Would You Submit Biometric Data to Join a Gym?
An anonymous reader asks: "I went to my gym (Rocky River, OH branch) yesterday and there was a huge line of people at the counter. When I went to the scanner to swipe my membership card, I noticed they were training people in the use of their new security system that requires the input of your thumb print. There currently a story on boingboing that mentions a tanning salon in Arkansas that is enacting a similar policy. I'm going to call the gym later today and see what type of security they have on their network. I guess we can look forward to a future where these sorts of personal services clubs require the submission of biometric data. I was wondering how the members here at Slashdot feel about the security risks involved in submitting biometric data to small private companies?"
I work for (and attend) a State University. Our gym (in 2002) enacted similar policies and equipment. It was *optional* however, and was enacted for people who didn't want to have to carry around a membership-card or student/employee-ID just to be able to get into the gym (since most gym shorts don't have a pockets, and many people on campus just walk to/from the gym rather than driving or bringing a full bag and using a locker). It was an option for about one year, until they realized that the extreme costs of using the hardware and managing it (and its slight errors) far outweighed pleasing a minority of people who attended. It's good to see the technology developing, but I still prefer losing my identity to a bunch of little numbers on a card.
No. And if the gym the wife and I belong to switches to biometrics, I'll demand a full refund of mine and my wife's membership.
Fuck 'em. We already own a treadmill and the wife's been wanting to buy an elliptical anyway.
Slowly things like this get introduced and the stupid sheeple submit en masse. The more people that stand up and argue with the un- and under-educated about such invasiveness, the better.
Sure, these things may not be so bad yet but this may just be the tip of the iceberg. Give 'em and inch and they'll take a mile.
Once these become the norm, it'll be easier for the government and so-called private "security agencies" to strip us of our right to privacy.
Religion is for people afraid of going to hell.
Yeah... I have dermatitis, basically when my skin is exposed to soap (the skin on my hands is more susceptible to this) it starts to "peel" off and the skin does not recover for 4-6 weeks. I avoid soap as much as possible, the non soap alternatives are quite expensive however.
When I am exposed to soap it causes a lot of problems with fingerprint scanners for me. So yeah, cards are a better option for people with my condition.
Why not go for something like card + hand geometry identification if they're so concerned with people "sharing" gym memberships.
"Those who would give up Essential Liberty, to purchase a little Temporary Safety, deserve neither Liberty nor Safety"
I wouldnt be a member of that gym for much longer
I went to check out a nice large brand-new gym near my house. They handed me a form to fill out including a questionnaire and a space for my name phone number and address. I answered a few of their questions and just put my first name on the form.
They mentioned that they'd like me to fill in my phone number and address and I said, "no thank you, I'd like to check out the equipment first before signing up." They told me they couldn't show me the gym without that information. Still thinking we just had a misunderstanding I pointed out that I wasn't there to use the gym, I just wanted to see what they had to offer before signing up. They then proceeded to point out to me that they were prepared to give me a tour, but would not do so without my phone number and address.
I said, "goodbye" and walked out the door. Even my bank doesn't require biometrics and didn't ask for an address before they told me about their features. These fitness center folks are too big for their own britches. Pushups and situps are free and running shoes don't cost that much compared to a gym membership. I'd like to use the gym, but I don't have to and I certainly wont consider it untless they figure out how to be less intrusive.
TW
If anyone is collecting sensitive information from you: SSN, biometric data, etc. you need to get a data retention and privacy policy in writing.
Will they transfer this data if the company is sold or goes out of business? Remember eToys had a privacy policy that went out the window during bankrupcy. Will they destroy the data when you cancel your membership. What security mechanisms and audit procedures do they have in place?
When you bring it up it may be the first time they have thought of it so be prepared to wait.
-weld
That control is gone when the data gets stored on computers owned by various businesses.
Well, not really. It's more like a hash. Unless the people that designed the security sytem didn't have a clue, they wouldn't store reversable fingerprint information at all.
I remember having this discussion with my old boss when he wanted to go biometric a few years ago. He even got ahold of a some fingerprint readers for testing. We found that the industry, and this manufacturer, were very clear on the matter. No one wanted to actually store your fingerprints.
So, feeling confident, he installs the software, plays with it for a little bit and invites me over to try to "hack" his account with my thumb. I put my thumb on the plate and sure enough the device tells me I'm unauthorized... while displaying a giant picture of my thumb accross most of the display.
My conclusion: I believe the companies really aren't storing reversible fingerprint information. I also believe they're doing a lousy job of making people feel confident about this fact.
I think there are enough other downsides that this technology should be condered DOA for most purposes, but this particular issue is probably just a PR problem.
TW