5 ms·
most of my family agreed to get fingerprinted to get free gym membership (family friend runs the gym and you scan your thumb at the door for access). It pissed
by latenightcoding 5y ago
most of my family agreed to get fingerprinted to get free gym membership (family friend runs the gym and you scan your thumb at the door for access).
It pissed me off so much.
- version_five 5y agoWhy did it piss you off? Is the fingerprint being used for something other than access? Is it even stored in a format that would allow it to be used for something else? I'm pretty privacy and personal freedom conscious- for example I wouldn't go anywhere that made me scan a QR code or use an app. But I can't think of any concern I have with a private business using my fingerprint as an access token, unless I'm also signing that they can use it for other stuff.
- katzgrau 5y ago> unless I'm also signing that they can use it for other stuff. Person at desk during signup: "Just press agree and then insert your thump on the reader below." That "agree" part is where they inserted their vague allusions to doing what they want
- PostThisTooFast 5y ago"I'm pretty privacy and personal freedom conscious- for example I wouldn't go anywhere that made me scan a QR code or use an app. But I can't think of any concern I have with a private business using my fingerprint as an access token" That is absolutely ridiculous and contradictory. You won't scan a QR code with a phone app, but you'll hand your fingerprints over to a private entity? For storage with unknown security and access by an unknown number of people? Dumb.
- chuckee 5y ago> unless I'm also signing that they can use it for other stuff. I find your trust in the strength of a terms of service agreement baffling. If they get a court order it doesn't matter what you allowed them to do with it. And even without a court order, if they used your fingerprint in ways you didn't allow, how would you know? They wouldn't be the first company to break the law when they think they can get away with it. Even if you trust them, what about when they go bankrupt, or acquired by a chain gym, and all their assets (fingerprints included) suddenly belong to less-scrupulous people.
- version_five 5y agoThe biggest reason I don't care is that I doubt they are asking for or recording something from which they can reconstruct my fingerprint. They are reading it into a proprietary scanner run by a local gym (this is an assumption, but I'll bet its true). The scanner has some proprietary code that checks if my fingerprint matches the next time. It can't export a fingerprint file, it cant share it with anyone. If I'm wrong, and they are actually scanning some portable fingerprint image that is readily used either to provide and example for comparison to others, or so generate a fingerprint, then your comment applies. But my guess is it's just a local gym with a scanner and a database that exists in the proprietary scanner software. I'd be much more concerned about giving my fingerprint to apple or lenovo or whatever device provider. Incidentally, I could be entirely wrong. For example, if there is some Fingerprint-as-a-service company the gym uses that lets you create a portable ID based on your fingerprint, I would refuse.
- ramblenode 5y agoI find it helpful to assume an adversarial worldview to any service that collects or handles data. You've mentioned some reasonable assumptions about how this system might work. But it's ultimately trust in a black box and a manufacturer with whom you have no personal or business relationship. You have no way of knowing if, at any time, your assumptions are still correct, or if one day in the future what's inside the box gets changed out. What incentives would it take for that to happen? To my imagination, not much. E.g. the manufacturer thinks it can start a side business collecting and selling your full prints. There is certainly a market for them, so why not collect them? Maybe law enforcement sees these devices proliferating and convinces lawmakers to require that the prints be stored to support local investigations. Who would be against catching predators at your gym? Meanwhile the gym doesn't care because this isn't it's problem---and it gets a discount. Things can change fast. If it seems possible, someone is probably thinking about how to do it.
- PragmaticPulp 5y agoModern fingerprint reader systems don’t capture and store an entire fingerprint. They use algorithms that extract a number of features from the print. You can’t extract someone’s fingerprint from a gym’s fingerprint scanning system and run it through a background check database, for example. If you’re concerned about giving up identifiable data points, the photo on your gym membership account is more likely to be usable in other search contexts than the application-specific reduced fingerprint data stored in their scanner.
- nullc 5y ago> You can’t extract someone’s fingerprint from a gym’s fingerprint scanning system and run it through a background check database, for example. Until they swap out the reader at the door for one that also saves fingerprint images (if the one there doesn't support that already!).
- Blikkentrekker 5y agoOr one's simple legal name and billing address. I'm honestly a fair bit more concern about that dealing in legal names and addresses is still so common than I am about tracking cookies, but, as usual, people are more afraid of new things than of old, even if the old be more dangerous.
- dane-pgp 5y ago> You can’t extract someone’s fingerprint from a gym’s fingerprint scanning system and run it through a background check database, for example. Reversing the algorithm in order to generate a plausible fingerprint from the features stored by the scanner seems much simpler than cracking a secure hash function, since the scanner algorithm has to deal with imprecise inputs. Whether the generated fingerprint would match the relevant record in the background check database depends on whether the features extracted by the scanner are sufficiently different from those used by the background check system, and I suspect that companies just reuse the same algorithms for both.