Technology

How Reverse Face Search Works

How Reverse Face Search Works

Wired reported that a reverse-lookup service left millions of people’s face photographs exposed. The specifics belong to their reporting. What is worth understanding, and what nobody explains, is how a service like that comes to hold your face at all when you never signed up for anything.

It is not matching pictures

The intuitive assumption is that a face search compares your photo against stored photos. It does not, and could not: comparing one image against billions would take far too long.

Instead, a neural network converts each face into a list of numbers, typically 128 or 512 of them, called an embedding or faceprint. The network is trained so that two photographs of the same person produce numbers that sit close together, while different people sit far apart. Lighting, angle, age and expression change the picture enormously but move the numbers only slightly.

Searching is then a geometry problem rather than an image problem: find the stored points nearest this one. That runs in milliseconds across billions of records.

This has an important consequence. The original photograph does not need to be kept. A service can discard every image and retain only the numbers, and still identify you from a new photo years later.

Where the faces come from

Almost entirely from scraping the public web. Social profiles set to public, company staff pages, news photographs, university directories, club and society listings, wedding galleries, conference speaker pages.

You do not have to have posted anything. Being in the background of someone else’s public photo is sufficient, because the system detects every face in an image, not just the subject.

This is why people find themselves in these databases having never used the platform involved. Consent was never part of the collection step.

Why the numbers are the problem

A leaked password can be changed. A leaked card can be cancelled. A faceprint is derived from a face you cannot replace.

Worse, embeddings are portable. A leaked set of numbers can be loaded into somebody else’s system and matched against their own collection, because the underlying models are similar enough that the geometry broadly transfers. The data outlives the company that gathered it.

Deleting your public photographs does not undo it either. If the faceprint was computed two years ago, removing the source image today changes nothing.

What you can actually do

  • Search for yourself. Several face search engines let you upload a photo and see what is indexed. Uninformative until you try it, and often startling.
  • Use the removal process. Most such services have one, because data protection law in the UK, the EU and several US states requires it. Biometric data is a special category under the GDPR and carries stronger rights than ordinary personal data.
  • Send a deletion request in writing and keep a copy. Regulators act on documented refusals, not on complaints about a form.
  • Set old accounts to private rather than deleting them. A deleted profile stops you monitoring what is still out there.
  • Ask to be untagged in public group photos. It does not remove the face, but it breaks the link between face and name, which is what makes a match useful.

The realistic assessment

If you have had a public online presence for more than a few years, your face is almost certainly in several of these systems already, and full removal is not achievable. That is an unsatisfying answer but it is the true one.

What is achievable is limiting future collection and exercising the rights you do have. Make new photographs private by default, be deliberate about which images carry your full name beside them, and submit removal requests to the services you can identify.

The broader point is one worth carrying into other decisions: biometric data is the category where a breach cannot be remediated. Every time something offers to scan your face for convenience, that is the trade being made.

Join the discussion

Held for review before it appears. Links are not allowed and your email is never published.