas, see Grits' discussion from 2004 here, here and here) use facial recognition with DMV photos. The Department of Justice has a database with fingerprints of 130 million people.

Biometrics have three characteristics which make them useful for identification: They are immutable, readily accessible, and individuating. Those characteristics, though are a source of both benefits and problems. Notably, while biometrics are individualized, your computer turns them into ones and zeroes, meaning they can be electronically captured. Biometrics data can be gathered from a distance in public settings on a mass scale and monitored continuously, telling more about a person than just their identity. It's one thing, said Schactman, to get a fingerprint or DNA swab upon arrest. But today telescopes can capture an iris scan from 1,000 meters away. Thus setting the stage, we turn to the panelists:

Game changer: Remote identification, 'multimodal' biometrics
Georgetown law professor Laura Donohue described how the recent "technological leap" into the 21st century has created a "statutory gap" and a "constitutional abyss." (See her related law review article.) Kraft Foods is in talks with Facebook, she said, so that a commecial kiosk identifies you through facial recognition to tailor individualized marketing. In Las Vegas, there's a billboard that analyzes your age and gender to market different products to different people (these are also proliferating in Japan). According to Donohue, there were 633 facial recognition patents issued between 2001 and 2011 compared to just a handful the decade before. She identified four emerging trends:
  • Move to multimodal biometrics. Pairing fingerprints with iris scans, DNA.
  • Pairing of biographic information and biometrics.
  • Interoperable databases
  • Collapsing distinction between law enforcement, homeland security and national security.
The FBI sees multimodal biometrics as a key law enforcement tool of the future, hoping to fuse contextual, biographical and biometric information in connected databases. E.g., facial recognition at political rallies can identify people who were at multiple rallies and checked against a "Repository of Individuals of Special Concern" (RISC). These functions are also being privatized. The company Rapback lets employers submit their employees' biometrics, which it then gives to the FBI and is notified in return of the employee's criminal and in some cases civil activities. The service could even notify an employer, she said, when an employee is spotted at a political rally if it's caught on film.

Historically biometrics were used for immediate, one-to-one identification: Fingerprints identified someone booked into the jail, or an iris scan let them enter a secure corporate facility. But now many biometrics can be matched remotely and instead of one-to-one matching, can to one-to-many, potentially wiping out any remaining vestiges of privacy in public spaces. The dynamic of biometrics use is changing, said Donohue, along the following axes:
  • One-to-one vs. one-to-many.
  • Close up or at a distance
  • Custodial detention vs. public spaces
  • Notice or consent vs. none
  • A one time, limited occurrence vs. continuous and ongoing manner.
On the statutory side, the laws "have not grappled with new technology." And on the constitutional front, the focus in US v. Jones (finding the placement of a location tracking device on a car was a "search") on the physical intrusion of placing a tracker on a car ignores the growing array of tracking technologies like remote biometrics that require no physical intrusion. One could read Jones as including a "shadow majority" of justices endorsing the "mosaic theory" that holds continuous tracking over time violates one's reasonable expectation of privacy, but there are other cases, she said, that blur that distinction.

Immigration enforcement driving interoperable government databases
NYU's Travis Hall discussed biometrics, interoperability and immigration reform, with a particular focus on the FBI and the Department of Homeland Security's "Secure Communities" program, where people arrested on state and local criminal charges are matched with federal immigration databases to check for immigration violators and people for whom a criminal offense might itself be an immigration violation under the terms of their visa. Defense Department and Department of Justice databases don't talk to each other, he said, but they communicate indirectly through the Department of Homeland Security. The United States has a "federated system," said Hall, with four main biometric databases that after 9/11 all began to share data directly or indirectly. Fingerprints from federal, state and local arrestees are uploaded to the FBI which sends them to DHS to check for immigration violators. That way, DOD and intelligence agencies end up with access to data from state and local law enforcement activities.

At first, Secure Communities was pitched to the states as an opt-in program and only 13 states signed up to be notified of immigration violators in their jails. Then, when Illinois and Boston tried to opt out, the feds said "no, you can't."

What's the problem? The lines between criminal and civil enforcement mechanisms are becoming blurred, said Hall. Immigration status is often not static but "fuzzy," making bright-line enforcement under Secure Communities problematic. This blurring of criminal and civil enforcement mechanisms could also have unforeseen consequences down the line in areas of law completely unrelated to immigration. (I found myself wishing he'd given more hypotheticals about what that might look like.) With the advent of mobile biometrics, immigration agents can perform fingerprinting and iris scans in the field that instantly connect up to all the above-mentioned federal databases. (See an EFF white paper by Jennifer Lynch on the conjunction of biometrics and immigration enforcement.)

The expansion of immigration-related biometrics may impact youth eligible under the DREAM Act (or the administrative equivalent announced last year by President Obama), which states that applicants must demonstrate "good moral character." Applicants go through background checks and must give up their biometrics in order to qualify for provisional status, a process that's resulted in an "entrenchment of surveillance tools." In order to be lenient on “the good guys,” he said, government needs surveillance on everyone to identify bad actors.

Facebook as Big Brother
In an earlier panel, 9th Circuit Presiding Judge Alex Kozinski pointed out that in the Katz case, in which SCOTUS first articulated the concept of a "reasonable expectation of privacy," the court based its interpretation of Mr. Katz's expectations in large part on the anachronistic fact that he closed the door to the wiretapped phone booth - an factor that appears quaint in the modern age of cell phones. Sen. al Franken's aide, Alvaro Redoya, said that today, "the phone booth door is very much open." He added that "the future is now," and "this is a big deal."

We shouldn't just be concerned about the Minority Report scenario where advertising is funneled to us based on remote identification, he said. Now your driver's license, passport and Facebook account are all connected to facial recognition applications.

Facebook is honing its facial recognition software through its tag suggestions program, which presently is active everywhere but Europe where privacy laws prevent its implementation. On the back end, Facebook makes a "faceprint" they can match like a fingerprint. When your friends upload pictures, they are prompted, "would you like to tag" the people in them. The company has rolled this out on an "opt out" basis, meaning they're gathering faceprint data unless you've specifically declined to participate. The average person has 53 photos on their Facebook page, he said. Assuming a 60% non-participation rate (which is probably way too high), the company would have a faceprint for one out of 20 people on the planet. Assuming a 20% opt-out rate, which is perhaps more realistic, Facebook has pictures of one out of 10 humans in their facial  recognition system. Every time Facebook suggests, "is this so-and-so?" and asks if you want to tag them, and you say "no, it's not that person," the company improves their algorithm. Essentially, Facebook has crowd-sourced refinement of its system. Facebook does not promise they won't sell information to third parties. There are scenarios with real person to person (P2P) harms. In early 2010 an Israeli company rolled out Click App, a facial recognition system which Facebook purchased last year. Someone hacked it and figured out you could download pictures from Facebook and use it as a private facial recognition system.

Prof. Donohue had earlier described how the FBI had developed facial recognition technology to scan individuals at political rallies, identifying everyone who had attended two or more events. Redoya said the events in the FBI's example were from Obama and Clinton political rallies. In all states where such facial recognition technology has been rolled out, he said, it's a crime to block a sidewalk, for example, so it's easy to find a law enforcement justification for its use in such settings. Your faceprint remains roughly the same between ages 20 and 50, he said.

In Katz, the Supreme Court considered it important that the phone booth door was closed. But every time you walk outside you knowingly expose your face to the public, Redoya observed. Unless the law catches up to that sort of functionality, those sorts of outdated distinctions will obliterate personal privacy.

Privacy in the age of augmented reality
Carnegie Mellon's Ralph Gross discussed "Privacy in the age of augmented reality" (see an FAQ) having conducted experiments analyzing the convergence of public self-disclosure in social networks, improvements in facial recognition accuracy, cloud computing, "ubiquitous computing," and "statistical re-identification" of de-identified data The results, he said raise the question of whether in an era of "augmented reality" we have finally reached “the end of anonymity”?

Combining publicly available social network data and off-the shelf facial recognition technology, Gross and his fellow Carnegie Mellon researchers downloaded images from Facebook and then from dating service websites, trying to match them. One out of 10 dating-site members could be identified, he said. A second experiment set up cheap webcam and asked students to let them take three photos from different angles. They could identify one out of three subjects, not just from their profile pictures but also from tagged images.

Even more disturbing was Gross' success at predicting social security numbers (!). Think for a moment: How many times have you given out the last four digits of your social security number as an identifier for online services? Have you ever thought about what happens if the other five digits could be inferred from public records? For 27% of subjects from Facebook, Carnegie Mellon researchers could guess the first five digits of their Social Security Number within four attempts. In other words, their algorithm could come up with four guesses and one of them was right 27% of the time. So starting with a photo and using information of Facebook, it's possible to guess those first five digits around a quarter of the time. Over time and with more data, that algorithm could become even more robust.

Gross said modern facial recognition technology can go from an anonymous face to matching it to a presumptive name, then get online information, demographics, their friends, and potentially predict their social security number and credit score, not to mention their political and sexual orientation. This could all be done, he said, "in real time with a smart phone app. The implications are staggering and include:
  • Faces as conduits between online and offline data.
  • The emergence of personally predictable information
  • The rise of visual, facial searches
  • Democratization of surveillance, and
  • Social network profiles as Real IDs
When your face can be connected to so much information about you, it essentially becomes your ID.  Today's technology has reached the stage where such capability is no longer purely the domain of science fiction but a real-world scenario which courts and legislatures have yet to address.

Location data as biometrics: You are where you go
EFF's Jennifer Lynch spoke about "location data as biometrics." To my mind, the takeaway from her presentation was "you are where you go." The same thing can't be in two places at the same time and two different things can't occupy the same place, said Lynch, so by its nature location data is individualizing.

Cell phones generate staggering amount of location data totaling 600 billion transactions per day worldwide, data which frequently is shared with third parties in volume and in real-time and constitutes a significant potential new market for cell-phone carriers. Your movements quickly reveal where you spend your time, when, and with whom, as well as what's typical and what's not. Though cell-tower data is "de-identified," she said, once you know all that information, "re-identification" - i.e, figuring out who is who - is a somewhat trivial technical feat (as Ralph Gross had earlier demonstrated).

The more cell-phone towers and antennas that exist, the more precise location tracking by cell phones becomes. Using a site called AntennaSearch, Lynch found that there were 74 cell towers and 529 antennas within four miles of the Yale Law School. (Running the same search for Grits' own home in Central East Austin, I found 145 towers and 675 antennas within a four mile radius.)

A young German politician named Malte Spitz sued his cell phone company for all his location data and partnered with a newspaper to produce an amazing graphic tracking his movements for six months. The graphic includes not just his location but how many phone calls and text messages he received and sent, also linking the data to his Facebook and Twitter timelines to add context, creating a stunning diary of his life. Given the foibles of human memory, it shows your cell-phone carrier (and by extension any government agency or third party that accesses that data) in some ways may know more about your life than you do.

Following in his footsteps, so to speak, Lynch tracked herself for a month with a Google program called “Latitude” that records everywhere you've been. Nothing earth shattering - she mostly went from home to office to her kid's school, with an occasional trip to a store or other destination - but really it's the mundane data that identifies you and provides the most information about who you are and how you live your life. Location data combines and amplifies all the problems with biometrics, said Lynch.

Aren't biometrics 'awesome'?
Wired editor Noah Schactman interjected to ask the panel, "Isn't the idea of your face as universal recognizer awesome?" It would make passwords useless, he said, since someone can't hack your face in the way you can hack a password. Not true, said Lynch, noting that Japanese kids hack cigarette machines with facial recognition tech by holding up magazine ads of older people. (Grits wrote in 2005 that, for that very reason, biometrics make terrible passwords. To a computer your fingerprint, iris scan or facial structure are just ones and zeros which are easily replicable.)

Travis Hall pointed out that, while we live just one life, there are "siloed" aspects to everyone's existence. New technology breaks down those silos in ways that people don't want broken down. Identity in one context may be open, but can now be linked to other contexts in ways that people would prefer remain closed. Prof. Donohue added that, for that reason, there's a public or social harm from long-term storage of this information. New guidelines allow the National Counter Terroism Center to retain personal information about non-suspects for five years instead of 180 days, generating an ever-more detailed and robust data set about individuals over time.

One-to-one biometrics are not as big a problem compared to "one to many" apps. It's one thing to verify identity of an individual and another to identify strangers from a crowd, especially in an era when cameras are so ubiquitous.

During the Q and A, Chris Soghoian pointed out that there are dating websites for people from specific religions, people with particular STDs, gay people, etc., asking if the data could all be scraped and dumped into some sort of uber-database. Gross replied that it may or not be legal to do that - most likely it would violate the sites' terms of service - but technologically, we're at a point where it can be done. Hall pointed out that the "real problem" with data analytics is that "you don't know you're being tracked.'

Judge Kozinski stepped to the questioners' mic to ask about the implications of the NSA's “Solar Wind” project in Utah - a data processing facility where information accessed by intelligence services may be churned through at an astonishing 4 terrabytes per second. "Can they apply these technologies to all that data?" he wondered, essentially answering his own question. I'm not sure many people in the room had considered that. There was a moment of stunned silence as everyone took in the implications, before Prof. Donohue pointed out that such massive data processing capacity was especially a problem when combined with indefinite data retention.

Another questioner asked, "Can you opt out of information being shared?" The answer is sometimes. Your cell phone, for example, must ping the nearest tower periodically so it can receive phone calls. Android phones, it was pointed out, automatically link phone numbers you dial to your Google contacts list. Could there be an automatic opt in instead of opt out? Sure. But it's not required, and in practice people opt in via terms of service agreements they never read.

Travis Hall observed that the "persistence of data is astounding."  Data has long shelf life. In Europe there is an ongoing debate about the “right to be forgotten.” As it turns out, it's very had to be forgotten. Engineers having trouble comprehensively deleting even a single photo.

For the most part, unlike the politician from Germany, you have no right to review records the government keeps about you, Hall observed, especially for data gathered under national security authority. Schactman pointed out that, ironically, Al Quaeda members may be the only people not being tracked in the government's biometric databases.

See prior, related Grits posts from the conference:

Wednesday, September 19, 2012

FBI spending $1 billion on facial recognition technology

The FBI is spending a billion dollars to implement facial recognition software. This writer says "criminals are really the only ones who should fear the facial recognition program at present, because only mug shots from the national criminal FBI database are being used." That seems a bit naive, to me, considering that as soon as the Texas Legislature removed restrictions on biometric data from drivers licenses, including fingerprint data, the state uploaded the information to so-called "fusion centers" to give the feds access. See more on the new facial recognition program from New Scientist, which notes that "it is easier to match up posed images and the FBI has already partnered with issuers of state drivers' licences for photo comparison."

Sunday, March 14, 2010

On biometrics and the politics of a national ID card

I find myself in total agreement with Bert Knab at the Glass Houses blog on why a national ID card is a bad idea and biometric identification won't stop employers from hiring illegal immigrants. Go read what he has to say.

I'd add an observation I've been stressing for many years on Grits: that biometrics are generally bad identifiers for ID purposes, precisely because they can't be altered if a thief gets hold of them. If someone steals your password or your credit card number, it can be changed. However if biometrics like your thumbprint or iris scan (which to a computer, after all, is just information: ones and zeroes) are used as identifiers, once they're stolen you can never mitigate the damage.

Sunday, September 27, 2009

Politics push toward expanded fingerprinting, biometric profiles

Three thematically related stories related to fingerprints caught my eye this morning and may interest Grits readers:
A common theme for all three is that there's intense political pressure to expand fingerprint systems and integrate them nationally. At the same time, fingerprint matching is a subjective craft and especially because of its wider use in immigration cases, in particular, demand for these services is increasing at a time when the science behind its use is being questioned. The story out of California highlights some of the hidden costs to agencies from this expansion.

Meanwhile, one wonders if "scent evidence" will be included in the comprehensive biometric profiles the FBI plans to create on the millions of Americans who come into contact with the justice system? According to Computerworld, "The next-generation FBI database system is under design by MorphoTrak and is expected to include DNA, iris scans, advanced 3-D facial imaging and voice scans among its multi-modal biometrics."