Grocery Outlet Wants to Prevent Shoplifting. Can They?

I missed this story when Biometric Update originally published it:

“Facial recognition systems are scanning shoppers as they enter a growing number of Grocery Outlet stores in the San Francisco Bay Area, comparing their faces against watchlists of people suspected of theft, violence, or other unlawful conduct.

“Signs disclosing the use of biometric face-matching software have been documented at Grocery Outlet stores in Pleasant Hill and Concord, as well as four San Francisco locations in the Mission, Portola, Bayview, and Richmond districts.

“The signs direct customers to the privacy policy for SAFR Guard, the system being used by the stores.”

Author Anthony Kimery notes that there are privacy concerns related to those people whose images are captured, but whose faces are NOT on a watchlist.

In addition, Grocery Outlet operates through independent operators, adding one complication to any concerns about privacy violations.

But at least Grocery Outlet isn’t located in Illinois, where their scanning of everybody’s faces could get them (and their independent operators) into BIPA trouble. They are primarily a Pacific (California, Oregon, Washington) and Atlantic (Maryland, Ohio, Pennsylvania) operation.

It’s Now a First “World”

When Bredemarket started covering the iris company then known as Worldcoin, it positioned itself as a revenue generator for third world users who wanted to prove their humanity (but not their identity).

“Once uniqueness is determined, the person can get money money money with an assurance that the same person won’t get money twice.”

The only problem was that their governments disagreed.

And the WLD token declined in value.

From CoinMarketCap.

So the company, now called World, is regrouping.

“As utility across the network increases, World is evolving its growth model to prioritize real-world utility and ecosystem participation. In the early stages of the network, token incentives played an important role in helping bootstrap adoption and participation. Going forward, World’s growth model will rely primarily on the utility from the products, services, and experiences powered by World ID.”

And they’re focusing on five countries:

  • The United States.
  • Germany.
  • The United Kingdom.
  • Japan.
  • South Korea.

We’ve seen this.

This is not a defeat; companies continuously evolve. I still remember when Apple Computer only made computers. Creation of the iPod (and the iPhone) wasn’t a failure.

But if you’re looking for someone to lift the developing world out of poverty, look elsewhere.

In-app Browsers: Chrome, Safari, and Edge Browser Privacy Settings Are Not Enough

Many of us select our favorite browser—Chrome, Safari, Edge, whatever—based on its privacy controls. Once we set our privacy controls to our satisfaction, we think we’re protected.

Not always.

Let’s say you’re in the Facebook app and click on a link. Facebook isn’t going to send you off to your default browser to access the link. Because Facebook has a special feature just for you.

“The in-app browser for Facebook and Instagram allows people to open web links within the Facebook or Instagram mobile app on iOS or Android. For example, when a customer sees a business ad on the Facebook app and taps on it, web links in the ad open in the in-app browser by default.

“The in-app browser uses industry-standard technology to enable customers to seamlessly view and take action on websites without leaving the Facebook app.”

Because you want a seamless experience…don’t you? DON’T YOU? YOU DO. MARKY MARK SAYS SO.

Marky Mark as depicted by Loren Feldman.

And naturally there’s something in it for Facebook also. Because the primary purpose of any social app is to keep you in that app forever and ever. If you suddenly switch to Chrome you have left the Meta ecosystem (which also includes Instagram, lest we forget) and have entered the Google ecosystem.

This is bad…for Facebook.

If we are locked within Facebook’s walled garden, then Meta captures all our data.

And then some.

“Facebook and Instagram applications use embedded browsers that automatically open when you click on external links within the app, rather than opening your default browser. This behavior allows Meta to inject JavaScript code into visited websites, enabling tracking of user interactions including form inputs, button clicks, and purchases made on external sites.”

Now obviously your own browser can do the same thing, but it’s relatively easy to clear your browser data, including cookies. It’s harder to clear the data from the in-app browsers within Facebook and Instagram. Once you find where the control is hidden this week, you can Clear Data (which differs from Clear Cache).

By the way, privacy-sucking in-app browsers are not solely provided by Marky Mark. Tik Tok does it also. The Amazon app uses JavaScript, but Felix Krause could not detect any tracking.

Other apps do not use JavaScript in their in-app browsers, including Reddit, Robinhood, Snapchat, and X.

But you can test yourself. Go to your favorite social app, type https://inappbrowser.com/ to your feed, and click on the link. The site may no longer be active.

Login.gov’s Technology Partners

I had always assumed that Login.gov only used homegrown technology.

Well, you know what happens when you assume.

From an Xcelerate Solutions press release:

“Leveraging their 2024 Login.gov Next Generation Identity Proofing Blanket Purchase Agreement (NG BPA), Xcelerate Solutions and their subcontractor Socure were awarded a five-year, $163M call order for Functional Area Three on May 1, 2026.”

And that’s not all. Here’s another press release:

“Diamond Capture Associates, a woman-owned business specializing in enterprise technology consulting and large-scale government implementations, and Incode Technologies, a global leader in identity security and fraud prevention, today announced the award of a $37.4 million contract from the General Services Administration (GSA), Federal Acquisition Service’s Technology Transformation Services (TTS).

“Under this call order, Diamond Capture Associates and Incode will support the Login.gov Next Generation Identity Proofing Blanket Purchase Agreement (NG BPA), a critical federal initiative focused on strengthening digital identity verification and reducing fraud across government services.”

Can Your Software Capture Irises with an Android Camera?

Iris solution vendors, I hope you saw the latest and greatest from SAM.gov (PEO-TIS: Contactless Iris Collection Collaboration Event (CE)):

CONTACTLESS iris?

Now wait a minute.

Is anyone actually proposing CONTACT iris collection?

And I’m not talking about the old system of putting your iris really close to the camera. I’m talking about the iris TOUCHING the collection device, like many fingerprint systems do today.

I don’t think so.

But let’s look at the meat of the opportunity.

SOFWERX, in collaboration with USSOCOM Program Executive Office Tactical Information Systems (PEO-TIS), will host a series of events to complete a study of mobile devices (Android-based cell phones and tablets) with built-in cameras for their use in unaided iris localization and collection, including resolution testing and image distortion analysis.

Note the word “unaided.” It’s a lot easier to capture irises if the capture device does the work for you. Soldiers in the field don’t have time to precisely position the camera with an uncooperative subject.

A previous study indicated that it is possible to conduct iris localization using a mobile device camera, but a wider population pool is required to validate these results. A wider population of 500-1000 is adequate to prove the basic viability of the biometric algorithm. 

Hey, it’s not a million people, but it’s not bad.

If you’re an iris solution vendor and register by August 28, here’s the timeline:

  • Phase 1: 30 September 2026 Collaboration Event (CE)
  • Phase 2 – 27 October 2026 to 27 November 2026 Submissions to the Assessment Event (AE) Open
  • Phase 2a – 11 November 2026 Q&A Telecon
  • Phase 3 – 30 November 2026 to 14 December 2026 Downselect
  • Phase 4 – 19 January 2026 [sic] to 21 January 2026 [sic] Assessment Event (AE)
  • Phase 5 – Path Forward

See the SAM.gov announcement for more details.

Since this effort is primarily technical, Bredemarket can’t drive the effort. But if you need assistance in content, proposal, or analysis materials before, during, and after the event, talk to me.

My Algorithm is American Made

The United States of America, like many other countries, displays patriotism. One example is the Oak Ridge Boys song “American Made.”

And the United States of America, like many other countries, commercializes patriotism. One example is the Miller commercial “Made the American Way.”

At the time this commercial was filmed, Miller WAS American made, under the ownership of Philip Morris. Today, of course, Miller is NOT solely American made, with the company owned by Molson Coors with headquarters and executive offices in Chicago, Montreal, and Golden Colorado. Its brand competitor Budweiser is Belgian made.

I am very familiar with cross-border ownership, having worked for Safran (French headquarters) and IDEMIA (French headquarters, but primarily owned by a U.S. investment firm). So when someone asks whether IDEMIA is a U.S. company or a French company, the proper answer is “yes.”

IDEMIA’s major competitors, NEC and Thales, are non-U.S. owned.

And if the Amadeus deal goes through, an American investment firm will NOT own the new entity.

But there are U.S. biometric firms. Bredemarket works or has worked for multiple U.S.-owned/headquartered biometric companies.

One company that is not (yet) a Bredemarket client is ROC (a/k/a Rank One Computing). Since it works with U.S. security agencies, you can bet that ROC echoes the Oak Ridge boys in its marketing. Josh Engelsma:

“For decades, large-scale U.S. biometric identity systems have relied heavily on foreign fingerprint providers. ROC’s performance in the NIST FRIF TE E1N evaluation, including #1 global ranking in Class B slap fingerprints, a critical capture format for high-scale civil and government identity programs, proves that American technology can now lead at the highest levels of global biometric performance.”

It’s hard to predict whether U.S. government agencies will become “more patriotic,” since there are so many good foreign algorithms out there. But don’t count on DHS implementing a system with a Chinese algorithm.

“Muvaffaqiyat kaliti” (The Key to Success)

When I asked Google Lyria to create the first of my two World Cup songs, the result was in Spanish.

Which gave me an idea. And impressed on me that I may never use a standalone translation app again.

Because if I want Uzbeks to promote Bredemarket, it helps them if I (or more accurately my bot) create content.

Because I am the Uzbek sales enablement content marketing expert.

Muvaffaqiyat kaliti. Google Lyria. Public Domain.

What does it mean? Unless Gemini is lying to me, “The Key to Success.”

(Yor-yor-ey…) Bredemarket!

New horizons in the U.S. market,

Your brand will shine, blooming like flowers.

Strategic writing, powerful marketing,

A brand new targeting for your business.

The key to success, Bredemarket!

The key to your business, Bredemarket!

Gemini appears to be interpreting the prompt from a regional perspective. I don’t normally use “new horizons” and “blooming like flowers” to promote my services to Bay Area, San Diego, or New York firms.

Google Gemini.