Skip Navigation

Your Glasses Shouldn’t Be Able to Dox Me

Putting on a pair of glasses should not be enough to identify a stranger, pull up their home address, and turn a chance encounter into a data profile. But in 2024, two Harvard students did exactly that. Using Meta’s Ray-Ban smart glasses, the facial-recognition search engine PimEyes, and public databases, they identified strangers in public and retrieved personal information, including names, workplaces, relatives, and home addresses. In several cases, they approached people and confirmed the information in conversation, all without letting the subjects know how they had been identified. 

This experiment reveals a growing gap in American privacy law: Consumer technologies now allow ordinary individuals to conduct real-time surveillance and identification, while existing legal frameworks remain focused on outdated notions of recording and consent. Unless the law evolves, smart glasses will normalize a world where public anonymity disappears—and with it, basic personal safety. 

The technology involved in the aforementioned incident was neither complicated nor restricted. Meta’s Ray-Ban smart glasses retail for around $250, and the identification tools used in the Harvard experiment are easily accessible online. What once required institutional resources can now be assembled by anyone with a few consumer products and a browser. 

That capability is also scaling rapidly. EssilorLuxottica, Meta’s manufacturing partner, reported selling more than 7 million pairs of Meta smart glasses in 2025, after smart glasses sales nearly tripled compared with the previous year. The glasses allow users to record photos and videos, livestream to Instagram, and interact with Meta’s AI assistant through voice commands. Meta is now exploring adding facial recognition, which would allow users to identify people and pull up information about them in real time. Internal memos obtained by the New York Times suggest the company knows these features would be controversial, explicitly acknowledging “safety and privacy risks.” The report indicates Meta has considered how to market and sell the technology despite those concerns—and may even seek to introduce it during periods of political tumult, when public attention and potential backlash from civil society groups are likely to be diluted.

This raises questions about whether the recording legislation in place today is equipped to address such technology. Existing recording laws focus on whether participants in a conversation consent to being recorded. Under the federal Electronic Communications Privacy Act, recording is generally legal if at least one participant consents. Some states, including California, Illinois, and Pennsylvania, require all-party consent. But these frameworks all assume that recordings involve a defined set of people engaged in a conversation.

Smart glasses disrupt that assumption. In a crowded subway car, restaurant, or classroom, wearable cameras can capture dozens of bystanders who are not part of any interaction. Their faces, voices, and behavior can be recorded (and potentially analyzed) without their knowledge. Courts have long held that people have limited expectations of privacy in public spaces, but smart glasses push that principle to its limit. Unlike smartphones, which are usually visible when recording, smart glasses can operate far more discreetly, making it nigh impossible for bystanders to know when they are being captured or to object. When combined with real-time identification tools, this presents a paradigm shift from passive documentation to immediate identification, often without the subject’s awareness or opportunity to consent.

Although it may seem like science fiction, this is already happening. In one case, a Manhattan restaurant worker later discovered that a video recorded from a customer’s Meta glasses had received more than two million views on TikTok, despite the worker not realizing he was being filmed. He later said the experience made him so uncomfortable that he stopped working front-of-house at the restaurant. Another restaurant owner noticed he was being recorded only after spotting the tiny indicator light on the glasses midway through a conversation. The problem is not just that people are being filmed in public; it is that workers and customers, who often cannot object or opt out of the interaction, can be turned into viral content without ever knowing they are on camera.

The risks go well beyond awkward viral videos. A Swedish investigation found that outsourced workers reviewing footage from Meta’s smart glasses had access to highly sensitive material, including bank details, images of people using the toilet, getting dressed, and appearing naked without knowing they were being filmed—sparking a class action lawsuit earlier this year. This means the privacy problem does not stop with the person wearing the glasses; footage can also be watched by third-party contractors far removed from the original encounter. If that footage is mishandled or leaked, it could expose people to harassment, identity theft, or nonconsensual distribution of intimate images, with little ability to trace or contain the damage once it spreads.

Smart glasses also make sexual harassment easier and harder to prevent. CNN interviewed women who said they had been secretly filmed by men using the glasses, with clips then posted online advertised as pickup artists or “rizz” content. In one case, a woman named Toluwa said a man recorded her in an airport lounge, asked for her number, and then posted the video even after she said she did not want it shared. After it went viral, strangers began recognizing her in public.

If Meta does eventually add facial recognition as a function, those harms will become even more serious. Civil liberties groups have long warned that facial recognition is not just invasive but unequal: It is more likely to misidentify people of color, and it is often used in ways that reinforce existing patterns of racial profiling and surveillance. There are obvious risks to smart glasses which let you look at a stranger and instantly see a name, workplace, or social media profile. A stranger could identify someone outside a bar, pull up their name and workplace, and follow them home, all without that person realizing what is happening. If the system gets it wrong, that person could be confronted or targeted based on a false match, with no way to correct it at the moment. What is new here is not just the technology, but the loss of any practical ability to remain anonymous in public or to contest how you are being identified.

Despite these risks, regulatory responses remain limited. Recent lawsuits against Meta focus largely on how user data is handled, rather than the broader issue of constant recording in public. The 2026 class action lawsuit surrounding Meta’s undisclosed use of third-party contractors to review highly sensitive footage centres on consumer protection, particularly whether users were adequately informed about how their data would be accessed and processed. It does not address the more fundamental issue that these devices enable continuous, and often unobtrusive, recording of people in public spaces who have neither consented to nor are even aware of being captured.

More broadly, US privacy law still treats most acts of public recording as legal. Outside a handful of state biometric laws, there are few restrictions on collecting visual data in public spaces. Illinois’ Biometric Information Privacy Act, one of the strictest laws in the country, requires companies to obtain written consent before collecting biometric data such as faceprints. But laws like this remain the exception, not the rule, and they primarily regulate how companies collect and use data, rather than how individuals might deploy these tools in everyday settings. As a result, they do little to address a scenario in which someone uses smart glasses to identify strangers in real time or record and share that footage without consent.

Existing laws also focus on narrow questions—whether a conversation was recorded with consent, or whether data was properly disclosed—rather than the larger issue these devices create: the routine collection of information about everyone nearby. Legal experts increasingly argue that current frameworks are simply not built for this kind of constant, ambient surveillance. Addressing this gap will require more than minor updates. Regulators could restrict facial recognition in consumer devices, require consent from bystanders, not just users, and limit how long this data is stored and who can access it. But the real issue runs deeper. Privacy law still treats recording as something that happens between participants, when these devices are built to capture everyone in view. 

“Big Brother” used to suggest a visible system of surveillance, something you could point to. This is now harder to see. Today it is built into an everyday object, one that blends in and moves through the world like anyone else. Changing the law may limit some uses, but it does not change how easily this kind of watching fits into ordinary life. And all it takes is a pair of glasses.

SUGGESTED ARTICLES