Deep Pockets and Amazon Rekognition

There’s a case in Missouri where someone spent 17 months in jail due to faulty facial recognition. The facial recognition software used? Amazon Rekognition, whom I’ve discussed previously.

But was Amazon Rekognition used properly, and was the police department even allowed to use it?

Amazon made the following statement, as recorded by Biometric Update:

““Our terms of service prohibit the use of Rekognition’s face comparison feature by police departments in connection with criminal investigations, and we expect our customers to comply with those terms. However, police departments may use Rekognition for other permitted purposes. We do not access customer content without their agreement so we do not know exactly how the St. Louis Police Department chose to use Rekognition or whether any use case violated our terms, but we will fully investigate any additional information that comes out during the litigation,” an AWS spokesperson said.”

Add to this the advice from Amazon that submitted images be of high quality, not “grainy, blurry, taken from a distance and from above the suspect’s face.” Oh, and not with a hood over the person’s forehead and a medical mask over the person’s face.

But that policy didn’t stop the victim from amending his complaint to include Amazon as a defendant.

Why? Because Amazon has a lot more money than the relevant police department.

But should a software vendor be liable when someone misuses the software…and wasn’t supposed to use the software in the first place?

If your firm has questions about competing with Amazon, or other biometric vendors, you should use Bredemarket’s analysis services. Book a free meeting below to discuss your analysis needs.

More information on my services and my analysis services in the videos below.

Bredemarket: Services, Process, and Pricing.
Impossible?

Managing Privacy When Your Face is Your Password

We know the damage that can happen when people steal passwords. But other stolen information can do harm, including facial templates.

Non-password authentication

I’ve been writing some use cases around the common “selfie plus ID” method.

  • Usually you use facial recognition plus a government-issued ID (such as a driver’s license) to enroll in the system and verify your identity. (Although you could use other factors.)
  • Usually you use only facial recognition (against the template stored from enrollment) to authenticate your identity. (Again, you could use other factors, even a password.)

If the identity mechanism is centralized, you don’t store a password, but instead store a biometric template.

The threat of theft

What happens when—not if—the central storage is hacked?

Even if the storage is decrypted (you did encrypt the data at rest, right?), all may not be lost. Biometric templates from one vendor may not be usable by another vendor’s system.

But even in the worst case scenario in which someone steals and reuses someone’s biometric template, it’s practically useless if the system guards against presentation attacks (liveness) and injection attacks. With those guards, you need more than a valid template to get into a system.

And for those who respond that decentralized identity is the perfect solution…edge devices can be hacked also.

The threat to privacy

But those are just the technical issues. You have to deal with the business issues.

Because the theft exposes personally identifiable information, which may result in legal issues.

Depending upon local law, you have to inform your users of the breach, potentially disclosing what data was breached.

What now?

Are you ready to deal with the business consequences?

Bredemarket can help you get ready.

Mexico’s Fan ID and the Form (and Order) of Consent

It’s not enough to get consent. You have to get consent that is rigorous enough. And not just in Illinois, but also in Mexico.

Biometric Update:

“Mexico’s anti‑corruption regulator has hit the Mexican Football Federation (FMF) with one of one of the country’s largest-ever privacy penalties. The FMF has been fined 42.8 million Mexican pesos (US$2.14 million) for violations linked to its Fan ID system….

“Mexico’s Ministry of Anti‑Corruption and Good Governance (SABG) said FMF failed to tell fans that the photographs collected for Fan IDs were sensitive biometric data and did not obtain the express written consent required under Mexican law.

“Instead, FMF relied on a simple website checkbox without any mechanism to prove the user providing consent was the actual data subject.”

But if your mobile application’s workflow begins with consent before identity verification, how can you change the order and perform facial recognition to positively identify the person giving consent? After all, the person hasn’t given consent to perform facial recognition to confirm the consenting person “was the actual data subject.”

Unless you resort to a manual consent method.

Google Gemini.

Comfort in the Frame

No more trips to CVS for passport photos?

“Comfort in the Frame.” Google Lyria. Public Domain.

For fuller background information, see “Secretary of State Marco Rubio on Online Passport Applications, July 2, 2026.”

For more on what ICAO Document 9303 recommends regarding facial expression, see this post.

And this song.

“Neutral Expression.” Google Lyria. Public Domain.

High-Stakes Biometrics?

This amused me.

I was querying a generative AI tool on behalf of a Bredemarket client, asking a technical question about ICAO Document 9303 (the “don’t smile on your passport” document).

Google Gemini.

And the generative AI tool responded to my prompt with a reference to “high-stakes biometrics.”

I couldn’t let that one slide.

High-stakes biometrics. Google Gemini.

Facial Recognition Motion Blur? What About Irises?

There are some interesting similarities between facial recognition and iris recognition. Scale is not one of them.

Both faces and irises recommend a minimum distance between features. While face distances vary depending upon the algorithm, some recommend a minimum 32 pixels between the eyes. For irises, John Daugman recommended an iris radius of 70 pixels.

Of course, on a human face, the real distance between eyes is much larger than the distance within a small part of an eye.

So what?

If a person’s face is moving rather than stationary, and the camera shutter speed isn’t optimized, the resulting image suffers from motion blur.

Google Gemini simulation.

Try submitting THAT to a facial recognition system. Garbage in, garbage out.

But it gets worse. What if the system in question were an iris recognition system?

Google Gemini simulation.

Compare with an excellent quality image with no blur. Yes, this is an AI simulation, but you get the idea.

Google Gemini simulation.

And that is why irises, despite their impressive accuracy, are not the best solution for all use cases. Which use case is better suited to iris matching?

Google Gemini.

Let Me Explain

If you’re a fingerprint biometric firm and need Bredemarket, I can’t help you this month. I’m already working with one of your competitors.

Likewise, if you’re a face biometric firm and need Bredemarket, I can’t help you this month. I’m already working with one of YOUR competitors.

So where am I seeking clients, if not fingerprint or face companies?

Tell you later.

Another Great Renaming (From 2024)

In August 2023, I talked about what I called a “great renaming” in which the National Institute of Standards and Technology (NIST) differentiated between its face recognition tests and its face analysis tests: a very important distinction and a critical update.

FRVT becomes FRTE and FATE. From NIST.

The ramifications of that renaming persist. Just last week I reminded a biometric firm that its references to “FRVT” were dated.

But what if references to biometrics are dated?

Find…what?

Over twenty years ago a publication called FindBiometrics was established that discussed you-know-what. Fingerprints, faces, irises, and all sorts of stuff.

You would think that a name that incorporated “biometrics” would be all inclusive. It certainly was twenty years ago. But as the industry evolved, the name became a little dated. While biometrics remain critically important, I have to say (with apologies to my former Motorola colleague Edward Chen) that biometrics is not “4” ALL. (You see what I did there.)

The publication realized this also, and performed its own great renaming.

“TORONTO, ONTARIO, CANADA, November 21, 2024 /EINPresswire.com/ — FindBiometrics, a leading news media platform for the biometrics and digital identity industry, is now ID Tech—a refreshed brand identity that reflects the beginning of a new era in the identity technology space.”

Why?

“…the scope of identity tech has expanded to integrate new developments in areas like artificial intelligence, blockchain, and digital ID.”

One example being mobile driver’s licenses, which can utilize biometrics but goes far beyond it. After all, biometrics (something you are) is just one of the six factors of identity verification and authentication. See below.

So now the former FindBiometrics platform is called “ID Tech,” and its URL is now https://idtechwire.com/. And biometrics now shares the stage with other factors.

Biometrics shares the stage. “Revealed” from Google Lyria; Public Domain.

But ID Tech isn’t the only place to learn about identity beyond biometrics. There’s also my book.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.

Shout It From the Mountaintops

When I first heard about the “Florida man” facial recognition mismatch, I couldn’t tell whether the relevant police entity had arrested him based upon the facial recognition results alone, which is a big no-no. (Repeat after me: “investigative lead.”)

Chris Burt of Biometric Update repeated this:

“Shout it from the mountaintops: Probable cause cannot come from facial recognition alone.”

In his article, he also noted that the Pinellas County Sheriff’s Office is cracking down on the relevant police entity:

“PCSO says in its response that it has entered into an MoU requiring [the relevant entity] to send its officers for training on facial recognition before they are allowed to use the system…”