Persona, Discords "Age Verification" Service, creates a profile of you, sends it to the US Feds and deems you suspicious based on your appearance, exposed by Hackers

https://lemmy.blahaj.zone/post/38950187

Blåhaj Lemmy - Choose Your Interface

“Why wouldn’t I use verification? I’ve got nothing to hide”.

This. This is why you do not submit willingly, regardless of what you have to hide. Fascism doesn’t give a shit if you’re innocent.

Using Microsoft teams at work, it keeps on asking me record a voice sample and selfy so it can identify me in meeting , yeah no thanks
And then your coworkers think you’re IT challenged because you don’t even know how to do the simplest things. (true story)

My company just mandatorily implemented “Windows Hello”

No one seems to be able to tell me why the information from Microsoft says the fingerprint and face scans are both “local only” and may take 24 hours to sync after initial setup. Where are they syncing to?
(I opted for the ‘pin’ method instead of surrendering my biometrics.)

My assumption is that they are recorded locally, then hashed, then the hash is sent to Azure (Microsoft cloud) as Windows Hello leverages some cloud features. Some things in Azure have warnings about taking up to 24 hours to take effect.

Hashing locally and sending the hash to a server is the same way all passwords for online services and systems work, so nothing nefarious there.

There’s probably perceptual hashing so they can count 95% similarity as a match without having to check against the source material every time.

I could accept that it has to do with azure propagation delays, but the verbiage was explicit about our computers syncing to the tenant. (Vs. data propagating across it.)

I sort of reject the idea that there’s nothing nefarious going on. The misdirect is weird.

Unless they’re salting the hashed data with information they can’t access, they’re just creating a database of faces and fingerprints.
Sure, maybe if their cryptography is good the DB cannot be reversed but they can still use an unsalted database to give match/no match info on scans of faces and fingerprints submitted to it.
But also, I firmly don’t trust Microsoft. They’ve violated our ELA several times - mostly around applying analytics tools to our data without consulting us first. (Like rolling out MS Viva without telling us.)