Live data from Hacker News

The golden age of scammers: AI-powered phishing

mailgun.com

91–100 of 143 posts

Re: The golden age of scammers: AI-powered phishing

#91
post #87
post #75

I'm kind of amazed how slow 'AI phishing' has been to roll out. The technology for customised text based attacks at scale has been available at least since Llama was open sourced. The tech for custom voice and image based attacks is basically there too with whisper / tortoise and stable diffusion - though clearly more expensive to render. I'm honestly not sure why social networks aren't being leveraged more to target…

Forgive my ignorance, but why are we surprised that voice messages aren't being spoofed more often? Doesn't this require a pretty darn decent dataset for training? Unless they've got a ton of videos of themselves shared on a public social media profile, I don't know that this is going to be a thing.

The dataset you need to train in the first place is indeed huge, but I think the idea is once them model is trained, new "voices" can be acquired with much less data than was required to train it in the first place. Just like you can instruct ChatGPT to talk about topics never heard of on the internet and in a dialect you customize and invent on the spot and it can comply, despite not consuming an internet's worth of subject matter about it.

Re: The golden age of scammers: AI-powered phishing

#92
post #87
post #75

I'm kind of amazed how slow 'AI phishing' has been to roll out. The technology for customised text based attacks at scale has been available at least since Llama was open sourced. The tech for custom voice and image based attacks is basically there too with whisper / tortoise and stable diffusion - though clearly more expensive to render. I'm honestly not sure why social networks aren't being leveraged more to target…

Forgive my ignorance, but why are we surprised that voice messages aren't being spoofed more often? Doesn't this require a pretty darn decent dataset for training? Unless they've got a ton of videos of themselves shared on a public social media profile, I don't know that this is going to be a thing.

> Unless they've got a ton of videos of themselves shared on a public social media profile, I don't know that this is going to be a thing.

That sounds like a great recipe for spear phishing public figures.

Re: The golden age of scammers: AI-powered phishing

#93

Earlier quoted context omitted.

Also the URL "security scanner" things on corporate email systems. The user can't see the URL by hovering over it.

I was about to complain about this. I take security training to inspect URLs and then Microsoft safe link or whatever it's called gives me a twenty line long URL filled with random characters. I have to trust it works since they took my manual inspection ability away.

i am fairly certain that whole thing is about tracking and not security. If it was about security, then they could still include the real URL in the "safeurl" url. They do not do this though, because it is not about safety, it is about data.

Re: The golden age of scammers: AI-powered phishing

#94

Earlier quoted context omitted.

They shut them down pretty much right away, but they pop back up right away too. And they usually viewbot to the top of the front page. Seems like a fairly simple thing to solve though, limit ages of accounts needed to be featured etc

I wouldn't be surprised if alot of the viewbots are using the same pool of IP addresses. Blocking VPNs, VPSes, tor, and ranges with large amounts of bans would probably help. On the other hand, twitch keeps firing employees, so they probably just ban the stream account every 20 minutes because they don't have the manpower.

does twitch auto-generate subtitles? just mine what is being transcribed for signs of being likely to be a scam.

Re: The golden age of scammers: AI-powered phishing

#95
post #75

I'm kind of amazed how slow 'AI phishing' has been to roll out. The technology for customised text based attacks at scale has been available at least since Llama was open sourced. The tech for custom voice and image based attacks is basically there too with whisper / tortoise and stable diffusion - though clearly more expensive to render. I'm honestly not sure why social networks aren't being leveraged more to target…

It appears that criminals really are stupid, and thank goodness for it!

Most people are criminals. Speeding, piracy, dubious porn, and so on. In a wider sense consumption of products or other use of criminally exploited labour.

At the same time, most people are more clever than one tends to expect.

Re: The golden age of scammers: AI-powered phishing

#96
post #29

Earlier quoted context omitted.

Scanning your digital ID card would be a start, but oHnO that's cOmmUniSM!

Wouldn't this just result in my digitalid getting lost in the next equifax breech?

Did your credit card get lost in the last one?

Re: The golden age of scammers: AI-powered phishing

#97
post #89
post #75

I'm kind of amazed how slow 'AI phishing' has been to roll out. The technology for customised text based attacks at scale has been available at least since Llama was open sourced. The tech for custom voice and image based attacks is basically there too with whisper / tortoise and stable diffusion - though clearly more expensive to render. I'm honestly not sure why social networks aren't being leveraged more to target…

It’s not enough for the method to be possible, it has to be economical. If it’s not prevalent yet it means one of two things: (1) cheaper methods work too well for now to even bother with sophisticated approaches (2) it’s too expensive to be worth the effort It would be interesting to plot out the cost of an integrated AI stack for this over time.

>(1) cheaper methods work too well for now to even bother with sophisticated approaches

Pig butchering scams uses all forms of kidnapping, human trafficking, and slave labor

Re: The golden age of scammers: AI-powered phishing

#99
post #77

Earlier quoted context omitted.

> Tbh the browser/email client makers are complicit in these phishing attempts for hiding the URLs and the actual email addresses. It's worse. Research "Scamicry". Big business now is so fake, such a grift, drenched in PR deception, and lacking integrity and trustworthiness, there isn't much space left between what is "legitimate" and what is a scam. If businesses like Google or Facebook hide URLs and email addresses…

I beat that drum so long it turned into beating my head against a wall. The last two companies I worked for insisted that customer account security was the highest priority, but as soon as I said we needed to stop hiding links to our own website behind Hubspot tracking URLs so we don't train our customers to click links that look like gobbledygook garbage, the marketing team melted down and it became clear where user…

People realize the risk, they just think it can't happen to them personally, and/or just don't care because they personally aren't going to bear the risk. People run businesses the way they drive their cars, i.e. selfishly and arrogantly.

Re: The golden age of scammers: AI-powered phishing

#100
post #6

Earlier quoted context omitted.

I mean, the mere existence of said biometrics imply that they're inferrable and thus bad security, like basically all biometrics

basically everything that retains the same structure between two occurrences can be inferred. Only randomness cannot be inferred. But true randomness is not useful for determining if you are who you say you are.

Even a password can be changed if there's a compromise. Biometrics are bad because they can be imitated, but not changed. A breach is permanent
Post reply on HN