SlideShare a Scribd company logo
Biometric Unsecurity
Carina C. Zona
@cczona
BIOMETRICUNSECURITY
DJANGOCON EUROPE
// CARINA C. ZONA
// SEPTEMBER 18, 2020
Biometric Unsecurity
Carina C. Zona
@cczona
Domination,Abuse, and Exploitation
surveillance and stalking
human rights violations
and genocide
policing and
carceral systems
immigration and
border control
religious bias and
persecution
refugees
famine
wildfires
transphobia
ableism
psychological abuse
sexual abuse
(censored) NSFW images
(cens**d & uncensored)
slurs
Content Warning
Biometric Unsecurity
Carina C. Zona
@cczona
BIOMETRICS
BIOMETRICSPYTHONDJANGO
Biometric Unsecurity
Carina C. Zona
@cczona
Biometric Unsecurity
Carina C. Zona
@cczona
Biometric Unsecurity
Carina C. Zona
@cczona
Absolute
Authentication Authorization
This exactly matches that This is permitted
Probabilistic
Verification & Identification Categorization
This seems akin to that Attributes of this seem to be
Biometric Unsecurity
Carina C. Zona
@cczona
Identification Is Not Identity
Identification Compare credential data
Data comparison. Username/password,
security token, passport, key.
Biometric
identification
Compare physical trait data.
Sensor data comparison. Face, gait,
heartbeat.
Identity
Who we know ourselves to be,
individually and collectively.
Culture, groupings. Race, gender,
religion, ethnicity.
Biometric Unsecurity
Carina C. Zona
@cczona
UNSECURITYUNDOINGOFSAFETY
UNSECURITY UNRAVELSAUTONOMY, FUNDAMENTAL SAFETY, HUMAN RIGHTS, EXISTENTIAL THREATS
Biometric Unsecurity
Carina C. Zona
@cczona
Trades Exactness for %
Biometric Unsecurity
Carina C. Zona
@cczona
SECURITYACCESS+CONTROLLOSS PREVENTION FOR VALUABLE ASSETS
Biometric Unsecurity
Carina C. Zona
@cczona
UNSECURITYACCESS+CONTROLACCESS TO PUBLIC SPHERE CONDITIONED ON CEDING PERSONAL CONTROL
SIM
Food
Transit
School
Pension
Welfare
Employment
Immigration
Medication
BASIC SERVICES
Shopping
Banking
Insurance
Real Estate
FINANCE
Home
Neighborhood
City
"SMART"
Access + Control
Biometric Unsecurity
Carina C. Zona
@cczona
Security Unsecurity
Biometric Unsecurity
Carina C. Zona
@cczona
Unreusability
(January2018-May2020)https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
PASSWORDRESET
Biometric Unsecurity
Carina C. Zona
@cczona
Unreusability
(January2018-May2020)https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
PASSWORDRESET
“BODYRESET”
Biometric Unsecurity
Carina C. Zona
@cczona
BODIESARE
MUTABLE
BIOMETRICS CHANGE
Naturally Or Accidentally. Unconsciously Or Deliberately. Temporarily Or Permanently
Biometric Unsecurity
Carina C. Zona
@cczona
Data
"COGNITIVE"/
BIOSIGNALS
PHENOLOGICAL
BEHAVIORAL
Types
• Visual expression of genetics
• Actions
• Neurological Responses
Biometric Unsecurity
Carina C. Zona
@cczona
fingerprint
gait involuntary
Biometric Unsecurity
Carina C. Zona
@cczona
Probabilistic
DETECT Person RECOGNIZE Trait ANALYSIS
Verify (1:1)
Classify (label)
DATA Record Identify (1:M)
"74.2% Hostile"
"94.6% Activist"
"67.9% Queer"
Biometric Unsecurity
Carina C. Zona
@cczona
• ECG
• ECG
• EKG
Sensors
• Optical
• Thermal
• Infrared
• Microphone
• Camera
• Accelerometer
• CCTV
• Webcam
• Body camera
Biometric Unsecurity
Carina C. Zona
@cczona
Data Sources
• Smart speaker
• Smart doorbell
• Smart appliance
• Arrest records
• Watchlists
• Body cameras
• National ID
• School ID
• Drivers license
• Passport & visa
• Work permit
• Refugee registration • Ghost workers
• Smart glasses
• Wearables
• Stock photos
• Paparazzi
• Social media
• Generated
photos
• Drone
• Activity tracker
Biometric Unsecurity
Carina C. Zona
@cczona
UNIQUEA MEASURABLE STABLE BODY TRAIT THAT'S UNIQUE.
EXACTLY ONE PERSON, PERIOD.
UNIQUENESS IS ABSOLUTE.
Biometric Unsecurity
Carina C. Zona
@cczona
UNIQUEA MEASURABLE STABLE BODY TRAIT THAT'S UNIQUE.
EXACTLY ONE PERSON, PERIOD.
UNIQUENESS IS ABSOLUTE.
Biometric Unsecurity
Carina C. Zona
@cczona
Traits
• Apparel
• Accessories
• Tatoos
• Cardiac signature
• Gestures
• DNA
• Skin temperature
• Internal temperature
• Skin color
• Skin tone
• Skin reflectance
• Skin texture
• Brain activity
Biometric Unsecurity
Carina C. Zona
@cczona
Traits • Head cover
• Iris
• Eye movement
• Gaze direction • Face geometry
• Earlobe geometry
• Voice
• Periocular geometry
• Laughter
• Face cover
• Eye cover
• Facial veins
• Retina
• Head movement
• Facial expression
• Head pose
Biometric Unsecurity
Carina C. Zona
@cczona
• Fingerprint
• Palm print
Traits
• Finger veins
• Palm veins
• Blood flow pulse
• Cardiac electric activity
• Hand geometry
• Typing speed
• Typing cadence
• Handwriting speed
• Handwriting stroke order
Biometric Unsecurity
Carina C. Zona
@cczona
• Footprint
Traits
• Gait
• Knee, leg, and ankle geometry
Biometric Unsecurity
Carina C. Zona
@cczona
• Trait
distinctiveness
• PIE (pose,
illumination,
exposure)
• Cooperation
• Sensors
• Resolution
• Noise
• Distance
• Duration
• Skin reflectance
• Body changes
• Environment
• Background
• Occlusions
• Activities
• Make-up
• Health
• Hormones
• Culture
• Class
• Gender
• Race
Biometrics Are Full of Biasing Variables
More Data != More Accurate
Sourcerefingerprint,iris,handgeometry: https://heimdalsecurity.com/blog/biometric-authentication/(May1,2019)
Biometric Unsecurity
Carina C. Zona
@cczona
BIOMETRIC
DATASETS&PLATFORMS
POWER UNSECURITY
Biometric Unsecurity
Carina C. Zona
@cczona
"IFWECOULDPUT
MASSSURVEILLANCE
INAPACKAGE…
WEWOULD
SENDITTOYOU."
https://stealthisposter.org/poster/URL(centershttps://twitter.com/berlinvsamazon/status/1305553645602254848(right)
Biometric Unsecurity
Carina C. Zona
@cczona
TECHNICALDEBT
PROJECT
ETHICALDEBT
PEOPLE
Biometric Unsecurity
Carina C. Zona
@cczona
Its collector
comes only
after harm has
been inflicted
https://www.wired.com/story/opinion-ethical-tech-starts-with-addressing-ethical-debt/
Biometric Unsecurity
Carina C. Zona
@cczona
https://twitter.com/_alialkhatib/status/1301281740527468544
Biometric Unsecurity
Carina C. Zona
@cczona
"What makes us think
that A.I. won’t be
mobilized to work
toward anything but
the detriment, rather
than the interests of,
Black people, anyway?"
—Charlton McIlwain,
"Black Software: The Internet & Racial Justice,
From the AfroNet to Black Lives Matters”
https://slate.com/technology/2020/08/algorithms-artificial-intelligence-racism-reparations-history.html
Biometric Unsecurity
Carina C. Zona
@cczona
"
We never
thought about
misuse" is the
precursor to
ethical debt.
https://www.wired.com/story/opinion-ethical-tech-starts-with-addressing-ethical-debt/
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.nbcnews.com/tech/internet/facial-recognition-s-dirty-little-secret-millions-online-photos-scraped-n981921
CREATIVE
COMMONS
Copyright
X Model
consent to be
defamed
Biometric Unsecurity
Carina C. Zona
@cczona
• Diversity in Faces
• ImageNet: slurs
• Tiny Images
(MIT): slurs,
NSFW
Labels
Datasets
VinayUdayPrabhu&AbebaBirhane
https://deepai.org/publication/large-image-datasets-a-pyrrhic-win-for-computer-vision
Biometric Unsecurity
Carina C. Zona
@cczona
EDUCATION
UNSECURITY
Biometric Unsecurity
Carina C. Zona
@cczona
Face,fingerprint,behavioral,
temperature

• Entrance
• Attendance
• Meals
• Messaging
Schools
Education Unsecurity
"childreneating"bypedroreynahttps://www.flickr.com/photos/thebigtable/11695084114
"ChildrenEatIceCream"bylenifuzheadhttps://www.flickr.com/photos/lenifuzhead/64070145
Biometric Unsecurity
Carina C. Zona
@cczona
Face,behavioral,cognitive

• Attendance
• Proctoring
Remote Edtech
Education Unsecurity
"childreneating"bypedroreynahttps://www.flickr.com/photos/thebigtable/11695084114
"ChildrenEatIceCream"bylenifuzheadhttps://www.flickr.com/photos/lenifuzhead/64070145
Biometric Unsecurity
Carina C. Zona
@cczona
Facial recognition

• Violates GDPR
• Coersive
• Overeach
• Less safety
Schools
Biometrics Shift Power
"childreneating"bypedroreynahttps://www.flickr.com/photos/thebigtable/11695084114
"ChildrenEatIceCream"bylenifuzheadhttps://www.flickr.com/photos/lenifuzhead/64070145
Biometric Unsecurity
Carina C. Zona
@cczona
PROCTORINGEXAM MONITORING
INVIGILATION
Biometric Unsecurity
Carina C. Zona
@cczona
https://twitter.com/NONBlNARY/status/1305138377629609985
Biometric Unsecurity
Carina C. Zona
@cczona
Proctoring
Psychological Unsecurity
"18" by Bambi WIllow https://search.creativecommons.org/photos/6af499cf-e866-4134-8f84-d140dc14dcbf
Bias
Privacy
Abuse
Ableism
Facial Identification
Gaze Tracking
Voice tracking
Attentiveness
Biometric Unsecurity
Carina C. Zona
@cczona
LIAR,LIARWFH MUST BE
DISHONEST
DISTANCE PROCTORING'S PREMISE
PSYCHOLOGICAL
ABUSE MUST BE OKAY
Biometric Unsecurity
Carina C. Zona
@cczona
https://twitter.com/legendariee16/status/1304098649186742273
Biometric Unsecurity
Carina C. Zona
@cczona
Name-calling. Lazy, suspicious,
liar, worthless, failure, stupid.
Monitoring whereabouts.
Know where you are at all
times.
Intimidation.Threatening to
take away something important,
belittling accomplishments,
humiliation.
Isolation. From assistance,
support, neutral observers.
Digital spying. Browser
history, keystrokes, app
launches, window movements.
More: violating boundaries,
invading privacy, financial
control, etc.
https://www.medicalnewstoday.com/articles/325792
Control Via Fear
Psychological Abuse
Biometric Unsecurity
Carina C. Zona
@cczona
"Children who had been psychologically abused
suffered from anxiety, depression, low self-esteem,
symptoms of post-traumatic stress and suicidality at
the same rate and, in some cases, at a greater rate
than children who were physically or sexually abused.
Among the three types of abuse, psychological
maltreatment was most strongly associated with
depression, general anxiety disorder, social anxiety
disorder, attachment problems and substance abuse."
—"Psychological Trauma: Theory, Research, Practice, and Policy" review,
American Pediatric Association
https://www.apa.org/news/press/releases/2014/10/psychological-abuse
Biometric Unsecurity
Carina C. Zona
@cczona
• Racial bias of photo exposure algos*
• Religious head coverings
• Neurodiversity
• Disabilities
• Class differences
• Homeless
• Privacy of thoughts, interests
• Privacy of home, family, roommates
• Bullying
• Stalking
Proctoring
Psychological Unsecurity
https://www.slideshare.net/cczona/consequences-of-an-insightful-algorithm
https://www.youtube.com/watch?v=YRI40A4tyWU(32:00-35:00)
Biometric Unsecurity
Carina C. Zona
@cczona
Once you’ve shown the whole space, you’re able to take the exam. For the
duration of the exam, the camera and microphone are on recording the test-
taker. Not only are sounds picked up by the microphone flagged, but it also
flags every time the test-taker looks away from the screen. In the least
problematic cases it flags for looking away while thinking—in the worst, it flags
folks with physical disabilities as cheating.
https://twitter.com/Angry_Cassie/status/1301360994044850182
Biometric Unsecurity
Carina C. Zona
@cczona
Proctoring/Invigilation
Phenotypical Behavioral Non-biometric Other
Proctorio
ProctorTrack
ProctorU
Examity
Face (3D)
Finger knuckle patterns
Head movements
Mouth movements
Eye movememts
Voice & vocalizations
Keystroke patterns
Name
Address
Phone number
Parent name
Drivers license
Birthdate
360 scan of room
Scan of desk
No sound/voices
Real-time surveillance
Computer & browser control
Record screen, webcam, audio
No head covering, ear covering,
jewelry, or accessories
No CDs, glasses, mirror, toaster
Mac or Windows. System administration privileges. Chrome or Firefox.
3rd party application (not via app store), Applet, browser extension, or Flash Player.
Webcam, headphones, and microphone. Broadband. Private room. Well-lit.
Biometric Unsecurity
Carina C. Zona
@cczona
Elevating Speculation
To (Harmfully False)
Objectivity
Biometric Unsecurity
Carina C. Zona
@cczona
• Detect: eyes, face, angle
• Identify: gaze direction, movements relative to fixed point
• Assumption: not maintaining gaze is meaningful.
• interpretation: inattention (a mental state), non-compliance, underproductive, distracted
• personal consequences: grades, income, trust
• Insititional consequences: underestimate people (including implied judgement of intelligence), loss of talent
• Socioeconomic consequences: fail, loss of financial aid or diploma, unemployment, incarceration
• Expense consequences: equipment, personnel, training, subscriptions, technical support, updates
Gaze Tracking Students & Workers
Thought Stalkery
Biometric Unsecurity
Carina C. Zona
@cczona
OUTERAPPEARANCE
TOINFER
INNERCHARACTER
PHYSIOGNOMY
Biometric Unsecurity
Carina C. Zona
@cczona
OUTERAPPEARANCE
TOINFER
INNERCHARACTER
PHYSIOGNOMY
JUNKSCIENCE
Biometric Unsecurity
Carina C. Zona
@cczona
INCOME
UNSECURITY
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.cbsnews.com/news/job-hunting-ai-is-judging-you-but-critics-say-its-snake-oil/
Hiring
HireVue
Biometric Unsecurity
Carina C. Zona
@cczona
Vocabulary, word choices, expressions, more…
“In a 20-minute interview, we can
collect a lot of data. We have no
idea who the candidate is, but
we can collect a lot of data about
vocal variation, personal
pronouns” and other information
to make an assessment.
https://www.cbsnews.com/news/job-hunting-ai-is-judging-you-but-critics-say-its-snake-oil/
Hiring
HireVue
Biometric Unsecurity
Carina C. Zona
@cczona
https://twitter.com/random_walker/status/1195347349427687425
Hiring
8 and Above
Biometric Unsecurity
Carina C. Zona
@cczona
• Stress
• Emotions
• Thoughts
• Honesty
• Criminality
• Employability
• Wakefulness
• Attentiveness
Affectmetrics Is Mind-Reader B.S.
Mental State Physiognomy
Biometric Unsecurity
Carina C. Zona
@cczona
“NOSUBSTANTIALEVIDENCE”
FORAFFECTMETRICS—AI NOW INSTITUTE
Biometric Unsecurity
Carina C. Zona
@cczona
Mind-Reading,Charlatanism,Projection
Pseudoscience
Modalities Psychometrics Demographics
Physical
Stress
Mood
Affect
Vocal Tone
Age
Gender
Race
Ethnicity
Nationality
Behavioral
Liveness
Awake
Attention
Neurological
Attitude
Memories
Tendencies
Biometric Unsecurity
Carina C. Zona
@cczona
PSEUDOMEDICAL
BIOMETRICS
Biometric Unsecurity
Carina C. Zona
@cczona
"Amazon says Halo uses “multiple advanced sensors” to provide “highly accurate information,” but
Halo isn’t a medical device. Unlike the Apple Watch and some other devices, Halo’s functions
haven’t been cleared by the Food and Drug Administration."
Amazon Halo
Pseudomedical Biometrics
https://onezero.medium.com/want-a-free-amazon-halo-wearable-just-hand-over-your-data-to-this-major-insurance-company-56b6430b0749
Biometric Unsecurity
Carina C. Zona
@cczona
1. leverages our deep expertise in artificial intelligence (AI)
2. help customers understand how they sound to others
3. helping improve their communication and relationships
4. analyze the positivity and energy of your voice
5. positivity is measured by how happy or sad you sound,
and energy is how excited or tired you sound
6. you might see that in the morning you sounded calm,
delighted, and warm
Extraordinary Claim—
Junk Science
https://blog.aboutamazon.com/devices/a-new-tool-to-help-you-understand-and-improve-your-social-wellbeing
not psychology
basis for psychological claim?
evidence of causality?
3rd Party
Consent
sound to who?
threshold for assigning labels?
validated axes? for stress?
comm? relationships?
Biometric Unsecurity
Carina C. Zona
@cczona
Points 1 & 2 aren't about
"voice tone", "voice
positivity", or "voice energy".
Citations 1 & 2 link to the
page's own URL.
There is no citation 3.
Amazon has cited no study,
no evidence, no psychologist.
Let alone rigorous
independent science.
...Extraordinary Lack of Evidence
Junk Science
https://blog.aboutamazon.com/devices/a-new-tool-to-help-you-understand-and-improve-your-social-wellbeing
Biometric Unsecurity
Carina C. Zona
@cczona
Projection
Pseudoscience
"I SAID A
THING."
"THEY THINK
YOU FEEL
______"
Biometric Unsecurity
Carina C. Zona
@cczona
Projection casts images onto a
blank screen. Psychological
projections are external
representations that may bear
little to no relationship with the
person they are ascribed to.
https://narcissistfamilyfiles.com/2017/10/03/the-narcissists-funhouse-of-mirroring-and-projection
Biometric Unsecurity
Carina C. Zona
@cczona
Abusers Love Projection
Section Title
https://psychcentral.com/lib/narcissists-and-abusers-use-this-to-target-empaths (image)
Positive Projections Negative Projections
1. Support grandiose
assertions
2. Control through
favoritism
3. Take credit for
others
4. Show an idealized
face to the world
1. Escape accountability
2. Expel self-doubt and
self-hatred
3. Justify manipulation
and exploitation
4. Blame others for their
own abusive
behavior
Biometric Unsecurity
Carina C. Zona
@cczona
Biometrics
Power
Alter
Biometric Unsecurity
Carina C. Zona
@cczona
HYPEISAWEAPON
Biometric Unsecurity
Carina C. Zona
@cczona
SOCIAL
UNSECURITY
Biometric Unsecurity
Carina C. Zona
@cczona
Aadhaar Identification
Number
Face
Irises
Fingers
Economic Unsecurity
"Inclusion."
"Ease."
"Voluntary."
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.bloomberg.com/features/2020-covid-vaccine-tracking-biometric/
Biometric Unsecurity
Carina C. Zona
@cczona
AnkitaAggarwal(research)&JessicaPudussery(animation)
Biometric Unsecurity
Carina C. Zona
@cczona
Nearly 3 hundred thousand people
cutoff from their pensions by biometric
identifier system’s shortcomings.
Biometric Unsecurity
Carina C. Zona
@cczona
https://rethinkaadhaar.in/testimonials/2018/1/17/i-do-not-get-rations-they-say-machine-does-not-recognise-your-fingerprints
Biometric Unsecurity
Carina C. Zona
@cczona
Biometric Unsecurity
Carina C. Zona
@cczona
As of January 2020,
1.2 billion Indians –
including 95% of adults –
have an Aadhaar
https://timesofindia.indiatimes.com/blogs/toi-edit-page/aadhaar-at-10-taking-stock-the-unfinished-work-lies-with-the-most-vulnerable-sections-of-society/
Biometric Unsecurity
Carina C. Zona
@cczona
“Over 2/3 of the 4.7% whose
biometrics failed during
authentication were still able to
get rations.
The remaining one-third remain
an urgent action item for India.”
https://timesofindia.indiatimes.com/blogs/toi-edit-page/aadhaar-at-10-taking-stock-the-unfinished-work-lies-with-the-most-vulnerable-sections-of-society/
Biometric Unsecurity
Carina C. Zona
@cczona
AnkitaAggarwal(research)&JessicaPudussery(animation)
Biometric Unsecurity
Carina C. Zona
@cczona
Mission creep
Design for privileged bodies
Income unsecurity
Food unsecurity
Trust and safety unsecurity
Biometric Unsecurity
Carina C. Zona
@cczona
UNSECURITY
EXPLOITS
PANDEMIC&
PROTEST
Biometric Unsecurity
Carina C. Zona
@cczona
"At every step there
were police present,
and drones being
flown overhead
constantly. 10am in
the morning till
11-12pm at night."
COVID-19https://twitter.com/inetdemocracy/status/1300743592281923586?s=21
— Muslim woman living in predominantly
Muslim neighbourhood in Jharkhand, India
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.theverge.com/2020/8/26/21402978/clearview-ai-ceo-interview-2400-police-agencies-facial-recognition
"Clearview AI was used at least once to identify
protesters in Miami."
"Facial recognition was also used by the New York
Police Department to arrest an activist during the
Black Lives Matter uprising this summer."
Biometric Unsecurity
Carina C. Zona
@cczona
EXTERNALS
PSYCHOLOGICAL
BEHAVIORAL
Unmasking
• Periocular
• Voice
• Gait
• Tattos
• Clothes
• Mask
Biometric Unsecurity
Carina C. Zona
@cczona
periocular
tattoogait
Biometric Unsecurity
Carina C. Zona
@cczona
CIVIL
UNSECURITY
Biometric Unsecurity
Carina C. Zona
@cczona
Military Biometrics
Ethics
Biometric Unsecurity
Carina C. Zona
@cczona
Paramilitary Biometrics
Drones
Biometric Unsecurity
Carina C. Zona
@cczona
Military Biometrics
Drones
Biometric Unsecurity
Carina C. Zona
@cczona
REFUGEES
Biometric Unsecurity
Carina C. Zona
@cczona
OVER1MILLIONMUSLIM ROHINGYA IN
WORLD'S LARGEST REFUGEE CAMP
https://www.vice.com/en_us/article/dyzjqy/for-the-last-three-years-more-than-a-million-rohingya-muslims-have-been-stuck-in-bangladesh
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.rfa.org/english/news/myanmar/rohingya-children-08242020213342.html
Biometric Unsecurity
Carina C. Zona
@cczona
U
nited Nations investigators
detailed atrocities committed by
the Myanmar military against the
Rohingya during the 2017 crackdown
and called for those responsible to be
prosecuted for “genocidal intent.”
https://www.rfa.org/english/news/myanmar/rohingya-refugees-protest-strike-11262018154627.html
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.wired.co.uk/article/united-nations-refugees-biometric-database-rohingya-myanmar-bangladesh
Rohingya Refugees
Biometric Unsecurity
Carina C. Zona
@cczona
Bantu Rohingya Syrians Yemeni many others
Biometrics, or
Your Life
Biometric Unsecurity
Carina C. Zona
@cczona
LITERALLYNOTHINGLEFTBUT
BODYANDNOWTHEYWANTTHAT
TOO
Biometric Unsecurity
Carina C. Zona
@cczona
7.2MILLION* AS OF 2 YEARS AGO…
REFUGEES’ BIOMETRIC INFO TAKEN BY U.N.
*
Biometric Unsecurity
Carina C. Zona
@cczona
"The Rohingya are fleeing violence
and persecution on the basis of
their identities. Now their most
intimate information is being
collected and stored in a database
over which they have no control."
https://www.wired.co.uk/article/united-nations-refugees-biometric-database-rohingya-myanmar-bangladesh
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.unhcr.org/uk/550c304c9.pdf#zoom=95
UNHCRThailand/ Karenni
A refugee provides his iris scan
and fingerprints as part of a
verification exercise jointly
conducted by UNHCR and
the RoyalThai Government
in January 2015 regarding
the identities of 120,000
persons of concern inWestern
Thailand. (UNHCR/ S. Jefferies/
January 2015).
Through its Key Initiatives series, UNHCR’S Division of Programme Support and Management
(DPSM) shares regular updates on interesting projects that produce key tools, practical
guidance and new approaches aimed at moving UNHCR operations forward.
In February 2015, DPSM and the
Division of Information Systems and
Telecommunications (DIST) completed
development of UNHCR’s new biometric
identity management system (BIMS),
building on the successful use of biometrics
across a number of UNHCR operations
globally. When rolled out, BIMS will
support all standard registration activities
and help to better register and protect
people, verify their identity and target
assistance for the forcibly displaced in
operations around the world.
Re-establishing and preserving identities is key to
ensuring protection and solutions for refugees. By
linking new technologies, such as biometrics to
existing registration data, UNHCR can strengthen
the integrity of existing processes and significantly
improve efficiency for operations. Being able to
verify identities is extremely important and a matter
of human dignity.
Biometric Identity
Management System
Enhancing Registration and Data Management
Malawi / A young girl is having her irises
scanned in order to be enrolled in the
biometrics registration exercise at the
Dzaleka refugee camp. She sits against
a grey background, as it has been found
early on in the pilot that either grey or blue
backgrounds allow for improved quality
facial recognition scanning. / UNHCR /
T. Ghelli / December 2013)
USING BIOMETRICS TO SAFEGUARD
IDENTITIES
The use of biometrics provides an accurate way
to verify identities using unique physiological
characteristics, such as fingerprints, iris and facial
features. In accordance with UNHCR’s Policy on
Biometrics in Refugee Registration and Verification
(2010), biometrics should be used as a routine
part of identity management to ensure that
refugees’ personal identities cannot be lost,
registered multiple times or subject to fraud or
identity theft.
FIELD TESTING OF BIOMETRIC
IDENTITY MANAGEMENT
Since 2013, UNHCR has been developing a new
global Biometric Identity Management System
(BIMS). During initial pilot testing in Malawi, 17,000
refugees were enrolled into the system and a variety
of field conditions were tested.
“I can be someone now. I am registered globally
with the UN and you’ll always know who I am,”
said 43-year-old Congolese refugee Olivier Mzaliwa,
registered through biometrics in Malawi’s Dzaleka
refugee camp.
In January 2015, with essential support from UNHCR
Thailand, a joint DIST – DPSM team conducted final
field testing of BIMS in Thailand. The new system
permits the much faster and accurate verification of
identities than the manual search for records in
UNHCR’s database that was previously required. This
allows UNHCR to assist large volumes of refugees
and others of concern more quickly and efficiently.
MORE INFORMATION
For more information, please contact UNHCR’s Field Information and Coordination Support Section at:
FICSS@unhcr.org
contact info: FICSS@unhcr.org
WHAT COMES NEXT?
Following the rollout of BIMS to Thailand, the UNHCR BIMS team will undertake a number of
activities in preparation for the further rollout across operations globally, further enhancing
UNHCR’s registration and data management.
Development:
Resolve development bugs in BIMS identified during the exercise in Thailand to be ready for the
next deployment;
Make biometric identity verification an integral part of assistance distribution where required;
Work to ensure that BIMS can be integrated with proGres - UNHCR’s registration and case
management tools;
Deployment:
DPSM field support team and regional registration teams to plan and prepare for upcoming
BIMS roll outs through 2015 and 2016; including:
Supporting exercises to verify identities of refugees and others of concern in Chad and India;
Maintaining communications with UNHCR operations globally to plan and prepare for BIMS
global roll-out;
Support:
Developing a support model that ensure a sustainable use of BIMS after its deployment;
Establishing network of qualified and experienced BIMS users, reinforcing capacity and ensuring
correct system use.
Thailand / Multiple fingerprints
are recorded simultaneously with
the new BIMS system. / UNHCR /
S. Jefferies/ January 2015
Thailand / Iris scans are quickly and easily
recorded during Biometric enrolment. /
UNHCR / S. Jefferies / January 2015
INNOVATIVE SYSTEM DESIGN
BIMS operates under a wide range of infrastructure
conditions and can provide numerous operational
and protection benefits to existing identity
management practices.
Better coverage
Unlike previous UNHCR biometric systems, BIMS
captures and stores all fingerprints and iris scans
from refugees and others of concern. Capturing
these multiple characteristics, rather than relying for
example only on finger-prints, allows for more
complete coverage of the population and, thus,
more accurate identification.
Operational in various contexts
Though benefiting from an online system
architecture, BIMS has been designed to also work
seamlessly when no internet connection is available
due to weak connectivity. BIMS also comes in a
portable, mobile configuration using a conventional
laptop and requiring no extra source of power to
use the USB driven fingerprint scanners, iris scanners
and webcams.
“During our recent pilot in Thailand, we had
20 operators working full-time, and not one of
them was affected by the fact that the satellite
connection was dropping out for several hours
a day. The system automatically queued their
operations. That kind of service offers some real
opportunities for UNHCR”
– BIMS Infrastructure Architect Pat Kartas.
Quick processing
Identifying a person using BIMS is quick and simple.
After enrolment, refugees and others of concern
need only to present two or more biometric
elements (e.g., two fingers, two eyes, or a
combination thereof) for BIMS to be able to
ascertain their identity within seconds. The
matching time for identity checks during the roll
out in Thailand was on average five seconds.
refugees were e
of field conditions were tested.
“I can be someone now. I am registered globally
with the UN and you’ll always know who I am,”
said 43-year-old Congolese refugee Olivier Mzaliwa,
registered through biometrics in Malawi’s Dzaleka
refugee camp.
In January 2015, with essential support from UNHCR
Thailand, a joint DIST – DPSM team conducted final
field testing of BIMS in Thailand. The new system
permits the much faster and accurate verification of
identities than the manual search for records in
HCR’s database that was previously required. This
umes of refugees
captures and stores a
from refugees and ot
these multiple chara
example only on fin
complete coverage
more accurate iden
Operational in v
Though benefitin
architecture, BIM
seamlessly when
due to weak con
portable, mobi
laptop and req
dr
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.unhcr.org/uk/550c304c9.pdf#zoom=95
Fingers
Irises
Face
https://www.vice.com/en_us/article/dyzjqy/for-the-last-three-years-more-than-a-million-rohingya-muslims-have-been-stuck-in-bangladesh&https://www.reuters.com/article/us-myanmar-rohingya-bangladesh-factbox-idUSKCN25F02P
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.vice.com/en_us/article/dyzjqy/for-the-last-three-years-more-than-a-million-rohingya-muslims-have-been-stuck-in-bangladesh&https://www.reuters.com/article/us-myanmar-rohingya-bangladesh-factbox-idUSKCN25F02P
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.vice.com/en_us/article/dyzjqy/for-the-last-three-years-more-than-a-million-rohingya-muslims-have-been-stuck-in-bangladesh&https://www.reuters.com/article/us-myanmar-rohingya-bangladesh-factbox-idUSKCN25F02P
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.vice.com/en_us/article/dyzjqy/for-the-last-three-years-more-than-a-million-rohingya-muslims-have-been-stuck-in-bangladesh&https://www.reuters.com/article/us-myanmar-rohingya-bangladesh-factbox-idUSKCN25F02P
Biometric Unsecurity
Carina C. Zona
@cczona
Biometric Unsecurity
Carina C. Zona
@cczona
GENOCIDE
Biometric Unsecurity
Carina C. Zona
@cczona
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.buzzfeednews.com/article/meghara/china-new-internment-camps-xinjiang-uighurs-muslims
268NEWLYBUILT
COMPOUNDS
Biometric Unsecurity
Carina C. Zona
@cczona
1MILLION=
EVERYPERSONIN
KOLNORODESSA
Biometric Unsecurity
Carina C. Zona
@cczona
1MILLIONUIGHERS
=1/2THEPOPULATION
OFPARISORVIENNA
Biometric Unsecurity
Carina C. Zona
@cczona
“The largest-scale
detention of ethnic
and religious
minorities since
World War II” —Buzzfeed
https://www.buzzfeednews.com/article/meghara/china-new-internment-camps-xinjiang-uighurs-muslims
Biometric Unsecurity
Carina C. Zona
@cczona
Muslims in Xinjiang — half
its population of about 25
million —are under
perpetual surveillance
—Buzzfeed
https://www.buzzfeednews.com/article/meghara/china-new-internment-camps-xinjiang-uighurs-muslims
Biometric Unsecurity
Carina C. Zona
@cczona
Architecture in which everyone is
under continuous potential
surveillance.
One guard, but impossible to know
when it’s you being watched.
Uncertainty ensures universal self-
policing.
How to Panopticon
Panopticonic Gaze
https://en.wikipedia.org/wiki/Panopticon
Biometric Unsecurity
Carina C. Zona
@cczona
• Face
• Fingerprint
• Palm
• Iris
• Voice
• Speech pattern
• Gait
• Blood type
• DNA
• Emotions
Sources:

• Mandatory “physicals”
• Police
• CCTV
Ethnic & Religous Minorities in China
Panopticonic Gaze
HumanRightsWatchhttps://www.hrw.org/news/2017/12/13/china-minority-region-collects-dna-millions
https://www.hrw.org/news/2017/10/22/china-voice-biometric-collection-threatens-privacy
Biometric Unsecurity
Carina C. Zona
@cczona
3rd Wave Data Ethics
Biometric Unsecurity
Carina C. Zona
@cczona
https://venturebeat.com/2020/08/23/the-term-ethical-ai-is-finally-starting-to-mean-something/
https://venturebeat.com/2020/08/23/the-term-ethical-ai-is-finally-starting-to-mean-something/
Biometric Unsecurity
Carina C. Zona
@cczona
PHILOSOPHICAL
Principles
Fairness
Accountability
Transparency
“AI will help
solve problems”
TECHNICAL
Fixed It!
Interventions
Re-training
Tuning
“The right data +
unbiased
algorithm =
ethical”
SOCIETAL
Impact
Power
Equity
Action
“Expose, critique,
and change
systems of power”
What can we do?
1 2 3
What should we do? Whose power
are we
reinforcing?
Whose vulnerability
are we
exacerbating?
What threats
do our
(in)actions
contribute to?
Whose problems
are we
solving?
Whose solutions
might we be
unraveling?
Biometric Unsecurity
Carina C. Zona
@cczona
PHILOSOPHICAL
Principles
Fairness
Accountability
Transparency
“AI will help
solve problems”
TECHNICAL
Fixed It!
Interventions
Re-training
Tuning
“The right data +
unbiased
algorithm =
ethical”
SOCIETAL
Impact
Power
Equity
Action
“Expose, critique,
and change
systems of power”
What can we do?
1 2 3
What should we do?
are we
reinforcing?
Whose vulnerability
are we
exacerbating?
What threats
do our
(in)actions
contribute to?
Whose problems
are we
solving?
Whose solutions
might we be
unraveling?
Biometric Unsecurity
Carina C. Zona
@cczona
“The narrow focus on technical
fairness is insufficient…it confines
us to thinking only about whether
something works, but doesn’t
permit us to ask whether it should
work. “
— Ruha Benjamin
“Race After Technology: Abolitionist Tools for the New Jim Code”
Biometric Unsecurity
Carina C. Zona
@cczona
#TechWontBuildItREFUSE TO BUILD OPPRESSIVE TECHNOLOGY
Biometric Unsecurity
Carina C. Zona
@cczona
Military Biometrics
https://twitter.com/william_fitz/status/1293976563940126721
Drones
Biometric Unsecurity
Carina C. Zona
@cczona
PAX Pledge
http://reprogrammingwar.org/tech
Lethal Autonomous Weapons
Public commitment to not contribute to
development or production.

Clear policy on that commitment.

Commitment to keep workers well-
informed about what they work on.

Allow open discussions on any related
concerns.
Biometric Unsecurity
Carina C. Zona
@cczona
https://www.theatlantic.com/technology/archive/2020/07/defund-facial-recognition/613771/
https://www.theatlantic.com/technology/archive/2020/07/defund-facial-recognition/613771/
Biometric Unsecurity
Carina C. Zona
@cczona
SAFEFACEPLEDGEsafefacepledge.org
Biometric Unsecurity
Carina C. Zona
@cczona
EXISTENTIAL
UNSECURITY
Biometric Unsecurity
Carina C. Zona
@cczona
HANDBACK
POWERTHAT
WASN'TOURS
TOGIVEAWAYhttps://twitter.com/zeynep/status/1301192357463941125
Biometric Unsecurity
Carina C. Zona
@cczona
•Fires
•Heat
•Hurricane
•Fire Tornados
•Siberia
•Arctic Shelf
Climate Change
Existential Unsecurity
Biometric Unsecurity
Carina C. Zona
@cczona
BASELINE MINIMUM CARBON IMPACT OF TRAINING A RESEARCH-QUALITY NLP
https://arxiv.org/abs/1906.02243v1 &https://calculator.carbonfootprint.com/calculator.aspx
Biometric Unsecurity
Carina C. Zona
@cczona
300.000KGCO2BASELINE MINIMUM CARBON IMPACT OF TRAINING A RESEARCH-QUALITY NLP
https://arxiv.org/abs/1906.02243v1 &https://calculator.carbonfootprint.com/calculator.aspx
300 OPO-DEL FLIGHTS
Biometric Unsecurity
Carina C. Zona
@cczona
We cannot wait for regulations. Around the world,
legislatures and courts are still dithering over whether
even 1st wave basics like fairness, accountability, and
transparency are necessary. Let alone whether, and how,
biometrics violate civil rights or human rights. When they
do consider biometrics, they are preoccupied foremost
with facial recognition; as if it is the only one—or the only
one posing threats. Their concern focuses on threats
posed by privacy, and by inaccuracy in policing. They
show little interest in threats imposed by precision. And
they disregard the role of consumers, including
individuals and NGOs.
Biometric Unsecurity
Carina C. Zona
@cczona
They neglect to invite tech workers to the table in
these crucial discussions. They greet billionaires as
spokepeople for every person in our industry. They
take for granted that C-levels and academics
understand applied technology better than the
people who build and use it. They do not ask us
whether we want our industry to center the self-
interests of VCs, or would rather our labor be used to
prioritize humanity. We cannot wait for them to draw
lines in the sand. They are too far behind, and always
will be.
Biometric Unsecurity
Carina C. Zona
@cczona
It's up to us.
To make choices,
take stands,
do concrete actions.
What will you do next?
Biometric Unsecurity
Carina C. Zona
@cczona
THANKYOU
Biometric Unsecurity
Carina C. Zona
@cczona
Resources
Biometric Unsecurity
Carina C. Zona
@cczona
Follow
recommendations
YouTube list
Biometric Unsecurity
Biometric Unsecurity
Carina C. Zona
@cczona
Follow
recommendations
Twitter list
Biometric Unsecurity
Biometric Unsecurity
Carina C. Zona
@cczona
Follow
recommendations
Twitter list
Tech Labor Organizing
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
World Cat list
Biometric Unsecurity
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
Simone Browne
On the Surveillance of Blackness
Dark Matters
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
Ruja Benjamin
Abolitionist Tools for the New Jim Code
Race After Technology
https://docs.google.com/document/d/
1mVOVN0V9l8jSNc3YZw1TLs4pm4FGw6
kj402hjoUv0LU/mobilebasic
+ Reading Group Guide
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
Virgina Eubanks
How High Tech Tools
Profile, Police, and Punish the Poor
Automating Inequality
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
Btihaj Ajana The Biopolitics of Identity
Governing Through
Biometrics
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
Keith Breckenridge
The Global Politics of Identification and
Surveillance in South Africa, 1850 to the Present
Biometric State
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
Shoshana Zuboff
The Fight for a Human Future
at the New Frontier of Power
The Age of
Surveillance Capitalism
Biometric Unsecurity
Carina C. Zona
@cczona
Books
recommendations
The Strategic Alliance Between Nazi Germany and
America's Most Powerful Corporation
IBM & the Holocaust
Biometric Unsecurity
Carina C. Zona
@cczona
Deep Dives
recommendations
https://www.nature.com/articles/s42256-020-0219-9
The Carbon Impact of Artificial Intelligence
Biometric Unsecurity
Carina C. Zona
@cczona
Film
recommendations
Shalini Kantayya
(screenings schedule: https://www.codedbias.com/screen)
Coded Bias
Biometric Unsecurity
Carina C. Zona
@cczona
AiMyths.org
recommendations

More Related Content

More from Carina C. Zona

Debugging Tech’s Socioeconomic Class Issues [Madison+ Ruby Conf 2014]
Debugging Tech’s Socioeconomic Class  Issues [Madison+ Ruby Conf 2014]Debugging Tech’s Socioeconomic Class  Issues [Madison+ Ruby Conf 2014]
Debugging Tech’s Socioeconomic Class Issues [Madison+ Ruby Conf 2014]
Carina C. Zona
 
What Is ZeroVM
What Is ZeroVMWhat Is ZeroVM
What Is ZeroVM
Carina C. Zona
 
Schemas for the Real World [Software Craftsmanship North America 2013]
Schemas for the Real World [Software Craftsmanship North America 2013]Schemas for the Real World [Software Craftsmanship North America 2013]
Schemas for the Real World [Software Craftsmanship North America 2013]
Carina C. Zona
 
Schemas for the Real World [Madison RubyConf 2013]
Schemas for the Real World [Madison RubyConf 2013]Schemas for the Real World [Madison RubyConf 2013]
Schemas for the Real World [Madison RubyConf 2013]
Carina C. Zona
 
Schemas for the Real World [RubyConf AU 2013]
Schemas for the Real World [RubyConf AU 2013]Schemas for the Real World [RubyConf AU 2013]
Schemas for the Real World [RubyConf AU 2013]
Carina C. Zona
 
Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...
Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...
Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...
Carina C. Zona
 
Hacking for Sex Education
Hacking for Sex EducationHacking for Sex Education
Hacking for Sex Education
Carina C. Zona
 
Cool Git Tricks (That I Learn When Things Go Badly) [1/2]
Cool Git Tricks (That I Learn When Things Go Badly) [1/2]Cool Git Tricks (That I Learn When Things Go Badly) [1/2]
Cool Git Tricks (That I Learn When Things Go Badly) [1/2]
Carina C. Zona
 

More from Carina C. Zona (8)

Debugging Tech’s Socioeconomic Class Issues [Madison+ Ruby Conf 2014]
Debugging Tech’s Socioeconomic Class  Issues [Madison+ Ruby Conf 2014]Debugging Tech’s Socioeconomic Class  Issues [Madison+ Ruby Conf 2014]
Debugging Tech’s Socioeconomic Class Issues [Madison+ Ruby Conf 2014]
 
What Is ZeroVM
What Is ZeroVMWhat Is ZeroVM
What Is ZeroVM
 
Schemas for the Real World [Software Craftsmanship North America 2013]
Schemas for the Real World [Software Craftsmanship North America 2013]Schemas for the Real World [Software Craftsmanship North America 2013]
Schemas for the Real World [Software Craftsmanship North America 2013]
 
Schemas for the Real World [Madison RubyConf 2013]
Schemas for the Real World [Madison RubyConf 2013]Schemas for the Real World [Madison RubyConf 2013]
Schemas for the Real World [Madison RubyConf 2013]
 
Schemas for the Real World [RubyConf AU 2013]
Schemas for the Real World [RubyConf AU 2013]Schemas for the Real World [RubyConf AU 2013]
Schemas for the Real World [RubyConf AU 2013]
 
Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...
Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...
Full Stack & Full Circle: What the Heck Happens In an HTTP Request-Response C...
 
Hacking for Sex Education
Hacking for Sex EducationHacking for Sex Education
Hacking for Sex Education
 
Cool Git Tricks (That I Learn When Things Go Badly) [1/2]
Cool Git Tricks (That I Learn When Things Go Badly) [1/2]Cool Git Tricks (That I Learn When Things Go Badly) [1/2]
Cool Git Tricks (That I Learn When Things Go Badly) [1/2]
 

Recently uploaded

Assure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyesAssure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyes
ThousandEyes
 
Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™
Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™
Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™
UiPathCommunity
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
Enhancing Performance with Globus and the Science DMZ
Enhancing Performance with Globus and the Science DMZEnhancing Performance with Globus and the Science DMZ
Enhancing Performance with Globus and the Science DMZ
Globus
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
KAMESHS29
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Aggregage
 
Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIs
Vlad Stirbu
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
SOFTTECHHUB
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance
 
Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?
Nexer Digital
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
Jemma Hussein Allen
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
Sri Ambati
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
Kari Kakkonen
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
ControlCase
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
OnBoard
 
A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...
sonjaschweigert1
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 

Recently uploaded (20)

Assure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyesAssure Contact Center Experiences for Your Customers With ThousandEyes
Assure Contact Center Experiences for Your Customers With ThousandEyes
 
Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™
Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™
Le nuove frontiere dell'AI nell'RPA con UiPath Autopilot™
 
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdfFIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
Enhancing Performance with Globus and the Science DMZ
Enhancing Performance with Globus and the Science DMZEnhancing Performance with Globus and the Science DMZ
Enhancing Performance with Globus and the Science DMZ
 
RESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for studentsRESUME BUILDER APPLICATION Project for students
RESUME BUILDER APPLICATION Project for students
 
Generative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to ProductionGenerative AI Deep Dive: Advancing from Proof of Concept to Production
Generative AI Deep Dive: Advancing from Proof of Concept to Production
 
Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIs
 
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
Why You Should Replace Windows 11 with Nitrux Linux 3.5.0 for enhanced perfor...
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?Elizabeth Buie - Older adults: Are we really designing for our future selves?
Elizabeth Buie - Older adults: Are we really designing for our future selves?
 
The Future of Platform Engineering
The Future of Platform EngineeringThe Future of Platform Engineering
The Future of Platform Engineering
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
DevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA ConnectDevOps and Testing slides at DASA Connect
DevOps and Testing slides at DASA Connect
 
PCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase TeamPCI PIN Basics Webinar from the Controlcase Team
PCI PIN Basics Webinar from the Controlcase Team
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
 
A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...A tale of scale & speed: How the US Navy is enabling software delivery from l...
A tale of scale & speed: How the US Navy is enabling software delivery from l...
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 

Biometric unsecurity

  • 1. Biometric Unsecurity Carina C. Zona @cczona BIOMETRICUNSECURITY DJANGOCON EUROPE // CARINA C. ZONA // SEPTEMBER 18, 2020
  • 2. Biometric Unsecurity Carina C. Zona @cczona Domination,Abuse, and Exploitation surveillance and stalking human rights violations and genocide policing and carceral systems immigration and border control religious bias and persecution refugees famine wildfires transphobia ableism psychological abuse sexual abuse (censored) NSFW images (cens**d & uncensored) slurs Content Warning
  • 3. Biometric Unsecurity Carina C. Zona @cczona BIOMETRICS BIOMETRICSPYTHONDJANGO
  • 6. Biometric Unsecurity Carina C. Zona @cczona Absolute Authentication Authorization This exactly matches that This is permitted Probabilistic Verification & Identification Categorization This seems akin to that Attributes of this seem to be
  • 7. Biometric Unsecurity Carina C. Zona @cczona Identification Is Not Identity Identification Compare credential data Data comparison. Username/password, security token, passport, key. Biometric identification Compare physical trait data. Sensor data comparison. Face, gait, heartbeat. Identity Who we know ourselves to be, individually and collectively. Culture, groupings. Race, gender, religion, ethnicity.
  • 8. Biometric Unsecurity Carina C. Zona @cczona UNSECURITYUNDOINGOFSAFETY UNSECURITY UNRAVELSAUTONOMY, FUNDAMENTAL SAFETY, HUMAN RIGHTS, EXISTENTIAL THREATS
  • 9. Biometric Unsecurity Carina C. Zona @cczona Trades Exactness for %
  • 10. Biometric Unsecurity Carina C. Zona @cczona SECURITYACCESS+CONTROLLOSS PREVENTION FOR VALUABLE ASSETS
  • 11. Biometric Unsecurity Carina C. Zona @cczona UNSECURITYACCESS+CONTROLACCESS TO PUBLIC SPHERE CONDITIONED ON CEDING PERSONAL CONTROL
  • 13. Biometric Unsecurity Carina C. Zona @cczona Unreusability (January2018-May2020)https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ PASSWORDRESET
  • 14. Biometric Unsecurity Carina C. Zona @cczona Unreusability (January2018-May2020)https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ PASSWORDRESET “BODYRESET”
  • 15. Biometric Unsecurity Carina C. Zona @cczona BODIESARE MUTABLE BIOMETRICS CHANGE Naturally Or Accidentally. Unconsciously Or Deliberately. Temporarily Or Permanently
  • 16. Biometric Unsecurity Carina C. Zona @cczona Data
  • 17. "COGNITIVE"/ BIOSIGNALS PHENOLOGICAL BEHAVIORAL Types • Visual expression of genetics • Actions • Neurological Responses Biometric Unsecurity Carina C. Zona @cczona fingerprint gait involuntary
  • 18. Biometric Unsecurity Carina C. Zona @cczona Probabilistic DETECT Person RECOGNIZE Trait ANALYSIS Verify (1:1) Classify (label) DATA Record Identify (1:M) "74.2% Hostile" "94.6% Activist" "67.9% Queer"
  • 19. Biometric Unsecurity Carina C. Zona @cczona • ECG • ECG • EKG Sensors • Optical • Thermal • Infrared • Microphone • Camera • Accelerometer • CCTV • Webcam • Body camera
  • 20. Biometric Unsecurity Carina C. Zona @cczona Data Sources • Smart speaker • Smart doorbell • Smart appliance • Arrest records • Watchlists • Body cameras • National ID • School ID • Drivers license • Passport & visa • Work permit • Refugee registration • Ghost workers • Smart glasses • Wearables • Stock photos • Paparazzi • Social media • Generated photos • Drone • Activity tracker
  • 21. Biometric Unsecurity Carina C. Zona @cczona UNIQUEA MEASURABLE STABLE BODY TRAIT THAT'S UNIQUE. EXACTLY ONE PERSON, PERIOD. UNIQUENESS IS ABSOLUTE.
  • 22. Biometric Unsecurity Carina C. Zona @cczona UNIQUEA MEASURABLE STABLE BODY TRAIT THAT'S UNIQUE. EXACTLY ONE PERSON, PERIOD. UNIQUENESS IS ABSOLUTE.
  • 23. Biometric Unsecurity Carina C. Zona @cczona Traits • Apparel • Accessories • Tatoos • Cardiac signature • Gestures • DNA • Skin temperature • Internal temperature • Skin color • Skin tone • Skin reflectance • Skin texture • Brain activity
  • 24. Biometric Unsecurity Carina C. Zona @cczona Traits • Head cover • Iris • Eye movement • Gaze direction • Face geometry • Earlobe geometry • Voice • Periocular geometry • Laughter • Face cover • Eye cover • Facial veins • Retina • Head movement • Facial expression • Head pose
  • 25. Biometric Unsecurity Carina C. Zona @cczona • Fingerprint • Palm print Traits • Finger veins • Palm veins • Blood flow pulse • Cardiac electric activity • Hand geometry • Typing speed • Typing cadence • Handwriting speed • Handwriting stroke order
  • 26. Biometric Unsecurity Carina C. Zona @cczona • Footprint Traits • Gait • Knee, leg, and ankle geometry
  • 27. Biometric Unsecurity Carina C. Zona @cczona • Trait distinctiveness • PIE (pose, illumination, exposure) • Cooperation • Sensors • Resolution • Noise • Distance • Duration • Skin reflectance • Body changes • Environment • Background • Occlusions • Activities • Make-up • Health • Hormones • Culture • Class • Gender • Race Biometrics Are Full of Biasing Variables More Data != More Accurate Sourcerefingerprint,iris,handgeometry: https://heimdalsecurity.com/blog/biometric-authentication/(May1,2019)
  • 28. Biometric Unsecurity Carina C. Zona @cczona BIOMETRIC DATASETS&PLATFORMS POWER UNSECURITY
  • 29. Biometric Unsecurity Carina C. Zona @cczona "IFWECOULDPUT MASSSURVEILLANCE INAPACKAGE… WEWOULD SENDITTOYOU." https://stealthisposter.org/poster/URL(centershttps://twitter.com/berlinvsamazon/status/1305553645602254848(right)
  • 30. Biometric Unsecurity Carina C. Zona @cczona TECHNICALDEBT PROJECT ETHICALDEBT PEOPLE
  • 31. Biometric Unsecurity Carina C. Zona @cczona Its collector comes only after harm has been inflicted https://www.wired.com/story/opinion-ethical-tech-starts-with-addressing-ethical-debt/
  • 32. Biometric Unsecurity Carina C. Zona @cczona https://twitter.com/_alialkhatib/status/1301281740527468544
  • 33. Biometric Unsecurity Carina C. Zona @cczona "What makes us think that A.I. won’t be mobilized to work toward anything but the detriment, rather than the interests of, Black people, anyway?" —Charlton McIlwain, "Black Software: The Internet & Racial Justice, From the AfroNet to Black Lives Matters” https://slate.com/technology/2020/08/algorithms-artificial-intelligence-racism-reparations-history.html
  • 34. Biometric Unsecurity Carina C. Zona @cczona " We never thought about misuse" is the precursor to ethical debt. https://www.wired.com/story/opinion-ethical-tech-starts-with-addressing-ethical-debt/
  • 35. Biometric Unsecurity Carina C. Zona @cczona https://www.nbcnews.com/tech/internet/facial-recognition-s-dirty-little-secret-millions-online-photos-scraped-n981921 CREATIVE COMMONS Copyright X Model consent to be defamed
  • 36. Biometric Unsecurity Carina C. Zona @cczona • Diversity in Faces • ImageNet: slurs • Tiny Images (MIT): slurs, NSFW Labels Datasets VinayUdayPrabhu&AbebaBirhane https://deepai.org/publication/large-image-datasets-a-pyrrhic-win-for-computer-vision
  • 37. Biometric Unsecurity Carina C. Zona @cczona EDUCATION UNSECURITY
  • 38. Biometric Unsecurity Carina C. Zona @cczona Face,fingerprint,behavioral, temperature • Entrance • Attendance • Meals • Messaging Schools Education Unsecurity "childreneating"bypedroreynahttps://www.flickr.com/photos/thebigtable/11695084114 "ChildrenEatIceCream"bylenifuzheadhttps://www.flickr.com/photos/lenifuzhead/64070145
  • 39. Biometric Unsecurity Carina C. Zona @cczona Face,behavioral,cognitive • Attendance • Proctoring Remote Edtech Education Unsecurity "childreneating"bypedroreynahttps://www.flickr.com/photos/thebigtable/11695084114 "ChildrenEatIceCream"bylenifuzheadhttps://www.flickr.com/photos/lenifuzhead/64070145
  • 40. Biometric Unsecurity Carina C. Zona @cczona Facial recognition • Violates GDPR • Coersive • Overeach • Less safety Schools Biometrics Shift Power "childreneating"bypedroreynahttps://www.flickr.com/photos/thebigtable/11695084114 "ChildrenEatIceCream"bylenifuzheadhttps://www.flickr.com/photos/lenifuzhead/64070145
  • 41. Biometric Unsecurity Carina C. Zona @cczona PROCTORINGEXAM MONITORING INVIGILATION
  • 42. Biometric Unsecurity Carina C. Zona @cczona https://twitter.com/NONBlNARY/status/1305138377629609985
  • 43. Biometric Unsecurity Carina C. Zona @cczona Proctoring Psychological Unsecurity "18" by Bambi WIllow https://search.creativecommons.org/photos/6af499cf-e866-4134-8f84-d140dc14dcbf Bias Privacy Abuse Ableism Facial Identification Gaze Tracking Voice tracking Attentiveness
  • 44. Biometric Unsecurity Carina C. Zona @cczona LIAR,LIARWFH MUST BE DISHONEST DISTANCE PROCTORING'S PREMISE PSYCHOLOGICAL ABUSE MUST BE OKAY
  • 45. Biometric Unsecurity Carina C. Zona @cczona https://twitter.com/legendariee16/status/1304098649186742273
  • 46. Biometric Unsecurity Carina C. Zona @cczona Name-calling. Lazy, suspicious, liar, worthless, failure, stupid. Monitoring whereabouts. Know where you are at all times. Intimidation.Threatening to take away something important, belittling accomplishments, humiliation. Isolation. From assistance, support, neutral observers. Digital spying. Browser history, keystrokes, app launches, window movements. More: violating boundaries, invading privacy, financial control, etc. https://www.medicalnewstoday.com/articles/325792 Control Via Fear Psychological Abuse
  • 47. Biometric Unsecurity Carina C. Zona @cczona "Children who had been psychologically abused suffered from anxiety, depression, low self-esteem, symptoms of post-traumatic stress and suicidality at the same rate and, in some cases, at a greater rate than children who were physically or sexually abused. Among the three types of abuse, psychological maltreatment was most strongly associated with depression, general anxiety disorder, social anxiety disorder, attachment problems and substance abuse." —"Psychological Trauma: Theory, Research, Practice, and Policy" review, American Pediatric Association https://www.apa.org/news/press/releases/2014/10/psychological-abuse
  • 48. Biometric Unsecurity Carina C. Zona @cczona • Racial bias of photo exposure algos* • Religious head coverings • Neurodiversity • Disabilities • Class differences • Homeless • Privacy of thoughts, interests • Privacy of home, family, roommates • Bullying • Stalking Proctoring Psychological Unsecurity https://www.slideshare.net/cczona/consequences-of-an-insightful-algorithm https://www.youtube.com/watch?v=YRI40A4tyWU(32:00-35:00)
  • 49. Biometric Unsecurity Carina C. Zona @cczona Once you’ve shown the whole space, you’re able to take the exam. For the duration of the exam, the camera and microphone are on recording the test- taker. Not only are sounds picked up by the microphone flagged, but it also flags every time the test-taker looks away from the screen. In the least problematic cases it flags for looking away while thinking—in the worst, it flags folks with physical disabilities as cheating. https://twitter.com/Angry_Cassie/status/1301360994044850182
  • 50. Biometric Unsecurity Carina C. Zona @cczona Proctoring/Invigilation Phenotypical Behavioral Non-biometric Other Proctorio ProctorTrack ProctorU Examity Face (3D) Finger knuckle patterns Head movements Mouth movements Eye movememts Voice & vocalizations Keystroke patterns Name Address Phone number Parent name Drivers license Birthdate 360 scan of room Scan of desk No sound/voices Real-time surveillance Computer & browser control Record screen, webcam, audio No head covering, ear covering, jewelry, or accessories No CDs, glasses, mirror, toaster Mac or Windows. System administration privileges. Chrome or Firefox. 3rd party application (not via app store), Applet, browser extension, or Flash Player. Webcam, headphones, and microphone. Broadband. Private room. Well-lit.
  • 51. Biometric Unsecurity Carina C. Zona @cczona Elevating Speculation To (Harmfully False) Objectivity
  • 52. Biometric Unsecurity Carina C. Zona @cczona • Detect: eyes, face, angle • Identify: gaze direction, movements relative to fixed point • Assumption: not maintaining gaze is meaningful. • interpretation: inattention (a mental state), non-compliance, underproductive, distracted • personal consequences: grades, income, trust • Insititional consequences: underestimate people (including implied judgement of intelligence), loss of talent • Socioeconomic consequences: fail, loss of financial aid or diploma, unemployment, incarceration • Expense consequences: equipment, personnel, training, subscriptions, technical support, updates Gaze Tracking Students & Workers Thought Stalkery
  • 53. Biometric Unsecurity Carina C. Zona @cczona OUTERAPPEARANCE TOINFER INNERCHARACTER PHYSIOGNOMY
  • 54. Biometric Unsecurity Carina C. Zona @cczona OUTERAPPEARANCE TOINFER INNERCHARACTER PHYSIOGNOMY JUNKSCIENCE
  • 55. Biometric Unsecurity Carina C. Zona @cczona INCOME UNSECURITY
  • 56. Biometric Unsecurity Carina C. Zona @cczona https://www.cbsnews.com/news/job-hunting-ai-is-judging-you-but-critics-say-its-snake-oil/ Hiring HireVue
  • 57. Biometric Unsecurity Carina C. Zona @cczona Vocabulary, word choices, expressions, more… “In a 20-minute interview, we can collect a lot of data. We have no idea who the candidate is, but we can collect a lot of data about vocal variation, personal pronouns” and other information to make an assessment. https://www.cbsnews.com/news/job-hunting-ai-is-judging-you-but-critics-say-its-snake-oil/ Hiring HireVue
  • 58. Biometric Unsecurity Carina C. Zona @cczona https://twitter.com/random_walker/status/1195347349427687425 Hiring 8 and Above
  • 59. Biometric Unsecurity Carina C. Zona @cczona • Stress • Emotions • Thoughts • Honesty • Criminality • Employability • Wakefulness • Attentiveness Affectmetrics Is Mind-Reader B.S. Mental State Physiognomy
  • 60. Biometric Unsecurity Carina C. Zona @cczona “NOSUBSTANTIALEVIDENCE” FORAFFECTMETRICS—AI NOW INSTITUTE
  • 61. Biometric Unsecurity Carina C. Zona @cczona Mind-Reading,Charlatanism,Projection Pseudoscience Modalities Psychometrics Demographics Physical Stress Mood Affect Vocal Tone Age Gender Race Ethnicity Nationality Behavioral Liveness Awake Attention Neurological Attitude Memories Tendencies
  • 62. Biometric Unsecurity Carina C. Zona @cczona PSEUDOMEDICAL BIOMETRICS
  • 63. Biometric Unsecurity Carina C. Zona @cczona "Amazon says Halo uses “multiple advanced sensors” to provide “highly accurate information,” but Halo isn’t a medical device. Unlike the Apple Watch and some other devices, Halo’s functions haven’t been cleared by the Food and Drug Administration." Amazon Halo Pseudomedical Biometrics https://onezero.medium.com/want-a-free-amazon-halo-wearable-just-hand-over-your-data-to-this-major-insurance-company-56b6430b0749
  • 64. Biometric Unsecurity Carina C. Zona @cczona 1. leverages our deep expertise in artificial intelligence (AI) 2. help customers understand how they sound to others 3. helping improve their communication and relationships 4. analyze the positivity and energy of your voice 5. positivity is measured by how happy or sad you sound, and energy is how excited or tired you sound 6. you might see that in the morning you sounded calm, delighted, and warm Extraordinary Claim— Junk Science https://blog.aboutamazon.com/devices/a-new-tool-to-help-you-understand-and-improve-your-social-wellbeing not psychology basis for psychological claim? evidence of causality? 3rd Party Consent sound to who? threshold for assigning labels? validated axes? for stress? comm? relationships?
  • 65. Biometric Unsecurity Carina C. Zona @cczona Points 1 & 2 aren't about "voice tone", "voice positivity", or "voice energy". Citations 1 & 2 link to the page's own URL. There is no citation 3. Amazon has cited no study, no evidence, no psychologist. Let alone rigorous independent science. ...Extraordinary Lack of Evidence Junk Science https://blog.aboutamazon.com/devices/a-new-tool-to-help-you-understand-and-improve-your-social-wellbeing
  • 66. Biometric Unsecurity Carina C. Zona @cczona Projection Pseudoscience "I SAID A THING." "THEY THINK YOU FEEL ______"
  • 67. Biometric Unsecurity Carina C. Zona @cczona Projection casts images onto a blank screen. Psychological projections are external representations that may bear little to no relationship with the person they are ascribed to. https://narcissistfamilyfiles.com/2017/10/03/the-narcissists-funhouse-of-mirroring-and-projection
  • 68. Biometric Unsecurity Carina C. Zona @cczona Abusers Love Projection Section Title https://psychcentral.com/lib/narcissists-and-abusers-use-this-to-target-empaths (image) Positive Projections Negative Projections 1. Support grandiose assertions 2. Control through favoritism 3. Take credit for others 4. Show an idealized face to the world 1. Escape accountability 2. Expel self-doubt and self-hatred 3. Justify manipulation and exploitation 4. Blame others for their own abusive behavior
  • 69. Biometric Unsecurity Carina C. Zona @cczona Biometrics Power Alter
  • 70. Biometric Unsecurity Carina C. Zona @cczona HYPEISAWEAPON
  • 71. Biometric Unsecurity Carina C. Zona @cczona SOCIAL UNSECURITY
  • 72. Biometric Unsecurity Carina C. Zona @cczona Aadhaar Identification Number Face Irises Fingers Economic Unsecurity "Inclusion." "Ease." "Voluntary."
  • 73. Biometric Unsecurity Carina C. Zona @cczona https://www.bloomberg.com/features/2020-covid-vaccine-tracking-biometric/
  • 74. Biometric Unsecurity Carina C. Zona @cczona AnkitaAggarwal(research)&JessicaPudussery(animation) Biometric Unsecurity Carina C. Zona @cczona Nearly 3 hundred thousand people cutoff from their pensions by biometric identifier system’s shortcomings.
  • 75. Biometric Unsecurity Carina C. Zona @cczona https://rethinkaadhaar.in/testimonials/2018/1/17/i-do-not-get-rations-they-say-machine-does-not-recognise-your-fingerprints Biometric Unsecurity Carina C. Zona @cczona
  • 76. Biometric Unsecurity Carina C. Zona @cczona As of January 2020, 1.2 billion Indians – including 95% of adults – have an Aadhaar https://timesofindia.indiatimes.com/blogs/toi-edit-page/aadhaar-at-10-taking-stock-the-unfinished-work-lies-with-the-most-vulnerable-sections-of-society/
  • 77. Biometric Unsecurity Carina C. Zona @cczona “Over 2/3 of the 4.7% whose biometrics failed during authentication were still able to get rations. The remaining one-third remain an urgent action item for India.” https://timesofindia.indiatimes.com/blogs/toi-edit-page/aadhaar-at-10-taking-stock-the-unfinished-work-lies-with-the-most-vulnerable-sections-of-society/
  • 78. Biometric Unsecurity Carina C. Zona @cczona AnkitaAggarwal(research)&JessicaPudussery(animation) Biometric Unsecurity Carina C. Zona @cczona Mission creep Design for privileged bodies Income unsecurity Food unsecurity Trust and safety unsecurity
  • 79. Biometric Unsecurity Carina C. Zona @cczona UNSECURITY EXPLOITS PANDEMIC& PROTEST
  • 80. Biometric Unsecurity Carina C. Zona @cczona "At every step there were police present, and drones being flown overhead constantly. 10am in the morning till 11-12pm at night." COVID-19https://twitter.com/inetdemocracy/status/1300743592281923586?s=21 — Muslim woman living in predominantly Muslim neighbourhood in Jharkhand, India
  • 81. Biometric Unsecurity Carina C. Zona @cczona https://www.theverge.com/2020/8/26/21402978/clearview-ai-ceo-interview-2400-police-agencies-facial-recognition "Clearview AI was used at least once to identify protesters in Miami." "Facial recognition was also used by the New York Police Department to arrest an activist during the Black Lives Matter uprising this summer."
  • 83. EXTERNALS PSYCHOLOGICAL BEHAVIORAL Unmasking • Periocular • Voice • Gait • Tattos • Clothes • Mask Biometric Unsecurity Carina C. Zona @cczona periocular tattoogait
  • 84. Biometric Unsecurity Carina C. Zona @cczona CIVIL UNSECURITY
  • 85. Biometric Unsecurity Carina C. Zona @cczona Military Biometrics Ethics
  • 86. Biometric Unsecurity Carina C. Zona @cczona Paramilitary Biometrics Drones
  • 87. Biometric Unsecurity Carina C. Zona @cczona Military Biometrics Drones
  • 88. Biometric Unsecurity Carina C. Zona @cczona REFUGEES
  • 89. Biometric Unsecurity Carina C. Zona @cczona OVER1MILLIONMUSLIM ROHINGYA IN WORLD'S LARGEST REFUGEE CAMP https://www.vice.com/en_us/article/dyzjqy/for-the-last-three-years-more-than-a-million-rohingya-muslims-have-been-stuck-in-bangladesh
  • 90. Biometric Unsecurity Carina C. Zona @cczona https://www.rfa.org/english/news/myanmar/rohingya-children-08242020213342.html
  • 91. Biometric Unsecurity Carina C. Zona @cczona U nited Nations investigators detailed atrocities committed by the Myanmar military against the Rohingya during the 2017 crackdown and called for those responsible to be prosecuted for “genocidal intent.” https://www.rfa.org/english/news/myanmar/rohingya-refugees-protest-strike-11262018154627.html
  • 92. Biometric Unsecurity Carina C. Zona @cczona https://www.wired.co.uk/article/united-nations-refugees-biometric-database-rohingya-myanmar-bangladesh Rohingya Refugees
  • 93. Biometric Unsecurity Carina C. Zona @cczona Bantu Rohingya Syrians Yemeni many others Biometrics, or Your Life
  • 94. Biometric Unsecurity Carina C. Zona @cczona LITERALLYNOTHINGLEFTBUT BODYANDNOWTHEYWANTTHAT TOO
  • 95. Biometric Unsecurity Carina C. Zona @cczona 7.2MILLION* AS OF 2 YEARS AGO… REFUGEES’ BIOMETRIC INFO TAKEN BY U.N. *
  • 96. Biometric Unsecurity Carina C. Zona @cczona "The Rohingya are fleeing violence and persecution on the basis of their identities. Now their most intimate information is being collected and stored in a database over which they have no control." https://www.wired.co.uk/article/united-nations-refugees-biometric-database-rohingya-myanmar-bangladesh
  • 97. Biometric Unsecurity Carina C. Zona @cczona https://www.unhcr.org/uk/550c304c9.pdf#zoom=95 UNHCRThailand/ Karenni A refugee provides his iris scan and fingerprints as part of a verification exercise jointly conducted by UNHCR and the RoyalThai Government in January 2015 regarding the identities of 120,000 persons of concern inWestern Thailand. (UNHCR/ S. Jefferies/ January 2015). Through its Key Initiatives series, UNHCR’S Division of Programme Support and Management (DPSM) shares regular updates on interesting projects that produce key tools, practical guidance and new approaches aimed at moving UNHCR operations forward. In February 2015, DPSM and the Division of Information Systems and Telecommunications (DIST) completed development of UNHCR’s new biometric identity management system (BIMS), building on the successful use of biometrics across a number of UNHCR operations globally. When rolled out, BIMS will support all standard registration activities and help to better register and protect people, verify their identity and target assistance for the forcibly displaced in operations around the world. Re-establishing and preserving identities is key to ensuring protection and solutions for refugees. By linking new technologies, such as biometrics to existing registration data, UNHCR can strengthen the integrity of existing processes and significantly improve efficiency for operations. Being able to verify identities is extremely important and a matter of human dignity. Biometric Identity Management System Enhancing Registration and Data Management Malawi / A young girl is having her irises scanned in order to be enrolled in the biometrics registration exercise at the Dzaleka refugee camp. She sits against a grey background, as it has been found early on in the pilot that either grey or blue backgrounds allow for improved quality facial recognition scanning. / UNHCR / T. Ghelli / December 2013) USING BIOMETRICS TO SAFEGUARD IDENTITIES The use of biometrics provides an accurate way to verify identities using unique physiological characteristics, such as fingerprints, iris and facial features. In accordance with UNHCR’s Policy on Biometrics in Refugee Registration and Verification (2010), biometrics should be used as a routine part of identity management to ensure that refugees’ personal identities cannot be lost, registered multiple times or subject to fraud or identity theft. FIELD TESTING OF BIOMETRIC IDENTITY MANAGEMENT Since 2013, UNHCR has been developing a new global Biometric Identity Management System (BIMS). During initial pilot testing in Malawi, 17,000 refugees were enrolled into the system and a variety of field conditions were tested. “I can be someone now. I am registered globally with the UN and you’ll always know who I am,” said 43-year-old Congolese refugee Olivier Mzaliwa, registered through biometrics in Malawi’s Dzaleka refugee camp. In January 2015, with essential support from UNHCR Thailand, a joint DIST – DPSM team conducted final field testing of BIMS in Thailand. The new system permits the much faster and accurate verification of identities than the manual search for records in UNHCR’s database that was previously required. This allows UNHCR to assist large volumes of refugees and others of concern more quickly and efficiently. MORE INFORMATION For more information, please contact UNHCR’s Field Information and Coordination Support Section at: FICSS@unhcr.org contact info: FICSS@unhcr.org WHAT COMES NEXT? Following the rollout of BIMS to Thailand, the UNHCR BIMS team will undertake a number of activities in preparation for the further rollout across operations globally, further enhancing UNHCR’s registration and data management. Development: Resolve development bugs in BIMS identified during the exercise in Thailand to be ready for the next deployment; Make biometric identity verification an integral part of assistance distribution where required; Work to ensure that BIMS can be integrated with proGres - UNHCR’s registration and case management tools; Deployment: DPSM field support team and regional registration teams to plan and prepare for upcoming BIMS roll outs through 2015 and 2016; including: Supporting exercises to verify identities of refugees and others of concern in Chad and India; Maintaining communications with UNHCR operations globally to plan and prepare for BIMS global roll-out; Support: Developing a support model that ensure a sustainable use of BIMS after its deployment; Establishing network of qualified and experienced BIMS users, reinforcing capacity and ensuring correct system use. Thailand / Multiple fingerprints are recorded simultaneously with the new BIMS system. / UNHCR / S. Jefferies/ January 2015 Thailand / Iris scans are quickly and easily recorded during Biometric enrolment. / UNHCR / S. Jefferies / January 2015 INNOVATIVE SYSTEM DESIGN BIMS operates under a wide range of infrastructure conditions and can provide numerous operational and protection benefits to existing identity management practices. Better coverage Unlike previous UNHCR biometric systems, BIMS captures and stores all fingerprints and iris scans from refugees and others of concern. Capturing these multiple characteristics, rather than relying for example only on finger-prints, allows for more complete coverage of the population and, thus, more accurate identification. Operational in various contexts Though benefiting from an online system architecture, BIMS has been designed to also work seamlessly when no internet connection is available due to weak connectivity. BIMS also comes in a portable, mobile configuration using a conventional laptop and requiring no extra source of power to use the USB driven fingerprint scanners, iris scanners and webcams. “During our recent pilot in Thailand, we had 20 operators working full-time, and not one of them was affected by the fact that the satellite connection was dropping out for several hours a day. The system automatically queued their operations. That kind of service offers some real opportunities for UNHCR” – BIMS Infrastructure Architect Pat Kartas. Quick processing Identifying a person using BIMS is quick and simple. After enrolment, refugees and others of concern need only to present two or more biometric elements (e.g., two fingers, two eyes, or a combination thereof) for BIMS to be able to ascertain their identity within seconds. The matching time for identity checks during the roll out in Thailand was on average five seconds. refugees were e of field conditions were tested. “I can be someone now. I am registered globally with the UN and you’ll always know who I am,” said 43-year-old Congolese refugee Olivier Mzaliwa, registered through biometrics in Malawi’s Dzaleka refugee camp. In January 2015, with essential support from UNHCR Thailand, a joint DIST – DPSM team conducted final field testing of BIMS in Thailand. The new system permits the much faster and accurate verification of identities than the manual search for records in HCR’s database that was previously required. This umes of refugees captures and stores a from refugees and ot these multiple chara example only on fin complete coverage more accurate iden Operational in v Though benefitin architecture, BIM seamlessly when due to weak con portable, mobi laptop and req dr
  • 98. Biometric Unsecurity Carina C. Zona @cczona https://www.unhcr.org/uk/550c304c9.pdf#zoom=95 Fingers Irises Face
  • 103. Biometric Unsecurity Carina C. Zona @cczona GENOCIDE
  • 105. Biometric Unsecurity Carina C. Zona @cczona https://www.buzzfeednews.com/article/meghara/china-new-internment-camps-xinjiang-uighurs-muslims 268NEWLYBUILT COMPOUNDS
  • 106. Biometric Unsecurity Carina C. Zona @cczona 1MILLION= EVERYPERSONIN KOLNORODESSA
  • 107. Biometric Unsecurity Carina C. Zona @cczona 1MILLIONUIGHERS =1/2THEPOPULATION OFPARISORVIENNA
  • 108. Biometric Unsecurity Carina C. Zona @cczona “The largest-scale detention of ethnic and religious minorities since World War II” —Buzzfeed https://www.buzzfeednews.com/article/meghara/china-new-internment-camps-xinjiang-uighurs-muslims
  • 109. Biometric Unsecurity Carina C. Zona @cczona Muslims in Xinjiang — half its population of about 25 million —are under perpetual surveillance —Buzzfeed https://www.buzzfeednews.com/article/meghara/china-new-internment-camps-xinjiang-uighurs-muslims
  • 110. Biometric Unsecurity Carina C. Zona @cczona Architecture in which everyone is under continuous potential surveillance. One guard, but impossible to know when it’s you being watched. Uncertainty ensures universal self- policing. How to Panopticon Panopticonic Gaze https://en.wikipedia.org/wiki/Panopticon
  • 111. Biometric Unsecurity Carina C. Zona @cczona • Face • Fingerprint • Palm • Iris • Voice • Speech pattern • Gait • Blood type • DNA • Emotions Sources: • Mandatory “physicals” • Police • CCTV Ethnic & Religous Minorities in China Panopticonic Gaze HumanRightsWatchhttps://www.hrw.org/news/2017/12/13/china-minority-region-collects-dna-millions https://www.hrw.org/news/2017/10/22/china-voice-biometric-collection-threatens-privacy
  • 112. Biometric Unsecurity Carina C. Zona @cczona 3rd Wave Data Ethics
  • 113. Biometric Unsecurity Carina C. Zona @cczona https://venturebeat.com/2020/08/23/the-term-ethical-ai-is-finally-starting-to-mean-something/ https://venturebeat.com/2020/08/23/the-term-ethical-ai-is-finally-starting-to-mean-something/
  • 114. Biometric Unsecurity Carina C. Zona @cczona PHILOSOPHICAL Principles Fairness Accountability Transparency “AI will help solve problems” TECHNICAL Fixed It! Interventions Re-training Tuning “The right data + unbiased algorithm = ethical” SOCIETAL Impact Power Equity Action “Expose, critique, and change systems of power” What can we do? 1 2 3 What should we do? Whose power are we reinforcing? Whose vulnerability are we exacerbating? What threats do our (in)actions contribute to? Whose problems are we solving? Whose solutions might we be unraveling?
  • 115. Biometric Unsecurity Carina C. Zona @cczona PHILOSOPHICAL Principles Fairness Accountability Transparency “AI will help solve problems” TECHNICAL Fixed It! Interventions Re-training Tuning “The right data + unbiased algorithm = ethical” SOCIETAL Impact Power Equity Action “Expose, critique, and change systems of power” What can we do? 1 2 3 What should we do? are we reinforcing? Whose vulnerability are we exacerbating? What threats do our (in)actions contribute to? Whose problems are we solving? Whose solutions might we be unraveling?
  • 116. Biometric Unsecurity Carina C. Zona @cczona “The narrow focus on technical fairness is insufficient…it confines us to thinking only about whether something works, but doesn’t permit us to ask whether it should work. “ — Ruha Benjamin “Race After Technology: Abolitionist Tools for the New Jim Code”
  • 117. Biometric Unsecurity Carina C. Zona @cczona #TechWontBuildItREFUSE TO BUILD OPPRESSIVE TECHNOLOGY
  • 118. Biometric Unsecurity Carina C. Zona @cczona Military Biometrics https://twitter.com/william_fitz/status/1293976563940126721 Drones
  • 119. Biometric Unsecurity Carina C. Zona @cczona PAX Pledge http://reprogrammingwar.org/tech Lethal Autonomous Weapons Public commitment to not contribute to development or production. Clear policy on that commitment. Commitment to keep workers well- informed about what they work on. Allow open discussions on any related concerns.
  • 120. Biometric Unsecurity Carina C. Zona @cczona https://www.theatlantic.com/technology/archive/2020/07/defund-facial-recognition/613771/ https://www.theatlantic.com/technology/archive/2020/07/defund-facial-recognition/613771/
  • 121. Biometric Unsecurity Carina C. Zona @cczona SAFEFACEPLEDGEsafefacepledge.org
  • 122. Biometric Unsecurity Carina C. Zona @cczona EXISTENTIAL UNSECURITY
  • 123. Biometric Unsecurity Carina C. Zona @cczona HANDBACK POWERTHAT WASN'TOURS TOGIVEAWAYhttps://twitter.com/zeynep/status/1301192357463941125
  • 124. Biometric Unsecurity Carina C. Zona @cczona •Fires •Heat •Hurricane •Fire Tornados •Siberia •Arctic Shelf Climate Change Existential Unsecurity
  • 125. Biometric Unsecurity Carina C. Zona @cczona BASELINE MINIMUM CARBON IMPACT OF TRAINING A RESEARCH-QUALITY NLP https://arxiv.org/abs/1906.02243v1 &https://calculator.carbonfootprint.com/calculator.aspx
  • 126. Biometric Unsecurity Carina C. Zona @cczona 300.000KGCO2BASELINE MINIMUM CARBON IMPACT OF TRAINING A RESEARCH-QUALITY NLP https://arxiv.org/abs/1906.02243v1 &https://calculator.carbonfootprint.com/calculator.aspx 300 OPO-DEL FLIGHTS
  • 127. Biometric Unsecurity Carina C. Zona @cczona We cannot wait for regulations. Around the world, legislatures and courts are still dithering over whether even 1st wave basics like fairness, accountability, and transparency are necessary. Let alone whether, and how, biometrics violate civil rights or human rights. When they do consider biometrics, they are preoccupied foremost with facial recognition; as if it is the only one—or the only one posing threats. Their concern focuses on threats posed by privacy, and by inaccuracy in policing. They show little interest in threats imposed by precision. And they disregard the role of consumers, including individuals and NGOs.
  • 128. Biometric Unsecurity Carina C. Zona @cczona They neglect to invite tech workers to the table in these crucial discussions. They greet billionaires as spokepeople for every person in our industry. They take for granted that C-levels and academics understand applied technology better than the people who build and use it. They do not ask us whether we want our industry to center the self- interests of VCs, or would rather our labor be used to prioritize humanity. We cannot wait for them to draw lines in the sand. They are too far behind, and always will be.
  • 129. Biometric Unsecurity Carina C. Zona @cczona It's up to us. To make choices, take stands, do concrete actions. What will you do next?
  • 130. Biometric Unsecurity Carina C. Zona @cczona THANKYOU
  • 131. Biometric Unsecurity Carina C. Zona @cczona Resources
  • 132. Biometric Unsecurity Carina C. Zona @cczona Follow recommendations YouTube list Biometric Unsecurity
  • 133. Biometric Unsecurity Carina C. Zona @cczona Follow recommendations Twitter list Biometric Unsecurity
  • 134. Biometric Unsecurity Carina C. Zona @cczona Follow recommendations Twitter list Tech Labor Organizing
  • 135. Biometric Unsecurity Carina C. Zona @cczona Books recommendations World Cat list Biometric Unsecurity
  • 136. Biometric Unsecurity Carina C. Zona @cczona Books recommendations Simone Browne On the Surveillance of Blackness Dark Matters
  • 137. Biometric Unsecurity Carina C. Zona @cczona Books recommendations Ruja Benjamin Abolitionist Tools for the New Jim Code Race After Technology https://docs.google.com/document/d/ 1mVOVN0V9l8jSNc3YZw1TLs4pm4FGw6 kj402hjoUv0LU/mobilebasic + Reading Group Guide
  • 138. Biometric Unsecurity Carina C. Zona @cczona Books recommendations Virgina Eubanks How High Tech Tools Profile, Police, and Punish the Poor Automating Inequality
  • 139. Biometric Unsecurity Carina C. Zona @cczona Books recommendations Btihaj Ajana The Biopolitics of Identity Governing Through Biometrics
  • 140. Biometric Unsecurity Carina C. Zona @cczona Books recommendations Keith Breckenridge The Global Politics of Identification and Surveillance in South Africa, 1850 to the Present Biometric State
  • 141. Biometric Unsecurity Carina C. Zona @cczona Books recommendations Shoshana Zuboff The Fight for a Human Future at the New Frontier of Power The Age of Surveillance Capitalism
  • 142. Biometric Unsecurity Carina C. Zona @cczona Books recommendations The Strategic Alliance Between Nazi Germany and America's Most Powerful Corporation IBM & the Holocaust
  • 143. Biometric Unsecurity Carina C. Zona @cczona Deep Dives recommendations https://www.nature.com/articles/s42256-020-0219-9 The Carbon Impact of Artificial Intelligence
  • 144. Biometric Unsecurity Carina C. Zona @cczona Film recommendations Shalini Kantayya (screenings schedule: https://www.codedbias.com/screen) Coded Bias
  • 145. Biometric Unsecurity Carina C. Zona @cczona AiMyths.org recommendations