TL;DR
Facial recognition technology uses algorithms to match a captured image of a person's face against a stored database to confirm identity. It is used across industries from law enforcement to healthcare and online security, but carries real risks including biased datasets, privacy violations, and potential for misidentification. Users can take steps to protect themselves by opting out of tagging features, supporting privacy legislation, and securing their personal data.
What is facial recognition technology?
Facial recognition software compares two images that include a person's face. One is relatively recent, and the other resides within a database. Algorithms attempt to make a "match" between the two. When it's successful, face recognition software could determine a person's identity from a photo.
Facial recognition software typically relies on three steps:
- Capture: A camera collects your image. Sometimes you initiate the photo (by looking into your phone's camera, for example), but your photo could be taken without your knowledge.
- Modification: Face recognition software measures the width of your eyes, the relation of your eyes to your mouth, and other core features. All of that information is transformed into a digital signature.
- Search: Your digital signature is compared to thousands of data points within the algorithm. If the system already knows you, a match is made. The system may also deliver several potential matches, ranked by probability.
A real-world example of facial recognition in action
Police were looking for a man wanted in connection with a child abuse case. They had an image of the person, but they didn't know where he was at the moment. A company with a database of 3 billion images stepped in to help. They uncovered a photograph showing the man standing deep in the background. His image was tiny (about half the width of a fingernail). But it was enough for a positive identification.
Which industries use facial recognition software?
We often associate facial recognition software with law enforcement. Police officers use it to spot and apprehend suspects, and photos provide a valid avenue for arrests. But your image could be used in many other ways.
These are other industries that also use facial recognition:
| Sector | Description |
| Healthcare | Hospitals and clinics could use your image to help you check in or check out of care. You'll get the treatments you need with less paperwork. But some health systems are also experimenting with facial recognition to spot their clients doing unsafe things, such as smoking or skipping their medication doses. |
| Marketing | Some membership-based organizations, such as gyms, use facial recognition to distinguish frequent users from lapsed customers. |
| Online security | Your phone may unlock after you peer into the camera, and it may remain locked if a thief tries the same technique. Some databases work in the same manner. |
| Physical security | Your company may have a photographic database of all authorized personnel. If someone unusual appears in an image, the system alerts the staff. |
| Social media | Companies like Facebook allow users to "tag" their friends in photos. The information could be used to tailor online experiences based on where the person likes to go and whom the person is seen with. |
| Travel | Your mugshot could place you on a no-fly list. If you attempt to board an airplane, the authorities will know. |
As facial recognition software grows more ubiquitous, this industry list may grow.
What are the drawbacks of facial recognition?
Facial recognition could keep unauthorized or criminal activity in check. But it's not a perfect form of security.
How biased data leads to misidentification
The software relies on a database of images, and it's only as accurate as the data it's fed. If the dataset includes mostly white, male people, the system will struggle to correctly identify women and minorities. This could lead to false-positive identifications and unfair arrests.
How facial recognition can violate your privacy
The system could also violate your privacy. Most of us expect a degree of anonymity when we're moving through our daily lives. If a system is always photographing us and keeping track of where we go, that could be seen as a violation of trust.
How can you opt out of facial recognition?
You can't trademark your face and keep companies from photographing you. But there are steps you can take if you're concerned about privacy.
Try these three steps:
- Opt out when you can. Don't allow Facebook to automatically tag your photos. Don't allow Google to do the same. If you're given the chance to keep your face out of a database, take advantage.
- Pay attention at the voting booth. Some local legislators are fighting back against surveillance, and they're not allowing the technology to creep into everyday life. If you agree with this stance, find a candidate who supports privacy protections.
- Safeguard your privacy. Ensure that your system security protects you from intrusion. Don't allow people to dig into photos you'd like to keep private.
How Okta uses facial recognition for security
Facial recognition does have some benefits. For example, at Okta, we help customers deploy multi-factor authentication. Sometimes, that means we advise them to ask their employees to show their faces before they can access sensitive information. Follow the steps we've outlined above to keep your face safe.
Frequently asked questions
How does facial recognition software identify a person?
Facial recognition works in three stages: first, a camera captures an image of a person's face; second, the software measures key facial features (such as eye width and the spatial relationship between facial landmarks) and converts them into a digital signature; third, that signature is compared against a database of stored images to find a match.
What industries use facial recognition technology?
Facial recognition is used across a wide range of industries, including law enforcement, healthcare, marketing, online and physical security, social media, and travel. Each industry applies the technology differently — from helping patients check in at hospitals to flagging unauthorized individuals in secure facilities.
What are the main risks of facial recognition?
The two primary risks are accuracy and privacy. Systems trained on datasets that skew toward white, male subjects tend to misidentify women and minorities, which can lead to wrongful arrests. Additionally, continuous image capture in public spaces can erode the reasonable expectation of anonymity that most people hold in their daily lives.
Can you prevent your face from being added to a recognition database?
You cannot legally trademark your face to block all photography, but you can take practical steps: opt out of auto-tagging features on platforms like Facebook and Google, support local legislators who advocate for surveillance restrictions, and tighten your personal privacy settings to limit access to your photos.
How is facial recognition used in online security?
In online security contexts, facial recognition can serve as an authentication factor — for example, a smartphone may only unlock when it recognizes the registered owner's face. Organizations can also use it as part of multi-factor authentication to verify employee identity before granting access to sensitive systems.
Is facial recognition the same as multi-factor authentication?
No, but facial recognition can be one component of multi-factor authentication (MFA). MFA requires users to verify their identity through more than one method. Facial recognition serves as a biometric factor within that framework, adding a layer of security beyond passwords or tokens.
References
What if Facial Recognition Technology Were in Everyone's Hands? (August 2021). Slate.
Facial Recognition Is Everywhere. Here's What We Can Do About It. (July 2020). The New York Times.
Why Ubiquitous Facial Recognition Tech Is a Game Changer. (August 2018). TechRepublic.
As Facial Recognition Software Becomes More Ubiquitous, Some Governments Slam On the Brakes. (September 2019). ABA Journal.