Laws that ban facial recognition miss the larger point: we need laws on all tech used for identification and to decide how much of our data should be surveilled
and the ways that data is combined to create searchable profiles of us without any consent on our part. https://www.nytimes.com/... Dahlia Peterson / @dahlialpeterson : “A ban on facial recognition won't make any difference if, in response, surveillance systems switch to identifying people by MAC addresses...we are being identified without our knowledge or consent, and society needs rules about when that is permissible.” https://www.nytimes.com/... Adrienne Fichter / @adfichter : “People can be identified by their heart-beat, gait, fingerprint, iris patterns—all of which can be obtained remotely via tech. (...) we need rules protecting people's privacy and requiring their consent before any of these means are used” https://www.nytimes.com/... Marietje Schaake / @marietjeschaake : Facial recognition tech is under scrutiny but we need to have a serious conversation about all identification, correlation and discrimination technologies and decide how much we want to be spied on by governments and corporations @schneierblog ↘️https://www.nytimes.com / ... Lindsey Andersen / @linds_anders : Bruce hitting the nail on the head. A ban on #FacialRecognition won't stop mass surveillance. “The problem is that we are being identified without our knowledge or consent, and society needs rules about when that is permissible.” https://www.nytimes.com/... Dietmar Offenhuber / @dietoff : “focusing on [fac.rec] misses the point. We need to have a serious conversation about all the technologies of identification, correlation and discrimination” Bruce Schneider who started the 90s crypto battles by 1st publishing “forbidden” strong encryption https://www.nytimes.com/... Russjackson / @docrussjackson : San Francisco & other US cities have already banned facial recognition. Activists are understandably calling for a nationwide ban. The @nytimes argues focusing on just one method of identification fails to address the wider problem of mass surveillance. https://www.nytimes.com/... Oscar Pocasangre / @oscarpocasangre : Boarding at JFK now requires using a facial recognition machine. I tried opting out (on principle because they already have all my facial data) but airline employees didn't allow it. https://twitter.com/... Spencer Ackerman / @attackerman : “A ban on facial recognition won't make any difference if, in response, surveillance systems switch to identifying people by smartphone MAC addresses. The problem is that we are being identified without our knowledge or consent...” https://www.nytimes.com/... Kontra / @counternotions : “The whole point of modern surveillance is to treat people differently, and facial recognition technologies are only a small part of that.” https://www.nytimes.com/... @dhh : “The large internet surveillance companies like Facebook and Google collect dossiers on us more detailed than those of any police state of the previous century”, https://www.nytimes.com/... @privacyproject : “Focusing on one particular identification method misconstrues the nature of the surveillance society we're in the process of building,” writes @schneierblog https://www.nytimes.com/... Drew Harwell / @drewharwell : Facial-recognition surveillance on the general public is becoming the new normal today in London. Which city will be next? http://news.met.police.uk/... @privacyint : “We are being identified without our knowledge or consent, and society needs rules about when that is permissible”, writes Bruce Schneier in the NYT https://www.nytimes.com/... There are many ways you can be identified, some you might not know about. Here are some examples 👇 1/5
Context & Ripple Effects
This op-ed lands after a year of piecemeal action: San Francisco and other cities have banned government facial recognition, while critics have catalogued how US law enforcement deploys the technology with little transparency (law enforcement's expanding use of facial recognition). Bruce Schneier's argument is that those bans attack one sensor, not the practice — people can be identified remotely by gait, heartbeat, iris patterns, or MAC addresses, so a facial-recognition ban just reroutes surveillance to the next identifier.
The piece also widens the lens beyond government: commentators note Facebook and Google already hold user dossiers more detailed than historical police-state records, and JFK travelers reportedly could not opt out of facial-recognition boarding. That consumer-side ubiquity is exactly why later coverage argues regulation of government use alone leaves the problem unsolved (the same tech embedded in consumer devices).
First-order effects
- City-level bans like San Francisco's stop covering the threat surface: vendors and agencies can comply by swapping in gait, heartbeat, or MAC-address identification, none of which the bans touch.
- Microsoft and Amazon's lobbying for federal facial-recognition rules (their push for federal regulation) now looks misaligned with the op-ed's demand — industry-shaped rules scoped to one technology would leave every other identifier unregulated.
Second-order effects
- Vendors of alternative biometrics — gait, iris, heartbeat — become the beneficiaries of facial-recognition bans, gaining a compliance-friendly sales pitch to police departments and airports facing local restrictions.
- Consent becomes the contested battleground: if airlines cannot honor opt-outs at boarding and platforms build dossiers without permission, pressure shifts from banning hardware to legislating when identification of anyone, anywhere, requires notice and agreement.
Third-order effects
- If the pattern holds, privacy law reorganizes around a technology-neutral principle — regulating identification and data combination rather than named techniques — forcing every biometric and network-identifier vendor into the same consent framework.
- The gap between city bans and federal inaction points toward preemption fights: industry lobbying for narrow federal rules versus broader statutes covering all identification tech, with airports and consumer platforms as the test cases for whether opt-out rights are enforceable at all.
The trend: Privacy regulation is shifting from single-technology bans toward technology-neutral consent rules covering every method of identifying people, as each banned technique is replaced by another.