{"id":24029,"date":"2024-02-28T11:06:18","date_gmt":"2024-02-28T19:06:18","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/02\/28\/news-17759\/"},"modified":"2024-02-28T11:06:18","modified_gmt":"2024-02-28T19:06:18","slug":"news-17759","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/02\/28\/news-17759\/","title":{"rendered":"A Vending Machine Error Revealed Secret Face Recognition Tech"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/65d91d8d6248d84bf2a999c2\/master\/pass\/vending%20machine%20facial%20recognition.png\"\/><\/p>\n<p><strong>Credit to Author: Ashley Belanger, Ars Technica| Date: Sat, 24 Feb 2024 22:02:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-jWHrLH hAfVoD byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-jbHncj fuDQVo\"><span data-testid=\"BylineName\" class=\"BylineName-kwmrLn cVPPwi byline__name\"><a class=\"BaseWrap-sc-gjQpdd BaseText-ewhhUZ BaseLink-eNWuiM BylineLink-gEnFiw iUEiRd kZoQA-D ecbzIP BDKtv byline__name-link button\" href=\"\/author\/ashley-belanger-ars-technica\/\">Ashley Belanger, Ars Technica<\/a><\/span><\/span><\/p>\n<p>Canada-based University of Waterloo is racing to remove M&amp;M-branded smart vending machines from campus after outraged students discovered the machines were covertly collecting <a href=\"https:\/\/www.wired.com\/tag\/face-recognition\/\">face recognition data<\/a> without their consent.<\/p>\n<p class=\"paywall\">The scandal started when a student using the alias SquidKid47 <a data-offer-url=\"https:\/\/www.reddit.com\/r\/uwaterloo\/comments\/1anvv0q\/hey_so_why_do_the_stupid_mm_machines_have_facial\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.reddit.com\/r\/uwaterloo\/comments\/1anvv0q\/hey_so_why_do_the_stupid_mm_machines_have_facial\/&quot;}\" href=\"https:\/\/www.reddit.com\/r\/uwaterloo\/comments\/1anvv0q\/hey_so_why_do_the_stupid_mm_machines_have_facial\/\" rel=\"noopener\" target=\"_blank\">posted<\/a> an image on Reddit showing a campus vending machine error message, \u201cInvenda.Vending.FacialRecognitionApp.exe,\u201d displayed after the machine failed to launch a face recognition application that nobody expected to be part of the process of using a vending machine.<\/p>\n<p class=\"paywall\">&quot;Hey, so why do the stupid M&amp;M machines have facial recognition?&quot; SquidKid47 pondered.<\/p>\n<p class=\"paywall\">The Reddit post sparked an investigation from a fourth-year student named River Stanley, who was writing for a university publication <a data-offer-url=\"https:\/\/mathnews.uwaterloo.ca\/wp-content\/uploads\/2024\/02\/mathNEWS-154-3.pdf#page=6\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/mathnews.uwaterloo.ca\/wp-content\/uploads\/2024\/02\/mathNEWS-154-3.pdf#page=6&quot;}\" href=\"https:\/\/mathnews.uwaterloo.ca\/wp-content\/uploads\/2024\/02\/mathNEWS-154-3.pdf#page=6\" rel=\"noopener\" target=\"_blank\">called MathNEWS<\/a>.<\/p>\n<p class=\"paywall\">Stanley sounded the alarm after consulting Invenda sales brochures that promised \u201cthe machines are capable of sending estimated ages and genders\u201d of every person who used the machines\u2014without ever requesting consent.<\/p>\n<p class=\"paywall\">This frustrated Stanley, who discovered that Canada&#x27;s privacy commissioner had years ago investigated a shopping mall operator called Cadillac Fairview after discovering some of the malls&#x27; informational kiosks were secretly \u201cusing facial recognition software on unsuspecting patrons.\u201d<\/p>\n<p class=\"paywall\">This story originally appeared on <a href=\"https:\/\/arstechnica.com\/tech-policy\/2024\/02\/vending-machine-error-reveals-secret-face-image-database-of-college-students\/\">Ars Technica<\/a>, a trusted source for technology news, tech policy analysis, reviews, and more. Ars is owned by WIRED&#x27;s parent company, Cond\u00e9 Nast.<\/p>\n<p class=\"paywall\">Only because of that official investigation did Canadians learn that \u201cover 5 million nonconsenting Canadians\u201d were scanned into Cadillac Fairview&#x27;s database, Stanley reported. Where Cadillac Fairview was ultimately forced to delete the entire database, Stanley wrote that consequences for collecting similarly sensitive face recognition data without consent for Invenda clients like Mars remain unclear.<\/p>\n<p class=\"paywall\">Stanley&#x27;s report ended with a call for students to demand that the university \u201cbar facial recognition vending machines from campus.\u201d<\/p>\n<p class=\"paywall\">A University of Waterloo spokesperson, Rebecca Elming, eventually responded, confirming <a data-offer-url=\"https:\/\/kitchener.ctvnews.ca\/facial-recognition-error-message-on-vending-machine-sparks-concern-at-university-of-waterloo-1.6779835\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/kitchener.ctvnews.ca\/facial-recognition-error-message-on-vending-machine-sparks-concern-at-university-of-waterloo-1.6779835&quot;}\" href=\"https:\/\/kitchener.ctvnews.ca\/facial-recognition-error-message-on-vending-machine-sparks-concern-at-university-of-waterloo-1.6779835\" rel=\"noopener\" target=\"_blank\">to CTV News<\/a> that the school had asked to disable the vending machine software until the machines could be removed.<\/p>\n<p class=\"paywall\">Students told CTV News that their confidence in the university&#x27;s administration was shaken by the controversy. Some students claimed <a data-offer-url=\"https:\/\/www.reddit.com\/r\/uwaterloo\/comments\/1aoci3n\/new_vending_machines_have_alwayson_facial\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.reddit.com\/r\/uwaterloo\/comments\/1aoci3n\/new_vending_machines_have_alwayson_facial\/&quot;}\" href=\"https:\/\/www.reddit.com\/r\/uwaterloo\/comments\/1aoci3n\/new_vending_machines_have_alwayson_facial\/\" rel=\"noopener\" target=\"_blank\">on Reddit<\/a> that they attempted to cover the vending machine cameras while waiting for the school to respond, using gum or Post-it notes. One student pondered whether \u201cthere are other places this technology could be being used\u201d on campus.<\/p>\n<p class=\"paywall\">Elming was not able to confirm the exact timeline for when the machines would be removed, other than telling Ars it would happen \u201cas soon as possible.\u201d Elming declined Ars&#x27; request to clarify if there are other areas of campus collecting face recognition data. She also wouldn&#x27;t confirm, for any casual snackers on campus, when, if ever, students could expect the vending machines to be replaced with snack dispensers not equipped with surveillance cameras.<\/p>\n<p class=\"paywall\">MathNEWS&#x27; investigation tracked down responses from companies responsible for smart vending machines on the University of Waterloo&#x27;s campus.<\/p>\n<p class=\"paywall\">Adaria Vending Services told MathNEWS that \u201cwhat\u2019s most important to understand is that the machines do not take or store any photos or images, and an individual person cannot be identified using the technology in the machines. The technology acts as a motion sensor that detects faces, so the machine knows when to activate the purchasing interface\u2014never taking or storing images of customers.\u201d<\/p>\n<p class=\"paywall\">According to Adaria and Invenda, students shouldn&#x27;t worry about data privacy because the vending machines are \u201cfully compliant\u201d with the world&#x27;s toughest data privacy law, the European Union&#x27;s General Data Protection Regulation (GDPR).<\/p>\n<p class=\"paywall\">\u201cThese machines are fully GDPR compliant and are in use in many facilities across North America,\u201d Adaria&#x27;s statement said. \u201cAt the University of Waterloo, Adaria manages last mile fulfillment services\u2014we handle restocking and logistics for the snack vending machines. Adaria does not collect any data about its users and does not have any access to identify users of these M&amp;M vending machines.\u201d<\/p>\n<p class=\"BylineWrapper-jWHrLH cExbzu byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-jbHncj fuDQVo\"><span data-testid=\"BylineName\" class=\"BylineName-kwmrLn cYaBaU byline__name\">Byron Tau<\/span><\/span><\/p>\n<p class=\"BylineWrapper-jWHrLH cExbzu byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-jbHncj fuDQVo\"><span data-testid=\"BylineName\" class=\"BylineName-kwmrLn cYaBaU byline__name\">Julian Chokkattu<\/span><\/span><\/p>\n<p class=\"BylineWrapper-jWHrLH cExbzu byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-jbHncj fuDQVo\"><span data-testid=\"BylineName\" class=\"BylineName-kwmrLn cYaBaU byline__name\">David Nield<\/span><\/span><\/p>\n<p class=\"BylineWrapper-jWHrLH cExbzu byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-jbHncj fuDQVo\"><span data-testid=\"BylineName\" class=\"BylineName-kwmrLn cYaBaU byline__name\">Kate Knibbs<\/span><\/span><\/p>\n<p class=\"paywall\">Under the GDPR, face image data is considered among the most sensitive data that can be collected, typically <a data-offer-url=\"https:\/\/gdpr-info.eu\/recitals\/no-51\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/gdpr-info.eu\/recitals\/no-51\/&quot;}\" href=\"https:\/\/gdpr-info.eu\/recitals\/no-51\/\" rel=\"noopener\" target=\"_blank\">requiring<\/a> explicit consent to collect, so it&#x27;s unclear how the machines may meet that high bar based on the Canadian students&#x27; experiences.<\/p>\n<p class=\"paywall\">According to a <a data-offer-url=\"https:\/\/www.globenewswire.com\/en\/news-release\/2022\/01\/14\/2367130\/0\/en\/Automated-Retail-Innovator-Invenda-Raises-7-59M-for-Global-Growth.html\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.globenewswire.com\/en\/news-release\/2022\/01\/14\/2367130\/0\/en\/Automated-Retail-Innovator-Invenda-Raises-7-59M-for-Global-Growth.html&quot;}\" href=\"https:\/\/www.globenewswire.com\/en\/news-release\/2022\/01\/14\/2367130\/0\/en\/Automated-Retail-Innovator-Invenda-Raises-7-59M-for-Global-Growth.html\" rel=\"noopener\" target=\"_blank\">press release<\/a> from Invenda, the maker of M&amp;M candies, Mars, was a key part of Invenda&#x27;s expansion into North America. It was only after closing a $7 million funding round, including deals with Mars and other major clients like Coca-Cola, that Invenda could push for expansive global growth that seemingly vastly expands its smart vending machines&#x27; data collection and surveillance opportunities.<\/p>\n<p class=\"paywall\">\u201cThe funding round indicates confidence among Invenda\u2019s core investors in both Invenda\u2019s corporate culture, with its commitment to transparency, and the drive to expand global growth,\u201d Invenda&#x27;s press release said.<\/p>\n<p class=\"paywall\">But University of Waterloo students like Stanley now question Invenda&#x27;s \u201ccommitment to transparency\u201d in North American markets, especially since the company is seemingly openly violating Canadian privacy law, Stanley told CTV News.<\/p>\n<p class=\"paywall\">On Reddit, while some students joked that SquidKid47&#x27;s face \u201ccrashed\u201d the machine, others asked if \u201cany pre-law students wanna start up a class-action lawsuit?\u201d One commenter summed up students&#x27; frustration by typing in all caps, \u201cI HATE THESE MACHINES!\u00a0I HATE THESE MACHINES!\u00a0I HATE THESE MACHINES!\u201d<\/p>\n<p class=\"paywall\"><em>This story originally appeared on<\/em> <em><a href=\"https:\/\/arstechnica.com\/tech-policy\/2024\/02\/vending-machine-error-reveals-secret-face-image-database-of-college-students\/\">Ars Technica<\/a>.<\/em><\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/facial-recognition-vending-machine-error-investigation\/\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/65d91d8d6248d84bf2a999c2\/master\/pass\/vending%20machine%20facial%20recognition.png\"\/><\/p>\n<p><strong>Credit to Author: Ashley Belanger, Ars Technica| Date: Sat, 24 Feb 2024 22:02:00 +0000<\/strong><\/p>\n<p>A student investigation at the University of Waterloo uncovered a system that scanned countless undergrads without consent.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-24029","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24029"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24029\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}