AndyCrow Posted August 28, 2019 Posted August 28, 2019 Anybody heard of this being used in UK ? https://www.bbc.co.uk/news/technology-49489154# 1
GREED Posted August 28, 2019 Posted August 28, 2019 Yes, couple of edTech providers were showing this off at BETT couple if years back. Will not publicise their names, though do take a bit of personal pleasure after I told them how bad an idea this was against GDPR, and was assured it was all fine and it was GDPR compliant.
titch Posted August 29, 2019 Posted August 29, 2019 The article pertains to the use of biometric data in general. Whilst the school did ask for permission to use the biometric data it was deemed there were better ways to monitor attendance without collecting such sensitive data. Could the same be said for using fingerprints for cashless catering and library software?
synaesthesia Posted August 29, 2019 Posted August 29, 2019 Could the same be said for using fingerprints for cashless catering and library software? Not in the same way, no. Fingerprinting for catering in particular is useful as it's quick. When pushing through hundreds of students to get their meals in the short period of lunchtime, delays hurt; people forgetting pins, rummaging around for cash etc. You could counter with other ideas such as RFID cards but these are easily stolen and replicated. 1
GREED Posted August 29, 2019 Posted August 29, 2019 The article pertains to the use of biometric data in general. Whilst the school did ask for permission to use the biometric data it was deemed there were better ways to monitor attendance without collecting such sensitive data. Could the same be said for using fingerprints for cashless catering and library software? It 'could', but fingerprint in implicit - you actively need to do that individually to register. Same could be said for RFID on cards - it will only scan what it can. Facial Recognition will scan everyone, pick out those it knows, still scan an reject those it doesn't, but it has still taken those 'faces'. You have to have the data in order to then reject it. Side note on this, we have to remember that GDPR is still so new, it will need years of test cases in courts and what not to iron out the practicalities, and for tech and society to adjust. 1
titch Posted August 29, 2019 Posted August 29, 2019 Not in the same way, no. Fingerprinting for catering in particular is useful as it's quick. When pushing through hundreds of students to get their meals in the short period of lunchtime, delays hurt; people forgetting pins, rummaging around for cash etc. You could counter with other ideas such as RFID cards but these are easily stolen and replicated.You might say the same for registration. Image the admin burden lifted if no teachers had to take registers?
titch Posted August 29, 2019 Posted August 29, 2019 It 'could', but fingerprint in implicit - you actively need to do that individually to register. Same could be said for RFID on cards - it will only scan what it can. Facial Recognition will scan everyone, pick out those it knows, still scan an reject those it doesn't, but it has still taken those 'faces'. You have to have the data in order to then reject it. Side note on this, we have to remember that GDPR is still so new, it will need years of test cases in courts and what not to iron out the practicalities, and for tech and society to adjust.Playing devils advocate.....I would say some students don't understand the implication of having fingerprints taken. Is them putting there finger on the scanner an implication that a 8 year old is happy to have their fingerprint taken?
GREED Posted August 29, 2019 Posted August 29, 2019 Playing devils advocate.....I would say some students don't understand the implication of having fingerprints taken. Is them putting there finger on the scanner an implication that a 8 year old is happy to have their fingerprint taken? That is why they are not the ones signing the consent form to allow the school to have their fingerprint, the parents do
titch Posted August 29, 2019 Posted August 29, 2019 That is why they are not the ones signing the consent form to allow the school to have their fingerprint, the parents do Yes while I agree I reckon this is a ticking time bomb in itself.
GREED Posted August 29, 2019 Posted August 29, 2019 Yes while I agree I reckon this is a ticking time bomb in itself. I think if fingerprints were as new (reading, obviously fingerprints have been around a little longer!) as commercial facial recognition I would agree. I think this is the first test case, as is the one in Kings Cross right now, and things will get sorted out and then new interpretations will come about around privacy and GDPR. Think of it this way though, a PIN number is one step away from fingerprints - usually personal or something on you have or know. OK OK it is actually PIN and card combination, but the concept it the same. We use it to identify who we are. Facial recognition in isolation is much the same. The problem comes because it is non-invasive you a) don't know you are being captured (conceptually, obviously if it were happening you would do) and b) you have no choice but to be photographed. That is the real difference here. If say you have to go stand in front of a camera in a booth, and you could choose not to, and anyone who chose not to were not imaged, this would be less of an issue. Good debate this, very interesting ideas and questions being asked! 1
titch Posted August 29, 2019 Posted August 29, 2019 I'm waiting for the first little Johnny Smith to take a school/parent to court for allowing use of their biometric/DNA/photo consent etc etc in the very near future. At what line will guardians stop giving away data that lasts a life time? and will they be able to give this consent forever?
ITGURU Posted August 29, 2019 Posted August 29, 2019 Not in the same way, no. Fingerprinting for catering in particular is useful as it's quick. When pushing through hundreds of students to get their meals in the short period of lunchtime, delays hurt; people forgetting pins, rummaging around for cash etc. You could counter with other ideas such as RFID cards but these are easily stolen and replicated. We're just changing from a fingerprint to card system to get students through the canteen quicker as cards work first time, fingerprints not always detecting first time. However on the fingerprint side, we got the parents permission, however once captured they were encrypted and could never be read as an image, so secure and only stored on the schools local server.
titch Posted August 29, 2019 Posted August 29, 2019 We're just changing from a fingerprint to card system to get students through the canteen quicker as cards work first time, fingerprints not always detecting first time. However on the fingerprint side, we got the parents permission, however once captured they were encrypted and could never be read as an image, so secure and only stored on the schools local server.I'm always a bit sceptical around the spin the biometrics guys push. If it can read a fingerprint the the image of the fingerprint is stores somewhere and somewhere. It may be behind some very clever encryption but if the encryption key/method is ever broken then surely the images can be reverse engineered? Please correct me if I'm wrong. The other bit of spin from the biometrics guys is that the fingerprint data is not accurate enough to be emisable in a court of law. Correct me if I'm wrong again but......even if it's inaccurate....if only 2 suspects were in a room. Someone was murdered next to the canteen fingerprint reader are they suggesting that the fingerprint match that is completely different to the other person's fingerprint match could not be used? I don't think so.
mikeprice Posted August 29, 2019 Posted August 29, 2019 As far as I have been told the fingerprint is encrypted into a numeric/alphanumeric code - in the same way that normal passwords are encrypted This works fine in a relatively small environment like a school. There is a very low chance that 2 people's fingerprints would encrypt to the same code - but it is possible in a larger environment Just like normal passwords - there is no way to reverse the encryption. With normal passwords you can brute force attack the encryption starting with A then working up to zzzzzzzzzzzzzzz one change at the time I used to have a macro that would do this for excel passwords where the password has been forgotten - it always worked but never gave the original passwords - just a character string that also worked With an image such as a fingerprint this would also work but be massively more difficult to achieve Because of both these things the encrypted/encoded passwords from the fingerprint reading system would never be any use to the Police However, when we implemented it at a secondary school some years ago we did get some objections - which was weird as the kids whose parents families objected were the ones where the whole family's print were already recorded by the police anyway!
GrumbleDook Posted August 30, 2019 Posted August 30, 2019 The discussion has been an interesting read ... a few points to consider and remember though. Firstly, in the UK we have the Protection of Freedoms Act which also governs the use of biometric data and ICO / DfE have advice on this already ... it has been discussed in previous discussions and also in one of the sticky threads too. Secondly, whilst the translation of the final decision I have is a tad shaky, there are a few easy things to pick out as key points. 1 - the processing was more intrusive compared to other options 2 - processing of personal data under consent was effectively forced on the students. This meant that the lawful basis under both article 6 and article would be invalid. 3 - they failed to recognise aspects of article 5 (purpose limitation and data minimisation) 4 - the Risk Assessment (DPIA) was deemed inadequate as it did not deal with certain areas including fails on identification due to headgear/scarves/shawls. Having also spoken with some of the same folk at BETT about their systems, some of them had a clear message that DPIAs had to be rigorous and deal with all aspects. Others had a more laissez-faire attitude ... One important purpose, identification in the event of an emergency (e.g. fire or significant threat) was an interesting approach, but falling back in purpose limitation, you couldn’t then use that to justify general attendance use. It is an interesting area to consider when you think about the recent news about use of facial recognition in the Kings Cross area of London. More guidance on Risk Assessments is obviously needed.
enjay Posted August 30, 2019 Posted August 30, 2019 We've all taken this discussion down the route of linking it with biometrics, which is valid, but.... One thing which struck me from the article was the line "students had a certain expectation of privacy when they entered a classroom". If students have an expectation of privacy in a classroom, what does that mean for CCTV in classrooms? I remember seeing these systems at BETT and having some concerns. I think it is definitely an area worth investigating though, as schools spend enormous amounts of time counting children, and even then are often not confident they know where everyone is.
synaesthesia Posted August 30, 2019 Posted August 30, 2019 "expectation of privacy in a classroom" - full of staff and other students, with the whole school administration and therefore likely the MAT or LEA being aware of exactly where they are and what they should be doing? That's not very private, and it's also for good reason. School toilets yes. Classroom, no.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now