How to Implement Biometric Technology Safely

4.3K views
•
February 27, 2020
by
RSAC Cybersecurity
YouTube video player
How to Implement Biometric Technology Safely

TL;DR

Biometric technology should be implemented with clear user information, appropriate consent, and safeguards for collected data. Although biometrics can strengthen authentication, detect fraud, track attendance, and support transportation systems, organizations must assess whether facial templates, fingerprints, sensor patterns, or other characteristics identify individuals and therefore trigger privacy, security, and legal obligations.

Transcript

Okay. Good afternoon, and, uh, welcome to the session of Biometric Data: Power, Promise, and Privacy Challenges. Uh, let me introduce the presenters for today's session. Natalia Belaya, director of security compliance, uh, at, uh, Autodesk. Brett Cohen, partner, privacy and cybersecurity practice, uh, at, uh, Hogan Lovells. And, uh, Alexandra Ross,... Read More

Key Insights

  • Biometric information is data collected about characteristics that are unique to an individual or used to identify that individual. State laws may define it differently, so organizations must determine whether a planned system falls within each applicable legal definition.
  • A photograph is not necessarily biometric information under the Illinois definition discussed in the session. It may become biometric information when a system extracts a facial template from the image and uses that template to recognize or identify a person.
  • Biometric technology is used for security, safety, authentication, financial fraud detection, airport and customs processing, employee attendance tracking, transportation, and smart-city applications. These benefits should be evaluated alongside the privacy and security risks created by collecting distinctive personal characteristics.
  • Modern biometric identifiers extend beyond fingerprints, faces, irises, and voices. Heartbeat patterns, gait, vein patterns, accelerometer readings, and other sensor-derived behavioral patterns may qualify when they track personal characteristics or are used to identify someone uniquely.
  • Sensor data can create biometric information when patterns derived from watches, phones, or accelerometers uniquely identify an individual. A seemingly innovative use may therefore trigger consent requirements and other legal obligations even when the product was not originally described as a biometric system.
  • Clearview AI reportedly scraped more than three billion publicly posted photos from Facebook, Twitter, and other social platforms. The images were used by the FBI and other law-enforcement bodies, prompting Illinois lawsuits and concerns about privacy threats and civil liberties.
  • Clearview AI experienced a reported data breach affecting its customer list and information about searches performed by law-enforcement agencies. The available information presented in the session indicated that the underlying photos were not part of that breach.
  • The key to safer biometric implementation is understanding what information is collected, whether it identifies individuals, why it is needed, and which protections apply. Organizations should provide appropriate information to users and respect individual rights while mitigating both privacy and security risks.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is biometric data and how can it identify someone?

Biometric data consists of information collected about physical, physiological, or behavioral characteristics associated with an individual. Examples discussed include fingerprints, facial templates, iris scans, voice, heartbeat, gait, and vein patterns. Sensor-derived patterns from phones or watches can also become biometric information when they are used to track personal characteristics or uniquely identify a person.

Q: How can companies implement biometric technology safely?

Companies should first identify exactly what information the technology collects, how it will be used, and whether it can uniquely identify an individual. They should review relevant legal definitions, provide appropriate information to users, obtain the required consent, protect the collected information, and respect individual rights. Privacy and security risks should be evaluated before the technology is deployed.

Q: What are the main commercial uses of biometric technology?

Commercial biometric applications include unlocking phones, authenticating users, detecting fraud in financial services, processing travelers at airports and customs, tracking employee attendance, and supporting transportation or smart-city systems. These uses can improve security, safety, and convenience. However, each implementation must be assessed for privacy, security, consent, and legal risks associated with collecting identifiable personal characteristics.

Q: When does a photograph become biometric information?

A photograph alone is excluded from the Illinois definition described in the session, but its treatment changes when a system extracts a facial template from it. If that template is used to recognize or uniquely identify a person, it can qualify as biometric information. Organizations therefore need to evaluate both the original image and the information derived from it.

Q: Why does biometric data create significant privacy risks?

Biometric data can be uniquely connected to an individual and may be protected under state law similarly to other identifying information. Risks increase when organizations collect it without suitable notice or consent, use it for unexpected purposes, or fail to secure it. Persistent tracking through faces, voices, movement patterns, or sensors also raises broader concerns about surveillance and individual rights.

Q: How can phone and wearable sensor data become biometric data?

Phones and wearable devices contain sensors that continually collect information, including movement-related readings from accelerometers. Patterns derived from those readings may uniquely identify a person or reveal where the person went and what the person was doing. When sensor data tracks personal characteristics or is used for unique identification, it may fall within legal definitions of biometric information.

Q: What does the Clearview AI example show about biometric risk?

Clearview AI reportedly scraped more than three billion publicly posted photos from Facebook, Twitter, and other social platforms, and its system was used by the FBI and other law-enforcement bodies. Illinois lawsuits and civil-liberties concerns followed. A reported breach later affected its customer list and law-enforcement search information, although the photos themselves were not reported as affected.

Q: Why must organizations review biometric laws before deployment?

Legal definitions of biometric data can be complex and may distinguish between raw materials, such as photographs, and derived identifiers, such as facial templates. Laws may also focus on whether information tracks personal characteristics or uniquely identifies someone. Reviewing these definitions helps an organization determine whether notice, consent, security, and other obligations apply before an innovative use creates legal exposure.

Summary & Key Takeaways

  • Biometric technology measures characteristics associated with human life and can recognize or uniquely identify individuals. Examples include fingerprints, facial templates, iris scans, voice, heartbeat, gait, and vein patterns. Depending on applicable state definitions, biometric information may receive protections comparable to other identifying information, such as a name or Social Security number.

  • Commercial uses of biometrics include unlocking phones, processing travelers at airports and customs, detecting financial fraud, authenticating users, supporting transportation and smart-city systems, and tracking employee attendance. These applications offer security, safety, and convenience benefits, but organizations must understand exactly what data their systems collect, how it identifies people, and why it is needed.

  • Privacy and security risks arise when organizations collect biometric characteristics without appropriate notice, consent, or protection. The Facebook litigation in Illinois and scrutiny surrounding Clearview AI illustrate potential consequences. Companies considering biometric systems should evaluate legal definitions, collection purposes, identification capabilities, user rights, security controls, and the broader effects of persistent biometric tracking.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚