Surveillance devices get smaller… but it’s privacy that vanishes.

I’ve been blogging for a while about miniaturization and the ‘vanishing’ of surveillance devices. This disappearance occurs in many ways, one of which is the incorporation of high-tech surveillance features into objects and devices that we are already used to or their reduction to a size and form factor that is relatively familiar. Two examples coincidentally arrived in my inbox over the last week.

The first was the news that the US Navy has awarded a development contract for binoculars that incorporate three-dimensional face-recognition technology from StereoVision Inc (who may well be the bunch of  California-based face recog people I met at a biometrics industry show a few years back). This supposedly gets round the problems that standard two-dimensional face recognition has dealing with unpredictably mobile crowds of people in natural light (AKA ‘the real world’). The issue I’m highlighting here however is that we don’t expect binoculars to be equipped with face recognition. Binoculars may not be entirely socially acceptable items, and already convey implications of creepy voyeurism when used in urban or domestic situations, however this is something else entirely.

NY-CD236_NYPD1_G_20130123200238
Small terahertz wave scanner being tested by NYPD in January (NYPD_

The second is the extraordinarily rapid ongoing progress towards working handheld terahertz wave technology (a far more effective form of scanning technology than either the backscatter x-ray or millimeter wave systems used in the bulky bodyscanners currently in use at airports). Just four years ago, I noted the theoretical proof that this was possible, and last month, it was revealed that police in New York were testing handheld terahertz wave scanners, (Thruvision from Digital Barriers) which of course people were likening to Star Trek’s tricorders. The idea that the police could perform a virtual strip search on the street without even having to ask is again, a pretty major change, but it’s also the case that the basic technology can be incorporated into standard video camera systems – potentially everyone with a mobile phone camera could be doing this in a few years.

I’m not a technological determinist, but in the context of societies in which suspicion, publicity and exposure are becoming  increasingly socially normative, I have to ask what these technologies and many others like them imply for conventional responses based on ‘privacy’. Privacy by design is pretty much a joke when the sole purpose of such devices is to breach privacy. And control by privacy regulators is based on the ability to know that one is actually under surveillance – when everything can potentially be performing some kind of highly advanced surveillance, how is one able to tell, let alone select which of the constant breaches of privacy is worth challenging? So, do we simply ban the use of certain forms of surveillance technology in public places? How, would this be enforced given that any conventional form factor might or might not contain such technology? And would this simply result in an even more intense asymmetry of the gaze, when the military and the police have such devices, but people are prevented from using them? Do we rely of camouflage, spoofing and disabling techniques and technologies against those who might be seeking to expose us? You can bet the state will not be happy if these become widespread – just look at the police reaction to existing sousveillance and cop-watching initiatives…

Here comes the US ID-card push

For a while now, I’ve been wondering why the US didn’t attempt to push for a national biometric ID card system in the wake of the 9/11 bombings.

Given reported statements from biometrics industry bosses about 9/11 being ‘what we’ve been waiting for’ and so on, one might have expected there to be a major effort in this direction but officially, as Zureik and Hindle (2004) point out, the International Biometrics Industry Association (IBIA) was relatively cautious in its post-9/11 press work, although it argued that biometrics had a major role to play in the fight against terrorism. Even the 9/11 Commission didn’t recommend a national ID card scheme, instead limiting itself in its final report to In its final report, to recommending a “biometric entry-exit screening system” for travelers in and out of the USA.

Part of this is because of the uneasy relations between the federal government and states governments, and suspicion of the former from the latter, and particularly from the political right has meant national ID cards have always been out of the question, even in an era of identification. So even though ID is frequently required in social situations, especially in dealing with banks, police and government agencies, the US relies on the ubiquitous driver’s licenses, which are issued by states not by the federal government. I remember from my time living in the US (in Virginia) as a non-driver, that in order to have valid form of ID, I had the choice of either carrying my passport or getting a special non-driver’s driver’s license, which always struck me simply as an absurd commentary on the importance of the automobiles in US life because, being young at the time, the nuances of federal-state relationships escaped me. And of course, passports won’t cut it for most, as less than 50% of US citizens have one.

So, if the apparently ubiquitous threat of terrorism was not going to scare states’ rights advocates and the right in general into swallowing the industry lines about security that they might usually have lapped up, what would? Well, the one thing that scares the right more than terrorism – Mexicans! More seriously, the paranoia about undocumented migrants combined with the spiralling cost of oppressive yet clearly ineffective border control (walls, drones, webcams, vigilantes etc. etc.) seems to have no done what the fear of terrorism could not, and inspired a push on both the centre and the right for ID cards – not that there’s much evidence that biometric ID cards will do a better job of excluding undocumented migrants, given that they do nothing to address what’s driving this migration – the demand for cheap, tax-free labour in the USA.

Today, not only the beltway insider’s bible, the Washington Post has an editorial demanding biometric social security cards for all (and a concomitant reduction in spending on hardening the border) following on from a cross-party senate recommendation, but also the Los Angeles Times, a paper which in the past has often been wary of the march to a ‘surveillance society’ – indeed it was the first major US newspaper to use this term, way back in 1970 as well as publishing critics like Gary Marx (see Murakami Wood, 2009) – has an op-ed arguing for a national ID card. The LA Times version, written by Robert Pastor, also claims that this is necessary to deal with voter fraud, a constant concern of the right and which always has a strong undertone of racism, so it’s unsurprising coming after a black Democrat has been elected as President for a second time in a tight election. Ironically, however, the President whose supporters are clearly the target of such attacks, has recently made it clear that he is also a supporter of a ‘tamper-proof’ national ID system.

No-one has yet made the international competition argument that is also so often used in these debates (‘if India and Brazil can do it, then surely the USA can’), but this debate is now ramping up in a way that even 9/11 couldn’t manage. Interesting times ahead…

References:

Murakami Wood, David. “The Surveillance Society’: Questions of History, Place and Culture.” European Journal of Criminology 6.2 (2009).
Zureik, Elia, and Karen Hindle. “Governance, security and technology: the case of biometrics.” Studies in Political Economy 73 (2004).
(thanks to Sarah Soliman and Aaron Martin for the newspaper articles…)

The Iconography of High Velocity DNA tagging

There’s been quite a lot of media coverage in the last few days about the ‘High Velocity DNA Tagging System‘, made by UK company Selectamark, and apparently in line to be purchased by several UK police forces. The system uses a kind of airgun that can fire “a uniquely-coded DNA pellet” for up to 30-40 metres, which “can be used to mark an individual so that they can be apprehended at a less confrontational time for officers.” Claims on the website include one that the microdots of artificial DNA can penetrate through clothing and mark the skin of individuals, and also that the artificial DNA used can result in ‘infinite number’ of unique numerical identifiers.

None of this is entirely new: Selectamark is a company who’s core business is anti-theft marking of equipment, and essentially what they have done is create a gun-based delivery system for an existing technology that was previously used to mark things, thus turning it into a system for identifying individual human beings, in much the same way as has been suggested would occur with RFID implants (but which has not yet really happened in any widespread fashion). Like RFID, the identification is not biometric, i.e. resulting from unique bodily characteristics, but what amounts to a high-tech form of instant temporary tattooing or paint-marking. The company is silent on how temporary this is – and whether the microdots – which are just visible, but show up better under UV light – can be easily removed or washed off by those tagged.

What’s also really interesting is the imagery deployed in the website. Of course there are the usual images of policemen with large guns (here complete with light source for night-time use). These guns, like tasers, have an interestingly toy-like quality to them with their bright orange plastic finish. Guns that aren’t really guns…

selectadna-high-velocity-pistol-400

However what’s more interesting are the background images used on the site. The targets of the tagging system are clearly depicted in one background image and will be recognisable to all British readers – ‘hoodies’ – the marginalized urban youth who were implicated in the rioting in London in 2011 (although there is also an inevitable pop culture association, especially with all that light-saber-y UV around, with the evil Sith from the Star Wars franchise).

slider2

The youths are depicted encircled in lines of UV-like light whose coils also reflect the image of DNA, which is used here as another background image.

slider

The late Dorothy Nelkin and M. Susan Lindee described DNA as a ‘cultural icon‘, and indeed, the never-really-explained ‘artificial DNA’ technology which underpins Selectamark’s product seems deliberate discursively confused with exisiting DNA identification technologies, or at least the association is clear: that DNA fingerprinting, which is already understood in media discouse as standing for absolute certainty as to identification, is ‘the same’ as this technology. And clearly this sounds better than associating it, as I did earlier, with tattooing – which has a much less wholesome image when it comes to the state’s usage (Nazi death camps etc.).

And then the lines of light that surround the youth also seem to beam out across and enclose the entire world, which is both a standard marketing trope (“we are a global company”) but also a shift in scale that reflects the way in which security and surveillance has moved, to encompass the globe. The world is also depicted as dark with the suggestion of a coming sunrise (fitting in with the overall ‘crime lurks in the darkness and Selectamark will shine a (UV) light in it” theme) and almost entirely urban:

slider3

But then what is the value in this global world, which Selectamark (and the police) are seeking to protect? What is the source of the light? Well, the answer, in the final background image, will surprise no-one. It isn’t those who need justice, the poor, the downtrodden, the huddled masses, it’s big companies:

slider4

The corporate sector is depicted as icons streaming information-superhighway style from the light along grid patterns: rational, clean and bright and filling, overcoming, the darkness beyond, in a corporate version of the creation story in the Book of Genesis. We are saved! Thank-you, Selectamark and your High Velocity DNA Tagging!

Make like a Dandy Highwayman to beat Face Recognition Software

Spoofing biometrics has become a mini-industry, as one would expect as the technologies of recognition become more pervasive. And not all of these methods are high-tech. Tsutomu Matsumoto’s low tech ‘gummy fingerprint‘ approach to beating fingerprint recognition is already quite well-known, for example. I’ve also seen him demonstrate very effective iris scan spoofing using cardboard irises.

Facial recognition would seem the most obvious target for such spoofing given that it is likely to be the system most used in public or other open spaces. And one of the most ingenious systems I have seen recently involves a few very simple tips. Inspired by the increasing hostility of legal systems to masks and head coverings, CV Dazzle claims to be an ‘open-source’ camouflage system for defeating computer vision.

Among the interesting findings of the project, which started as part of the Interactive Telecommunications Program at NYU, is that the more complex and high-fashion disguise-type attempts to beat facial recognition did not work as well as the simpler flat camouflage approaches. The solution suggested thus involves many of the same principles as earlier forms of camouflage: breaking up surface patterns and disguising surface topography. It uses startling make-up techniques which look a bit like 80s New Romantic face painting as deployed by Adam and the Ants – hence the title of this post! The system concentrates especially on key areas of the face which are essential to most facial recognition software systems such as the area around the bridge of the nose, cheekbones and eye socket depth.

Results from the CV Dazzle project

So, will we see a revival of the Dandy Highwayman look as a strategy of counter-surveillance? Or more likely, will social embarrassment and the desire to seem ‘normal’ mean that video surveillance operators have a relatively easy life?

Adam Ant in the early 80s

Biometrics in Afghanistan

There’s a very interesting video-report from Sebastian Meyer here on the US military use of biometrics in Afghanistan to try to identify Taliban in what he calls ‘frontline anthropology’. Wired revealed last month that the NATO / US army operation is planned to be expanded into a nationwide biometric ID card scheme by next May. Wired says that there are only two biometric systems operating in Afghanistan but they don’t seem to have noticed that the UNHCR mission in the country is also using biometrics to identify returnees who  have already claimed the financial assistance on offer and are making fraudulent claims, in conjunction with the Afghan government. Are these systems all connected? More investigation is needed…

City of Leon to install mass public iris-scanning

The City of Leon in Mexico, if a report in Fast Company are to be believed, is going ahead with a scheme that goes far further than any other urban surveillance project yet in existence. They are already installing scanners that according to their manufacturers, Global Rainmakers Inc., an until recently secretive company with ties to US military operations, can read the irises of up to 50 people per minute.

Now, we have to be careful here. Gizmondo, as usual has gone way over the top with reports of ‘the end of privacy’ (which, if you believed their stories has already happened as many times as the apocalypse for 7th Day Adventists…) and talk of the ‘entire city’ being covered and ‘real-world’ operations (i.e. in uncontrolled settings). In fact, if you read the  Fast Company report, and indeed the actual description of the products from the company, they are far more limited even in their claims (which are likely to be exaggerated anyway). There is no indication that the iris scanners proposed will work in uncontrolled settings. When the company talk about the scanners working ‘on the fly’, they mean that they will work when someone is basically looking at the scanner or near enough whilst no more than 2 metres away (in the most advanced and expensive model and significantly less for most of them) and moving at no more than 1.5 metres per second (and, again, slower for the lower range devices). All the examples on the company website show ‘pinch points’ being used (walls, fences, gates etc.) to channel those being identified towards the scanner. In other words, they would not necessarily work in wide public streets or squares anyway and certainly not when people were moving freely.

So is this what is being proposed? Well, there are two phases of the partnership with Leon that the company has announced – and we have as yet no word from Leon itself on this. Phase I will cover the settings in which one might expect levels of access control to be high: prisons, police stations etc. Phase II will supposedly cover “mass transit, medical centers and banks, among other [unnammed] public and private locations”. It is also worth noting that the scheme’s enrolment is limited to convicted criminals, with all other enrolment on an entirely voluntary basis.

I am not saying that this is not highly concerning – it is. But we need to be careful of all kinds of things here. First of all, the Fast Company report is pure corporate PR, and the dreams of the CEO of Rainmakers, Jeff Carter (basically, world domination and ‘the end of fraud’ – ha ha ha, as if…) are the same kind of macho bulltoffee that one would expect from any thrusting executive in a newish company in a highly competitive marketplace. Secondly, there’s a whole lot of space here for both technological failure and resistance. The current government Leon may well find that the adverse publicity from this will lose rather than gain them votes and that in itself could see the end of the scheme, or its being limited to Phase I. In addition, without this being part of wider national networks, there may in the end be little real incentive for anyone to enrol voluntarily in this. Why would banks in Leon require this form of identification but not those in Mexico City or Toluca for example? Will the city authorities force everyone who use public transport to undergo an iris scan (which would make the ‘voluntary’ enrolment a sham)? This could all end being as insignificant as the Mexican companies offering RFID implants as a supposed antidote to kidnapping, it could be the start of a seismic shift in the nature of urban space, or it could be a messy mixture.

I hope my colleagues in Mexico are paying attention though – and I will try to keep updated on what’s really going on beyond the corporate PR.

India’s Biometric Census

A while back I was wondering how India was going to enrol 1.2 Billion people in its planned national Biometric ID card scheme. Well, I should have guessed that the answer was that it would combine it with a national census. This is apparently exactly what is going to happen, according to the BBC. The next Indian national census will be the first one not just to count and classify individuals with written answers, but will also take biometric details. These will then form the basis for the new ID database, with its 16-digit unique identifying number. And the process has already started – the only thing I can think of that will cause it significant problems is not any civil liberties opposition but rather the ongoing revolutionary movements often called ‘Maoist’ but really a lot of different loosely affiliated rural-based organisations…

UK Parliamentary Committee rejects Government DNA proposals

The House of Commons Home Affairs Select Committee has rejected a key part of the UK government’s new plans for the National DNA Database (NDNAD). The plans came in response to the ruling by the European Court that the NDNAD was being operated contrary to human rights law by keeping the profiles of innocent people indefinitely. The database has been filled largely through the provisions of a very vague and wide-ranging provision that allowed the police to take DNA from anyone arrested for an indictable offence, and to keep it even if they were never even charged (let alone charged and not convicted). The result had been that long-standing prejudices within the police had meant a bias in the databases against young black men, and a rapidly expanding set of profiles of children and the entirely innocent.The NDNAD had also been attacked by the HUman Genetics Commission (the government’s own watchdog) which recommended multiple reforms.

One of the main parts of the government’s response to the European Court ruling was that DNA should be retained for 6 years – the committee has recommended that this be halved to 3 years (we are still talking about the DNA of innocent people here…), and that there should be some proper national system for deciding who gets deleted entirely (at the moment it is at the discretion of Chief Constables of local police forces!). Of course all of these leaves the wider question of fairness and rights undebated. There are only two properly just ways to run a database of this sort. One would be to include only the DNA of those convicted of a crime or suspected in an ongoing investigation. The other would be to include everyone (as the UAE has decided to do). At the moment, the NDNAD is, like most things in Britain, an unaccountable mess of law, customary practice and happenstance that pleases no-one and is also remarkably ineffective for the money and effort put into it. This will only improve slightly even if the select committee’s recommendations are accepted.

Do we need to be concerned about a new iPhone face-recognition app?

The Huffington Post has got itself in a twist about a new iPhone face-recognition app, Recognizr, that it claims will enable someone to take a person’s picture and instantly give them access to all their social networking details. Except that isn’t quite the case. As one (largely ignored) commenter points out, it’s not quite as the HP portrays it. It isn’t an open system – the original story (linked in the HP one) says that you have to opt in to the system, and upload your photo, and other social networking sites you want to be linked, into the developer’s own database. So only those who have decided they want to be part of this system can be recognised and linked. It’s only a rather small step from existing methods of social networking, and perhaps considered as the face recognition equivalent of giving out a business card. There’s the potential there for all kinds of development from this though, I would agree, but this isn’t (yet) a stalker’s or a marketer’s dream.

You can find the Swedish developer, The Astonishing Tribe (err, TAT!), here, and the source story, which is just slightly more circumspect, from Popular Science, here.

(Thanks to David Lyon for the link to the HP story).

After the Thighbomber: Virtual Strip Searches at every airport?

The botched attempt to bomb a flight into the US by a the son of a wealthy Nigerian family, using explosive components strapped to his thigh, has led to an immediate techno-economic consequence, which is to speed up the process of installing terahertz wave or other body scanners in major airports, which if nothing else will provide a guaranteed income stream to Rapiscan and Qinetiq, who make these kinds of machines. Schipol in Amsterdam, where  announced they would be extending their body scanning operation and the British government almost immediately followed by saying that major British airports would be rolling out body scanning within weeks. Now, Canada is to do the same.

But, will this make a real difference or is it just more symbolic security? The scanners certainly ‘work’ in the sense that they do provide pretty good images of what is under the clothes of passengers (see below). However, interpreting what is seen is still no easy task and will the scanners will certainly not replace physical searches, but will add yet another extra layer of surveillant sorting and therefore delay. And there are questions over the effectiveness of the scanners in particular areas of the body. The Toronto Sun reports that trials at Kelowna Airport in British Columbia “left blind spots over the head and feet”, so these machines are certainly not the ‘silver bullet’.

Then of course, there are the privacy issues. I don’t have any particular problem with the technology, provided it is restricted to airports and doesn’t start to get used in other, more everyday, social settings (which given the rapid development of this technology is by no means certain). However, as I noted the last time I wrote about this, there will be many religious, gender-based and personal reasons for objecting to their use. The other question of course is whether, every time some lone lunatic tries something like this – that was, let us not forget, poorly planned and ineffective, and which should have been prevented by other conventional intelligence operations working properly – it makes sense to jump and harden security (or at least be seen to harden security) for everyone travelling internationally. Doing this just plays into the hands of terrorists as it disrupts the ordinary workings of an open society.

Body Scan Image (US TSA)