Why Facebook Shutting Down Its Old Facial Recognition System Doesnt Matter
On Monday morning, Meta â" the company formerly known as Facebook â" announced that it would be shutting down âthe Face Recognition system on Facebook,â a technology that has been raising privacy alarms since it debuted. In a blog post, the company described the move as âone of the biggest shifts in facial recognition usage in the technologyâs history.â On Twitter, outgoing CTO Mike Schroepfer and incoming CTO Andrew Bosworth, who previously oversaw Facebookâs Oculus virtual reality division, called the announcement a âbig dealâ and a âvery important decision.â The Electronic Frontier Foundation deemed it âa testament to all the hard work activists have done to push back against this invasive technology.â
But a review of Meta and Facebookâs VR privacy policies, and the companyâs answers to a detailed list of questions about them, suggest the companyâs face identification technology isnât going anywhere. And it is only one of many invasive data collection methods that may be coming to a metaverse near you. (Disclosure: In a previous life, I held policy positions at Facebook and Spotify.)
Facebook's recent announcement that it is shutting off its controversial facial recognition system comes at a difficult time for the company, which is facing significant regulatory scrutiny after years of bad press recently inflamed by a high-profile whistleblower.
But the moment may also be an opportune one. The company is shifting its focus to virtual reality, a face-worn technology that, by necessity, collects an enormous amount of data about its users. From this data, Meta will have the capacity to create identification and surveillance systems that are at least as powerful as the system itâs putting out to pasture. Just because it can create those systems doesnât mean it will. For the moment, though, the company is leaving its options open.
The fact is: Meta intends to collect unique, identifying information about its usersâ faces. Last week, Facebook founder Mark Zuckerberg told Stratecheryâs Ben Thompson that âone of the big new featuresâ of Metaâs new Cambria headset âis around eye-tracking and face-tracking.â And while the platform has âturned off the serviceâ that previously created facial profiles of Facebook users, the New York Times reported that the company is keeping the algorithm on which that service relied. A Meta spokesperson declined to answer questions from BuzzFeed News about how that algorithm remains in use today.
Meta may have shut down the facial recognition system on Facebook that raised so many concerns, but given that it intends to keep the algorithm that powered that system, there is no reason the company couldnât âsimply turn it on again later,â according to David Brody, senior counsel at the Lawyersâ Committee for Civil Rights Under Law.
Meanwhile, Metaâs current privacy policies for VR devices leave plenty of room for the collection of personal, biological data that reaches beyond a userâs face. As Katitza Rodriguez, policy director for global privacy at the Electronic Frontier Foundation, noted, the language is âbroad enough to encompass a wide range of potential data streams â" which, even if not being collected today, could start being collected tomorrow without necessarily notifying users, securing additional consent, or amending the policy.â
By necessity, virtual reality hardware collects fundamentally different data about its users than social media platforms do. VR headsets can be taught to recognize a userâs voice, their veins, or the shading of their iris, or to capture metrics like heart rate, breath rate, and what causes their pupils to dilate. Facebook has filed patents concerning many of these data collection types, including one that would use things like your face, voice, or even your DNA to lock and unlock devices. Another would consider a userâs âweight, force, pressure, heart rate, pressure rate, or EEG dataâ to create a VR avatar. Patents are often aspirational â" covering potential use cases that never arise â" but they can sometimes offer insight into a companyâs future plans.
Metaâs current VR privacy policies do not specify all the types of data it collects about its users. The Oculus Privacy Settings, Oculus Privacy Policy, and Supplemental Oculus Data Policy, which govern Metaâs current virtual reality offerings, provide some information about the broad categories of data that Oculus devices collect. But they all specify that their data fields (things like âthe position of your headset, the speed of your controller and changes in your orientation like when you move your headâ) are just examples within those categories, rather than a full enumeration of their contents.
The examples given also do not convey the breadth of the categories theyâre meant to represent. For example, the Oculus Privacy Policy states that Meta collects âinformation about your environment, physical movements, and dimensions when you use an XR device.â It then provides two examples of such collection: information about your VR play area and âtechnical information like your estimated hand size and hand movement.â
But âinformation about your environment, physical movements, and dimensionsâ could describe data points far beyond estimated hand size and game boundary â" it also could include involuntary reaction metrics, like a flinch, or uniquely identifying movements, like a smile.
Meta twice declined to detail the types of data that its devices collect today and the types of data that it plans to collect in the future. It also declined to say whether it is currently collecting, or plans to collect, biometric information such as heart rate, breath rate, pupil dilation, iris recognition, voice identification, vein recognition, facial movements, or facial recognition. Instead, it pointed to the policies linked above, adding that âOculus VR headsets currently do not process biometric data as defined under applicable law.â A company spokesperson declined to specify which laws Meta considers applicable. However, some 24 hours after publication of this story, the company told us that it does not âcurrentlyâ collect the types of data detailed above, nor does it âcurrentlyâ use facial recognition in its VR devices.
Meta did, however, offer additional information about how it uses personal data in advertising. The Supplemental Oculus Terms of Service say that Meta may use information about âactions [users] have taken in Oculus products'' to serve them ads and sponsored content. Depending on how Oculus defines âaction,â this language could allow it to target ads based on what makes us jump from fear, or makes our hearts flutter, or our hands sweaty.
But at least for the moment, Meta wonât be targeting ads that way. Instead, a spokesperson told BuzzFeed News that the company is using a narrower definition of âactionsâ â" one that does not include the movement data collected by a userâs VR device.
In a 2020 document called "Responsible Innovation Principles," Facebook Reality Labs describes its approach to the metaverse. The first of these principles, âNever Surprise People,â begins: âWe are transparent about how our products work and the data they collect.â Responding to questions from BuzzFeed News, Meta said it will be upfront about any future changes, should they arise, to how it will collect and use our data.
Without better clarity about the data that Meta is collecting today, âcustomers cannot make an informed choice about when and how to use their products,â Brody told BuzzFeed News. More to the point, it's hard for the public to understand any future changes Meta might make to how it collects and uses our data if it's never explained exactly what itâs doing now.
Brittan Heller, counsel at the law firm Foley Hoag and an expert in human rights and virtual reality, put it differently: "The VR industry is kind of in a 'magic eight ball' phase right now. On questions about privacy and safety, the answer that flutters up says, 'Outlook uncertain: ask again later.'"
0 Response to "Why Facebook Shutting Down Its Old Facial Recognition System Doesnt Matter"
Post a Comment