1 of 20

THOUGHT POLICE�HOW THE END OF PRIVACY IS NEAR

Suzanne Leibrick

@inannamute

#thinkcrime

2 of 20

WHY AM I TALKING ABOUT PRIVACY AND VR?

  • What is unique to Virtual Reality about Privacy?
  • What potential technologies exist today, or will soon, that affect Privacy?
  • Why is this something we should talk about now?
  • What are the potential good and bad outcomes for future VR and AR technologies?

3 of 20

HOW TO BUILD A MIND READER

The Technology of today and tomorrow

4 of 20

TODAY’S TECHNOLOGY

  • Already Exists in VR or AR headsets
    • Full hand and head tracking for motion and gesture
    • Positional and Location tracking
    • Collection of that data
    • Ability to tie that data to your real name
    • Heatmaps showing what you pay attention to in VR or AR
    • Spatial Mapping and awareness
    • External cameras
  • Already Exists, but not implemented widely in VR or AR headsets (yet)
    • Eye tracking
    • EEG monitoring
    • Machine Learning/Deep Learning
    • Artificial Intelligence
    • Full body tracking
    • Other bio sensors such as heart rate monitors
    • Privacy controls

5 of 20

HOW TO BUILD A MIND READER

  • Add in as many sensors as possible to a VR headset
  • Definitely include an eye tracker
  • Record all data!
  • Carefully curate content depending on what information you want to know
  • Tie all the data to one real person’s identity
  • Apply Deep Learning

6 of 20

STEP ONE

Add in as many sensors as possible to your VR or AR headset.

  • EEG is a must!
  • Heartrate monitors
  • Full Body Tracking

7 of 20

IT’S THE WAY YOU MOVE

Don’t think that you can tell a lot from minimal points of motion data? Let’s take a look.

https://www.biomotionlab.ca/Demos/BMLwalker.html

8 of 20

STEP TWO

Eye Tracking

  • Record all eye movements
  • Take pictures of the user’s eyes
  • Create detailed heat maps recording what users looked at, when.

9 of 20

STEPS THREE, FOUR AND FIVE

  • Figure out what I want to know about you, and then create content accordingly.
  • Make sure to tie this to your real world identity – the more data points, the better.
  • Collect and save all data, and then process it using Machine Learning.

10 of 20

“I DON’T HAVE ANYTHING TO HIDE”

So what’s the big deal?

11 of 20

NOTHING TO HIDE?

  • With my Big Brother headset, I can potentially know
    • Your blood pressure and heart rate
    • Whether you have cancer or aids
    • If you suffer from any kind of motor or general physical disability
    • If you’re pregnant
    • If you are at risk for heart attack, stroke, or diabetes
    • Your sexuality
    • Your political or religious beliefs
    • Anything that’s around you – the inside of your house, housemates.
    • What you’re thinking
    • What you’re going to do, before you do it.

12 of 20

NOTHING TO FEAR?

  • Even if I know all those things, what is there to fear?
    • Credit scores dropping
    • Health and life insurance rates skyrocketing
    • Targeted Media and advertising
    • Direct manipulation of your actions
    • Potential loss of security due to breaches which include your biometric data such as gait and retinal patterns.
    • Loss of freedom to act as you want to, anonymously.

13 of 20

FREEDOM TO ACT

Be someone you aren’t,

Somewhere you can’t be,

With other people

[Ralph Koster]

14 of 20

ANONYMITY AND PII

  • Many of the consequences of reduced privacy and increased monitoring go away if you can be truly anonymous.
  • Personally Identifiable Information tied to other data is the biggest risk - once my real name is tied to that data, I lose all control over what can be done with it.
  • For companies who collect data, collecting only the minimum necessary for a specific goal, and never tying that data to PII is key.

15 of 20

STILL DON’T CARE?

We could collect all this data on your children, too.

HIPAA and COPPA laws should apply to all VR and AR data collected where relevant.

Privacy laws should be expanded to cover all data potentially collected by VR and AR systems.

16 of 20

I COULD BE YOU.

17 of 20

NOW I’M REALLY BUMMED/SCARED

It’s not all bad news.

18 of 20

WE COULD DO GOOD, TOO.

  • With the potential power of VR and AR and massive data collection we could potentially
    • Catch some health problems at early stages and warn the users
    • Understand mental health problems with far greater precision than current systems allow.
    • Use VR or AR to help alleviate sufferers of mental health problems.
    • Improve our ability to educate everyone
    • Solve social issues and problems.
    • Provide locked-in or paralyzed patients with high fidelity ways to communicate and experience virtual worlds.
    • Create unique, custom experiences allowing us to hack our own brains for positive outcomes.

19 of 20

WHAT NOW?

  • Your choices right now as a user
    • Ask questions.
    • Use systems and software which disclose clearly what data they are collecting and using and how.
    • Talk about your privacy and why it is important to you. A lot.
  • Your choices right now as a developer
    • Ask questions
    • Design systems which only collect the data you need for an outcome, and securely dispose of that data when the outcome is achieved.
    • Talk to your companies about Privacy and why it’s really important to get this right.
    • Give users choices about the data they share, rather than Terms and Conditions they will never read.

��

20 of 20

THANKS FOR ATTENDING!�QUESTIONS?

Ping me on twitter @inannamute

Suzanne Leibrick