• Skip to primary navigation
  • Skip to main content
Identity Woman

Identity Woman

Independent Advocate for the Rights and Dignity of our Digital Selves

  • About
  • IETF Research
  • She’s Geeky: AI Edition
  • Weekly SSI Newsletter
  • Blog
  • Media Coverage
  • Contact
  • Show Search
Hide Search

Archives for March 2023

Industry orgs “warn” states against BIPA style laws. Why not have a dialogue at Thoughtful Biometrics Workshop – March 16th

Kaliya Young · March 10, 2023 ·

People and their representatives are rightly concerned about how biometric systems are used. This week while reading all the industry news I came across this article – CCIA Testifies On Maryland Biometric Privacy Proposal, Submits Written Comments On Biometric, Childrens, And Health Privacy Bills.

So what is BIPA? It is the Biometric Information Privacy Act that Illinois passed several years ago requiring any capturing of a biometric information in a template and in samples must get the subjects explicit consent. If companies don’t they face really large fines. White Castle just might have a $17billion dollar fine for violations over 10 years.

Industry associations like the Computer & Communications Industry Association are pushing back against these measures. This is their job to lobby on behalf of their members. Here is what they said.

The following can be attributed to CCIA State Policy Director Khara Boender:

“We share Maryland legislators’ concern about protecting biometric privacy and request that measures to address this important issue provide enough lead time for responsible sites to comply. We also recommend directing protections toward high-risk practices and aligning key definitions with privacy standards to encourage harmonization across state laws and aid compliance.”

“Privacy is particularly important for health data and for children online. While CCIA supports privacy measures tailored to specific age groups and the handling of more sensitive health data, the bills legislators are considering should prioritize ways to enable responsible companies to provide effective protections  rather than introducing punitive models with private rights of action that, in other states, have opened the floodgates to costly lawsuits.”

– CCIA Blog

I am hoping that organizations like CCIA can actually come to the Thoughtful Biometrics Workshop on March 16th and talk together with folks who are concerned about biometrics usage by the private sector and by government.

Biometrics =/= Digital ID

Kaliya Young · March 10, 2023 ·

I have been engaging with folks who work developing biometric systems and folks who are concerned about biometric systems for in preparation for the Thoughtful Biometrics Workshop coming up March 16th.

Two weeks ago I attended Biometrics Regulation: Global State-of-Play Symposium (one to many talking on zoom with no chat function) put on by the Berkeley Center for Longterm Cybersecurity.

The aim of the virtual symposium is to discuss the global state-of-play for biometric data protection. We want to think more critically about biometric technologies as well as biometric regulation. As a result, we want to merge conversations on data protection compliance with broader technological, social and policy issues in different biometric technologies.

– Workshop Description Biometrics Regulation: Global State of Play Symposium

The presentations were interesting and it was great to have folks from all around the world present. India’s Aadhaar system was discussed and a newer system that has similar qualities was just rolled out in Brazil.

However something very concerning – throughout the discussion there was repeated conflation of biometrics with digital ID. This conflation is a problem to have the type of real discussion we need to have about both but to not conflate them.

I think the conflation comes from the builders of certain systems like Aadhaar and MOSIP along with those promoting these systems like the World Bank and Omidyar.

I’ve been working on “Digital Identity” since 2002-3 and the folks that inspired me to look at this issue were really considering how independent people expressed themselves in the digital world with their handles or avatars. This really began with the general public with the first internet services in the west like AOL, Compuserve and Prodigy. When you signed up to these services you picked a handle/user-name or maybe a few and that likely connected to an e-mail account. This user-name and the email associated with it are “digital identities”. Your twitter handle is a digital identity. Your Gmail account or Yahoo account is a digital identity.

In the last 10 years you have these large scale national ID (Aadhaar) systems being developed (MOSIP) and pushed out to whole populations that in order to get a “record in the digital database” as a citizen you have to go through an erollment and registration system that requires you to share your biometrics – often a photo, iris scans of your two eyes and capturing of all 10 finger prints. Then this national system deduplicates you – makes sure you didn’t already enroll and then issues you a ID number that is in the digital database of the nation state.

– How Aadhaar is Giving an Identity to 1.3 Billion Citizens?

Then these national ID systems then create ways to “authenticate” against the database – prove that the person is represented by a given number/record in a database.

– How Aadhaar is Giving an Identity to 1.3 Billion Citizens?

This is a very different architecture/design of digital identity than people have accounts in digital services. These two very different paradigms of what “digital identity” is – is part of the massive confusion around the language we are using.

There is a new paradigms around digital identity that involve collecting and sharing attributes from authoritative sources in the form of Verifiable Credentials is yet another type of decentralized digital identity that I spend a lot of time these days working on and convening people working on it at the Internet Identity Workshop.

Several years ago I co-wrote a paper about how biometrics could play nice with this new decentralized digital identity called Six Principles for Self-Sovereign Biometrics. If you look at what US Citizenship and Immigration is doing with their roll out of digital green cards using the verifiable credential technology on the digital green card holder’s wallet will have a photo encoded that when presented can be checked against the presenter’s face in real life. This aligns with what we outline. There is no “phone home” to the USCIS database to pull the photo and then compare – the needed biometric a photo is digitally signed and in a credential that can be compared with the presenter.

Federal Agencies using Facial Recognition Technology: GAO report from 2021

Kaliya Young · March 10, 2023 ·

I just learned about a 2021 GAO report. It says that This means it is likely that more agencies are using FRT for more reasons. This report seems relevant because for the third time legislation is being put forward to do a Federal Facial Recognition Ban just this week.

The diagrams within the report do a good job of articulating clearly and simply different use-cases and how the systems work. I think they are great points of reference for us to use next week at the Thoughtful Biometrics Workshop on March 16th.

This set of diagrams articulates a whole range of uses by federal agencies.

– GAO report: Facial Recognition Technology: Current and Planned Uses by Federal Agencies

This diagram really stood out for me because they are clear that there is a difference between Matching or what they call Verification or Identification. This different is really key and today there are proposals coming out from congress about banning FRT broadly.

– GAO report: Facial Recognition Technology: Current and Planned Uses by Federal Agencies

This type of broad ban would limit the ability of agencies to use computer vision to match people to their documents – a technology that is widely used at boarder crossing in the US now and TSA has begun experimenting with at check points.

It would also limit the use of Biometrics as part of Biometric Exit I wrote about last week that compares passengers boarding flights leaving the US complied with access to galleries of photos of passengers drawn from DHS records (from entrance photos, document photos and passport records).

The GAO report includes a table breaking down the number of facial recognition systems owned by each agency:

  • Commerce Department: one system, used for physical security.
  • Defense Department: seven systems, used for physical security, domestic law enforcement, national security and defense, and other purposes.
  • Energy Department: one system, used for physical security.
  • Health and Human Services Department: three systems, used for physical security, domestic law enforcement and digital access/cybersecurity.
  • Homeland Security Department: four systems, used for domestic law enforcement, border and transportation security, and national security and defense.
  • Justice Department: seven systems, used for physical security, domestic law enforcement, national security and defense, and other purposes.
  • State Department: one system, used for border and transportation security, and national security and defense.
  • General Services Administration: one system, used for digital access/cybersecurity.
  • NASA: one system, used for “other” purposes, including employee identification if they forgot their badges.

I recommend scanning through the report to see the range of use-cases. I think it can be useful in having a nuanced conversation about use-cases/applications that make sense and ones that could be harmful and really impact civil liberties.

     Copyright © 2026 Identity Woman  evelurie.com/web design/develop     

  • Terms of Use
  • Privacy Policy
  • Accessibility
  • Sitemap
  • Contact