Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
発見する
投稿する
  • ようこそAIIDへ
  • インシデントを発見
  • 空間ビュー
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • インシデントレポートを投稿
  • 投稿ランキング
  • ブログ
  • AIニュースダイジェスト
  • リスクチェックリスト
  • おまかせ表示
  • サインアップ
閉じる
発見する
投稿する
  • ようこそAIIDへ
  • インシデントを発見
  • 空間ビュー
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • インシデントレポートを投稿
  • 投稿ランキング
  • ブログ
  • AIニュースダイジェスト
  • リスクチェックリスト
  • おまかせ表示
  • サインアップ
閉じる

レポート 1737

関連インシデント

インシデント 2231 Report
Hive Box Facial-Recognition Locks Hacked by Fourth Graders Using Intended Recipient’s Facial Photo

Loading...
Facial-Recognition Smart Lockers Hacked by Fourth-Graders
sixthtone.com · 2019

Facial-recognition locks used by a company claiming to operate the world’s largest network of express delivery lockers have been hacked by a group of fourth-graders.

The primary schoolers from Jiaxing in eastern China’s Zhejiang province told local TV program Haoqi Shiyanshi, or Curious Labs, that their science club recently discovered facial-recognition locks used by Hive Box, a Chinese smart locker company, could be opened using only a printed photo of the intended recipient’s face, leaving the lockers’ contents vulnerable to theft.

The episode’s host tests the security flaw himself and is able to replicate the kids’ findings with a nearly perfect success rate. Only when a photo wasn’t held steadily did the camera not recognize the face and open the locker. After airing Tuesday, the episode received wide attention online, prompting Hive Box to issue a statement the next day explaining that its facial-recognition feature was still in beta testing and had been suspended following the revelation of the bug.

Shenzhen-headquartered Hive Box has installed self-service pickup and drop-off stations across China in an effort to facilitate deliveries for the country’s booming logistics industry. Though a relative latecomer to smart lockers, which first emerged in China in 2012, Hive Box has outmuscled its domestic competitors and now claims to be the “world’s largest parcel machine operation company.”

Last year, 200 million people in over 100 Chinese cities retrieved 2.5 billion packages from Hive Box smart lockers, the company said, accounting for around 5% of the country’s total parcel deliveries that year. In July, Hive Box’s chief marketing officer, Li Wenqing, said the company is eyeing an initial public offering in the near future.

In response to the government’s call to turn China into a mighty nation powered by artificial intelligence, big data, and the internet of things, people and companies are increasingly embracing smart technologies aimed at making daily life more convenient. But the wide adoption and sometimes poor implementation of facial recognition in particular have given rise to privacy and security concerns.

In January, the State Administration for Market Regulation found that 15% of leading smart locks using facial-recognition technology could be opened using photographs. In March, a Sixth Tone investigation found that facial-recognition cameras were being installed in classrooms to monitor students, often without their parents’ knowledge or consent. And in September, a Chinese deepfake app called Zao that swapped users’ faces into famous scenes from movies and TV series came under fire over its collection of user data, including photos. Scrutiny of the app even prompted mobile payment giant Alipay to assure users that its “Smile to Pay” facial-recognition system could not be hacked using deepfakes.

In a previous interview, Wang Shengjin, a professor of electronic engineering at Tsinghua University, told Sixth Tone that, while some facial-recognition systems that rely on 2D mapping technology are more vulnerable and can easily be hacked using photos, the public shouldn’t worry about facial-recognition mobile payment systems — including Alipay, WeChat Pay, and Apple Pay — because their use of 3D mapping, in combination with infrared illumination and two-step verification, makes them much more secure.

情報源を読む

リサーチ

  • “AIインシデント”の定義
  • “AIインシデントレスポンス”の定義
  • データベースのロードマップ
  • 関連研究
  • 全データベースのダウンロード

プロジェクトとコミュニティ

  • AIIDについて
  • コンタクトとフォロー
  • アプリと要約
  • エディタのためのガイド

インシデント

  • 全インシデントの一覧
  • フラグの立ったインシデント
  • 登録待ち一覧
  • クラスごとの表示
  • 分類法

2024 - AI Incident Database

  • 利用規約
  • プライバシーポリシー
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • e1b50cd