Vinson·Li

Essay No. 69

Clearview scraped three billion faces. This is why we built on-device

The New York Times revealed a startup that matches any photo against billions of faces scraped from social media, and sells it to police. The worst version of my industry is now public.


On Saturday the New York Times published Kashmir Hill’s story on Clearview AI. It’s a small startup that scraped more than three billion photos from Facebook, YouTube, Venmo and millions of other sites, built a face search engine on top of them, and sold access to more than 600 law enforcement agencies. Take a photo of a stranger, upload it, and get back other photos of that person along with links to where they appeared. According to the story, the code includes the ability to pair it with augmented reality glasses, which would let the wearer identify anyone they look at.

I’ve written here several times about where I think the line is for face recognition: consent, a limited set of people to match against, benefit to the person being recognized, and an easy alternative. Clearview is on the far side of every one of those. No one in the database agreed to it. The set is everyone who has ever posted a photo online. The benefit goes to whoever is doing the searching. And there’s no way to opt out of a database you don’t know exists.

Technically, none of this is hard anymore. That’s the part that worries me most. Face embedding models that turn a face into a vector are widely available and good. Nearest-neighbor search over billions of vectors is a solved engineering problem. The scraping is the only real work, and it’s the kind of work that big platforms tell you not to do in their terms of service and mostly can’t stop. Several people have told me over the years that someone was going to build this. The big companies apparently chose not to. A small company with no reputation to protect did it.

When we started Amanda two years ago, we chose to run matching on the device, against a small list of people who had opted in for one event. We sometimes had to explain to investors why we were making our own lives harder. This is why. Architecture decides what a system can be used for. A system that has a central database of everyone’s faces can be turned into Clearview with a policy change. A system that only ever holds the faces of a few thousand consenting attendees, locally, for a few days, cannot.

I expect this story to lead to lawsuits, especially under Illinois’s biometric privacy law, cease-and-desist letters from the platforms that were scraped, and pressure on the police departments using it. I’d also expect it to make my job harder for a while, because a lot of people will reasonably hear “face recognition” and think of this. That’s fair. The industry earned it. I’d rather be judged on how we build than on the category name, but I understand why people won’t make that distinction right now.

Fin.

Add a comment

Comments

Plain text

  • Loading comments…