Live data from Hacker News

4TB of voice samples just stolen from 40k AI contractors at Mercor

app.oravys.com

81–90 of 250 posts

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#81
post #44

> If you were a Mercor contractor and you believe your voice may already be in circulation, ORAVYS will analyze the first three suspect samples free of charge. Awesome, if you're a victim of an AI company having your voice, you can help yourself by sending another AI company your voice! > Audio is never used to train commercial models without explicit consent I'm sure Mercor has explicit consent as well, legal teams…

Has your identity been stolen? Try our free credit monitoring for a month! Selling the solution to the problem you caused ought to be illegal.

This would eliminate the credit report, monitoring and fixing industry, which would be a good thing.

Court records are public in the US. If creditors want to know if you’ve been in financial trouble, they should check for bankruptcies and lawsuits, not the extrajudicial version of those that the credit reporting companies run based on hearsay.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#82

So, they should all just rotate their voices ... right? I jest but the majority of the "normal" people I know are happy to hand over biometrics because _it's easier_. We need to start branding biometrics as "forever passwords" or something to help people understand just what they're handing over when they validate access to their checking account or enter Disney World or whatever else.

Functionally, biometrics are closer to a username than a password.

Fingerprints, DNA, iris scans, gait patterns, etc. are all something you can't change (much like a permanent account ID) and are constantly being presented to the world (much like an email address). In addition under US law, police can compel presentation of fingerprints, but passwords are protected under the 5th amendment.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#84
post #3

The only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies. Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.

The only winning move is not to play.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#85
post #3

The only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies. Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.

Seems a bit like blaming the victim? Your voice (like DNA) is kind of ambient data that's hard to hide.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#86

Mercor is the most scummy company out there, run by a bunch of sleazeball 20 somethings who are getting a lot of press as the youngest billionaires in the making. Can't wait for them to crash and burn.

30 under 30 doing 10 to 20 candidates right there.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#87
Isn’t this going to immediately become daily news?

Half the time I call a company they say “we are recording your voice for security / authentication purposes”.

The companies that do that have all the information on me that they require for me to set up an account, so their data breaches will be just like this one, but 1000x larger.

Can we just fast forward through the part where this works for ID theft, past the firefox age verification plugin that uses these datasets, and even through the part where people in the plugin dataset are digital outcasts (this voice has been used too many times. Want to try another?)

At the end of this dark predictable tunnel, maybe there will be a ban on biometrics for important stuff, a repeal of the age verification laws, and actual privacy legislation with teeth.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#88
post #28
post #2

Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insuranc…

Interesting - thanks for the rabbit hole today. ;) Mercer hasn't released many public statements over the incident. Social media posts aren't necessarily public; but I did find this breach notification sample filed with CA - https://oag.ca.gov/ecrime/databreach/reports/sb24-621099 . I guess we'll see if our legislators finally take data privacy seriously.

Didn't this happen three weeks ago?

Mercor has definitely released statements with boilerplate "investigations are underway."

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#89
I'm pretty sure Google and Apple already have some decent examples of a LOT of people's voices in concert with other data collation. Google Voice IIRC was bought for audio sampling voicemail in the first place. Not sure if Apple has done similar, but would be more surprised if they didn't... Let alone the voice search options for both.
Post reply on HN