Biometrics in Airports
asv108 writes: "Extremetech has an article by renowned security expert Bruce Schneier about why face recognition in public places such as airports is not a good idea." Schneier is being generous - real world results show that facial recognition systems are a lot less than 99.99% accurate even under laboratory conditions (people posing for the camera under ideal lighting).
Any terrorist prepared to commit suicide is going to think nothing of having reconstructive surgery if that's what it takes to foil such a system.
Biometrics are much easier to implement when the person's alledged identity is known. If the person claims to be X, the system need only compute B(X) and compare that to a precomputed data base entry B'(X). These values will almost never be identical due to noisy real world systems (different lighting, microphone noise, dirt on the fingerprint/retina scanner, etc.). Instead a statistical comparison must be made. If B(X) is statistically similar to B'(X), admit entry, otherwise call the firing squad.
In the article, Bruce assumes his readers understand this. His explanation of why face recognition systems cannot find the rare targets in large populations is quite good. The same logic applies to voice matching for projects like Eschelon.
And, of course, this wouldn't prevent individuals from using their own valid IDs to access public areas. The assumption of most security systems is that the intruder wants to commit a crime and get out while minimizing the probability of detection. A suicidal terrorist does not have this goal. He/she seeks to enter an area, commit a crime, and then die in the attempt. The tools developed for normal security may not be appropriate for suicidal terrorists or individuals on shooting sprees.
Given one hour to live, the student replied: "I'd spend it with professor FP who can make an hour seem like a lifetime."
The fact that only a few people will be inconvenienced isn't the real problem. The problem is that the users of the system will mistrust it.
If only one in 10000 positives is really a terrorist, then most airport security personnel will never see one. They'll stop and inspect a few people each day, and in every case, they will be false positives. That will lead to a tremendous mistrust of the system.
Imagine if you were running airport security, and every day the computer told you that you should detain someone because they looked like a terrorist, and in every case it turned out to be false. You'd feel like a fool.
It would be just like having false fire alarms a couple of times a day, every day. You wouldn't evacuate every time, would you?
In the same way, the airport security people would stop responding as diligently after months of false alarms. Then the system wouldn't work.
A system that people don't trust isn't worth having. It's just a waste of time and money.
Wouldn't it make more sense and be much easier to simply link the FBI "watch list" to the airlines computers? Many of the hijackers were on this list. It seems incredible to me that a person on the list could buy a one-way ticket with cash without the system bringing up all sorts of warnings. Some of the hijackers (not all) fall into this category.
The following things should cause there to be extra scrutiny (especially if you do/are more than one of them):
It seems that doing a lookup on a name in a database is much quicker/easier/less expensive than installing facial recognition systems all over the place. Why not implement a simple solution that would have caught these guys first instead of a complex on that might not work?
If you feel that we must use high-tech solutions, maybe a smart card put into passports and driver's licenses would make more sense and be more accurate. Once simple solutions are implemented then we can worry about the crazy complex ones.
Lasers Controlled Games!
I understand your frustration with people who aren't open to ideas without having any to replace them. However, I'm going to do just that. The converse of that idea is that we just do anything regardless of whether it helps or not.
I'm terrified by the reaction of this country far more than terrorists. I'm wondering what "terrorist" means. The wierd totalitarian things that have happened here have fueled my paranoia. The White House issuing a statement telling people they have to "watch what they say" has me wondering if "terrorist" might mean anyone who dares dissent.
I'd rather let things cool down for awhile. The way terrorist cells operate is that after an action everybody flees and goes back into cover. We have awhile to think about this. I think it would be a very good thing to let these decisions come at a more cool headed time.
But then - the best biometric system in the world wouldn't have stopped the WTC attack - the hijackers were passengers with tickets and many used their real names anyway so
You do know that the FBI was busy looking for several of the terrorists even as the planes hit the WTC, right? They got into the country and disappeared- a face check at the gate might have flagged them and possibly prevented the attacks. The terrorists would have at least been delayed enough to stop some of the attacks.
You're right: biometrics is coming. This could be a very good thing if we drive the technology to good use. Fingerprint check when I use a credit card: why not? I'd love it if the store *knew* I was the owner of that card- I've had my number stolen before. Ever spoken with someone who's had their identity stolen? It's a multi-year nightmare of wrecked credit, endless phone calls and general heartburn.
Realize that we have almost no privacy anyway. Various large companies know a *lot* about me. They know personal details down to my last dollar, my taste for mint chip ice cream and the fact my wife and I are infertile. The government has run at least 3 background checks on me that I know of, the most recent within the last month. (I got my pilot's license recently: the FBI has already visited the airports I used to pull my records.)
Biometrics won't change that-what we need to do is make sure the transparancy goes both ways.
Eric
"Seven Deadly Sins? I thought it was a to-do list!"
I think alot of people are missing the point here. This system is supposed to 'stop terrorists by identifying potential terrorists'. The only way to catch a potential terrorist is if that individual has been caught or spotted and had his/her picture taken to compare. Of the 19 suspected terrorist that commited the Sept. 11 attacks only TWO of them had any kind of profile the rest were unknowns. So, someone please explain to me how exactly biometrics would have helped us here. Sure 2 of the terrorists would have potentialy been stoped, but the other 17 terrorists would have boarded the plane without much of a problem. Im sure biometrics might stop things for a small amount of time, but the terrorists will adapt quickly and all we are left with is a billion dollar step twords big brother is watching. There are sleeper agents all over the world, guys who have never been seen talking to a known terrorist, have been living in thier respective country for 5-10-15 years, have wives, kids, successfull careers, just waiting for thier 'phone call'. How exactly is a biometrics system going to solve that problem?
Which leads to a good point. How "suspect" do I have to be before you restrict my ability to move around and basically live a normal life?
If you stick to putting only known foreign terrorists in the database, fair enough. If you put known escaped US felons and bail jumpers in as well, again fair enough.
But the September the 11th terrorists were only suspects; we knew they were here, but they were here legally and openly, so we had nothing to charge them with. These are the people we want to stop, so we have to put them in and, what? Stop them flying? Search and question them? OK, lives are at stake, let's do that. it sucks, but it's necessary.
So, what's the criteria for putting a US citizen in? You don't have enough evidence to charge me. Am I an acknowledged activist, spouting anti-American slogans and calling for the end of US involvement in the Holy Land (pesky old 1st Amendment)? Or do I just have an uncle in Afghanistan who likes to send me encrypted mail? What are the criteria?
Do you stop me flying altogether, or do you just search me every time? If I'm not trusted on a plane, am I trusted with a gun? With access to explosives, or the materials to make them? Do you stop me using encryption? Or do you just watch me closely? Do I even know that I'm in the database at effectively wearing a big "suspicious" label because of my ethnicity, religion, family or political leanings?
I'm not against this technology (assuming we can get it to work), but I am very concerned that there be a clear, open procedure for who goes in the database. Specifically, I want to know:
If you were blocking sigs, you wouldn't have to read this.
And that, people, is why systems like this don't work.
By that logic, metal detectors are a lousy system. Anecdotally, at least 50% of the passengers trip off the metal detector. Note that it's not there to detect metal, but weapons. If 1 in 1000 people are carrying weapons, then the metal detectors are giving 500 false positives per 1000 people.
That, is of course, why the metal detector isn't a system. It is a part of the system; security officers and protocols are the remainder of the system. As such, tripping off the metal detector isn't a huge deal, but it does require further securing you (emptying pockets, etc.) until you no longer trip it.
Similarly, facial recognition software is a bad system when used alone. When used in conjunction with a security officer, it can be damned effective. I suggest in another post that the software's response to finding a match is showing the security officers the snapshot it matched to. Let the officer quickly check the real person against a mug shot, and most false positives won't even be noticed by the passenger falsely matched. Those who are incorrectly detained are detained because an officer thinks you look like a particular mug shot, regardless of what the machine says. As a society, we regard that as an acceptable risk, otherwise we wouldn't post faces in post offices.
It's not the technology, it's the way that you use it.
--The basis of all love is respect