Biometrics, Ownership and Privacy?
symbolic asks: "I just finished watching a small segment of World Business Review on PBS, where the topic of discussion the use of biometrics by employers to not only provide confirmation of identity, but as something to drive other parts of the operation - like tracking employee time. Briefly mentioned were face and iris scans, but as I was watching a picture of someone's iris, I realized that once an employer has captured a scan of your iris (or any biometric data), who has control over it? Does it become part of the cesspool of information trading that occurs between business and government entities? Will trading of someone's biometric information become as ubiquitous as their address or phone number. Is there any reason we should be concerned about this? I'd like to hear what others think about this." Ask Slashdot has previously approached the Biometrics topic for technical
issues, but the privacy issue of such data has yet to be addressed. How do you feel about biometric data (or any data derived from your physical makeup, like your genome) being used as another commodity (like your address) in the corporate data exchange?
Of course we should be concerned about this! You can change your phone number, your email address, your name, and even your social security number if you work hard enough. But you can't change your biometric data, so once it's in the wild marketplace or personal information, it's out there for good...
:wq
Coloured contact lenses.
It's not farfetched to think that some idiot in the wake of 9/11 might push a law making it illegal to wear them. Oh yeah, only after the law's been passed will things like this come to light...
Just think, a DMCA for identity-circumvention devices. No more anonymity, because, it's good for you!
... because you can't change or revoke them. What if someone manages to get a copy of the binary data that characterize your iris? What if it gets circulated in some crackers circle? Will you change your iris? Or will you change your job? Or will you simply loose your work, since your iris is now unusable by your company?
Recently I watched a presentation by a biometrics group, so this is a bit familiar to me. By far the biggest problem, the question unanswered, is what to do when your information is compromised.
See, you can change your credit card number, or your email address. You can even move someplace else. But you can't change your biometrics. Hopefully movies like Minority Report will provide some Good FUD about biometrics, so people realize that this information should be kept as private and closely-guarded as their own life.
It's funny how people seem more willing to give out their fingerprint or retina than they are a number on their credit card. It may be hard to hack. It may be very hard to hack. It may be almost impossible to use. But as those in the security business know, nothing is impossible. And with biometrics, once you're compromised, that's it.
Don't think of it as a flame---it's more like an argument that does 3d6 fire damage
I haven't had any problems with ethical/nonethical use of my information yet.
The key word here is yet. If a biometric national ID card comes into common use, you can bet that there are any number of corporations and script-kiddies who will find a way to use this information in a non-ethical way.
Think For Yourself. Question Authority.
The bottom line is this - making such divulgence of personal information compulsory. If it was voluntary that would be one thing, but each day we have to sacrifice more and more of our privacy and liberties in order to hold a job, make a living and not starve. I'm sorry but no one ever should be forced to obey a large system of rules and regulations just to stay alive - but thats how it is - and it tyranny pure and simple.
www.enthea.org
The only problem I can see here is that you would have to get Company X to agree to sign the NDA. Most people only give fingerprints/eye scans/whatever when Company X has something they want; for example, my thumbprint whenever I want to cash a check. I don't just run around getting retina-scanned and fingerprinted because I like it... there's something I want, and relinquishing a part of myself that can be sold (or worse, stolen) is a necessary evil that I bitch about whenever I get the chance.
So, what's to keep a bank from denying your application for a bank card when you present them an NDA? Or what's to keep your company from firing you or limiting your security clearance because they want nothing to do with your silly legal agreement? I know if I presented any papers to the bank when I tried to cash a check, they would simply say, "I'm sorry, we can't sign this." And I would not have any money.
Much like software license agreements - I think most people would be surprised to read the rights and priviledges they sign away when they click "I agree," but for the vast majority of people, it's just one more button to click before you get your free e-mail account or install your shiny new software. And the rules are such that unless you agree to THEIR rules, you're SOL.
Rather than worry about their legal liability when they sell your eyeprint, I suspect most companies would just refuse to do business with you, especially when there is a veritable plethora of customers who don't know or care enough to defend themselves in that way. Maybe the rules are different; if not, they really should be.