HN user

kcimc

63 karma
Posts6
Comments40
View on HN

i built a small system that tracks a fixed cohort of business jets (from FAA registry data, matched via ICAO hex) and counts how many are airborne at a given time.

it ingests ADS-B exchange heatmap files (30 min intervals), backfills historical counts, and compares the current value to a baseline for similar times of day/week.

the output is a simple deviation, shown as an "emergency level".

in practice it mostly shows a strong daily cycle, with occasional spikes during holidays, or on april 6th when trump threatened "a whole civilization will die tonight".

I made a few interactive art installations last year using SDXL Turbo with a multi-GPU on-site setup. After we got a request to show a piece in Europe, I researched whether it would be possible to run the installation in the cloud instead of shipping super expensive computers. It turns out that it is doable, but there are a lot of little gotchas. I wrote about my experience developing this system, and also include links to the GitHub repository if you want to try it yourself.

super fascinating to see this comment! it gave me the chance to take a step through my memories, and try to guess who might have felt this way. if i was an asshole to you and never apologized, send me a message and i would be very happy to take responsibility <3

my impression was that apple initiated contact based on an assumption that i was running a keylogger or other information that could be used for identity theft. they quickly learned it was an art project but decided to apply force via the secret service to keep it from gaining too much publicity. after that caused a bit of a streisand effect, they decided not pursue a civil case. i would guess that the judge decided not to pursue a criminal case because it would have been an obvious waste of resources.

author here. i'm deeply, genuinely grateful that you all care enough to revisit and discuss this decade-old work. special thanks to throwayyy479087 for stirring some shit on my behalf, saving me the work of creating a sock puppet just to cast shade and spread rumors. i'd be happy to answer any questions if you have them.

sorry it took a while to get to this post. i'm literally on a beach on a remote island in fiji, working on the next project. https://unframed.lacma.org/2021/01/21/art-tech-lab-project-u...

Just want to say thanks again for the great comment. I was following Van Buren, and it was a certainly vindication. I agree with you there is a push and pull. Here's hoping that debate & discussion that needs to happen plays out in a way that puts the people first, instead of expanding protections to the government and big corps.

Wow, incredible response! I appreciate you taking the time to respond :)

I am very familiar with Aaron's case. I think your analysis is correct: some people believe I made a bad judgement call, and the CFAA is broad enough that this created a liability, even though we cannot know whether it was legal. I think my frustration with most armchair-analysis (not including you, CaptArmchair) is that folks confuse their moral certainty (I "made a bad judgement call") with legal certainty ("this is the kind of thing the CFAA protects us from"). But the law is a lot more complicated.

For me the concern is exactly (d)(1). When the CFAA is overly broad, and the ability to investigate is granted to all "offenses", where does that leave us? Can Apple cry "CFAA!" at anything they don't like? In practice, there are some checks and balances: in this case, Judge Lois Bloom decided to sign the warrant; Judge Judith Philips refused to prosecute. Is this enough? To me, seeing the ways the CFAA has been abused in other cases, it's not so clear.

Thanks for spending time thinking through some of this :)

I think it "felt like 30" because I was nervous. Not because I thought it was illegal or unethical, but because I was breaking social norms. I see this as different from acting "unethically", and closer to what Erving Goffman would call a "breaching experiment".

I definitely did not want to raise any flags in the store itself, hence the staggered exit and furtive behavior. Again, not because I thought it was illegal or unethical, but because there was a certain way I wanted to see everything play out. If I got kicked out before I had a chance to exhibit the work, it would have made for a distractingly complicated story. I think this point is difficult for some folks who can only see this as a prank or security research, and don't understand how artists think and work and craft stories.

Regarding the question of what constitutes "public space" and legality of of using peoples likenesses for profit, there are some other great responses in this thread which explain the details (like the one here by sellyme). It's interesting for me to hear how most folks on HN assume that photography in the US operates more like the EU.

OP here. Thank you for sharing this. I'm lucky in that this is the only bad knock I've had. And after a few years this effect slowly disappeared for me.

Hi, OP here. Do I know you? Thanks for your thoughts :) I would hope that anyone evaluating this project today not look at it alone, but examine it as part of a much larger body of work I've made since around that time. By itself, it was a small gesture that got overblown. In context, I like to think that it has more to offer. In case anyone is curious, see on my website https://kylemcdonald.net/ "Facework", "Vibe Check", "ICESpy", "How We Act Together", "Sharing Faces", "us+", "FaceOSC" and "Face Substitution" (now people call it "face swapping").

OP here. The only reason I wasn't charged is because AUSA Judith Philips refused to prosecute me. Also, Aaron Swartz was investigated by both the FBI and the USSS.

OP here. syshum has it correct. If you take a photo with your lens on one side of the Apple Store's massive glass wall, it is legally the same from a privacy perspective as taking a photo on the other side (unless Apple explicitly forbids it).

Hi, OP here. Just some technical clarification. There were two apps. The first one took a photo once a minute and uploaded it to a PHP script on my server. Apple probably identified this one because it sent a ping to my server even when it didn't send a photo. The second app was essentially a screensaver that regularly checked a URL to see whether it should go fullscreen or not, and then it quit after one minute. These were both custom-built apps, less than 100 loc each and missing all of the functionalities of spyware and RATs. I would expect that real RATs have been installed on Apple Store machines in the past, and perhaps Apple suspected this was another. If I had been sniffing and posting keystrokes, the situation may have turned out completely different. But this project was focused on face analysis.

Hi, OP here. Just wanted to add one point of technical clarification: it wasn't a RAT, it was a C++ app that used the QuickTime SDK to connect to the camera, OpenCV to run face detection, and curl to regularly send the results to a hacked-together PHP script that uploaded them to Tumblr. It sat in the dock while it was running, with a silver Apple logo as the icon.

OP here. Not going to disagree about folks underestimating where the real danger is. But the fear of photography is not unfounded. There are many examples of people suffering from being captured in public settings. Sometimes it is because of their behavior (every "Karen" video), sometimes it is an abuser getting a lead on their ex's location from a tagged Facebook pic. For this project I tried to make sure that I didn't "feature" anyone, so attention was diluted across thousands of photos. When I eventually exhibited the work, I worked with a watercolor artist to create paintings from the photos to further disconnect the work from the customer's identity.

OP here. Just to clarify, this piece was not primarily designed for the Apple Store audience. I felt that it was important to exhibit the photos in the store, but I knew that the majority of the folks who heard about it would see it online. In the exhibition at the store, people first saw a photo of themselves, with no knowledge that they were posted to the internet. Online, people saw photos of folks in the store. If you have spent time in a big city like NYC, you might recognize the feelings of anonymity and privacy-in-public that I was drawing on. There are certainly "I'm harming you for your own good" style art installations I've made. For example, I had a piece called "Wifi Whisperer" around 2016 that sniffed all the open wifi traffic in a cafe, and a little speaker in the corner would describe what it sniffed. https://soundcloud.com/kyle-mcdonald/whisper I still think there is a place for non-consensual art to surprise and inform, especially in the physical context of an art exhibition or festival. But I also feel this work tends towards provoking fear and anger over any more helpful reactions. And there's the constant danger that in the process of crossing a boundary of consent, or in breaking a social contract that you might do real, even irreversible harm. So instead with projects like https://facework.app/ I find ways to critique face classification, but in a way that everything happens in-browser. Sometimes it's possible to have the feeling of boundary crossing without the dangers.

OP here. Thanks for taking the time to share the (scary) connection you made while reading. While this story has been picked up by security folks, I am definitely not a security researcher :) This project did help me to think more explicitly about security, founding a NYC-based group called "artsec" where security researchers and media artists worked together. One of the members was Samy Kamkar, who you may know for the infamous "Samy is my hero" MySpace worm. His case, also investigated by the USSS, actually went to court and ended with a 3-year ban from touching a computer. This is just to say that the relationship between "art" and "research" (and even "pranks") is not always clear. I understood (and still believe) what I did was legal. It is also undeniably art. I set out to make it as art, and it has been exhibited and written about as art. You can call it bad art, you can say it's similar to a prank, but unfortunately it's still art. Whether it was ethical or not is a much more complicated question, and something that we each have to decide for ourselves. I appreciate hearing your side. Thanks.

Hi, if you have any reference on why I needed consent to install an app in the Apple Store, I would love to hear! Because the case never went to court I didn't get a chance to hear a prosecutor spell it out. And my attorney at the time was unsure how they could possibly make that case, so I didn't get it from him either. But a lot of people here in the comments seem to believe that the case is clear. I'm not sure whether it's hubris, or if my attorney just didn't have the imagination of HN ;) Thanks!

Regarding the "legal" part, having looked into this quite deeply, I believe I was legally in the clear. Both in terms of of publishing the photographs and in terms of installing the app. Keep in mind this was 2011. To install the app today would require circumventing access control policies, but not at the time. If you do have additional elaboration on why you think it was illegal, I would be happy to learn more! Thanks.

Hi, I think I can answer (I am Kyle). tl;dr: It barely worked for many years, but I have since been able to find more & larger grants for my art, and get better paying consulting work on the side. Full story—first, income. Some examples from my books around 2011: $10k for a 3-month residency in Japan, $4k for 2 weeks of 14 hour days implementing computer vision and generative graphics as part of a team developing an interactive installation, $3k for 3 weeks of generative sound design work, $500 traveling overseas to give an hour-long talk, $500 traveling overseas to lead a full-day 3d scanning workshop for artists, $50 for an art+tech blog post. Regarding expenses: At the time I was living in a one-floor, 4bd apartment with three other people, $1815 divided 4 ways, about $450. I spent a similar amount each month on food, transportation, and utilities combined. I did not have healthcare. My artwork was digital so it did not require regular material costs, and I had no studio space. Total was closer to $20-25k/year due to additional costs and because I had $170k of college loans and no financial support. All together, I was barely in the black: I had between 8-12 jobs totaling $20-40k each year, from 2010-2014. My bank account hovered between $1-4k until 2015 when I started pitching larger projects that saw more income and also allowed me to start paying others. Hope that answers your questions, happy to share more.

Thanks! I think you are correct, after the successful completion I added that statement as a safety before deleting all other previous attempts. Reading this code again it really could have used the data more efficiently to predict the correct ID faster, but if I remember correctly it didn't take very long to run so I never made another attempt.

I helped build the cover song alignment pipeline for "Infinite Bad Guy" http://billie.withyoutube.com/ an interactive music video that brings together thousands of YouTube covers of "Bad Guy" by Billie Eilish. We just published a writeup on how we built the alignment (along with some simple tricks for estimating video similarity).

We used a bidirectional LSTM with CQT and chroma as input, and predicted the original beat for every cover beat as output. There's a bunch of existing work on this from Furkan Yesiler, Dan Ellis and others, and we're super grateful to them for advising.

Super open to feedback and critique here or in the post.

This project is based on the Labeled Faces in the Wild Attributes+ dataset released with the 2015 paper Deep Learning Face Attributes in the Wild by Ziwei Liu et al. covering 73 face attributes. "Big Lips", "Bushy Eyebrows", "Double Chin", four racial groups, "Sunglasses", "Curly Hair"... We trained a MobileNetV2 network on LFWA+ categories and then used the embeddings to add a few more categories using custom datasets. This all comes together in 10 minute game that explores what it feels like to be described by the machine, and placed in some of these weird categories. All the analysis runs in-browser with TensorFlow.js on mobile and desktop, no images are sent to any server. Usually this analysis happens behind the scenes, but we wanted to create an experience where people had the chance to see it play out in realtime and build direct intuition.

Very well done, but not the first: 2 years ago Jetpac released DeepBeliefSDK (https://github.com/jetpacapp/DeepBeliefSDK). They were acquired by Google and development stopped. But the demo has been ported (http://waylonflinn.github.io/DeepBeliefSDK/) using a newer toolkit called webblas (https://github.com/waylonflinn/weblas). Reddit discussion about webblas at (https://www.reddit.com/r/MachineLearning/comments/41luif/gpu...) which has some more links and thoughts about this kind of thing. One more toolkit, written during a hackathon and still getting started, is gpu.js (https://github.com/gpujs/gpu.js/).