Live data from Hacker News

4TB of voice samples just stolen from 40k AI contractors at Mercor

app.oravys.com

211–220 of 250 posts

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#211

Earlier quoted context omitted.

Data can never be stolen, because it is not a physical thing. Data can be copied, and it can be erased - sometimes both happens at the same time. Data can be lost, that is when its last existing copy was erased.

pedantic and true. What was stolen was not data, but future revenue based on exclusive access to that data.

Pedantic and relevant. If they lost the voice samples, they wouldn't have it for training new models. If they were copied, then they have lost nothing in terms of training.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#212
post #201

Earlier quoted context omitted.

> Self-audit your public audio footprint. Search YouTube, podcast directories, and old Zoom recording This is suggestion #1 on your list of remediation steps for victims, but you didn't provide any information on how anyone would actually do that. How exactly would I search the internet for copies of my voice? Please don't tell me the solution is giving an embedding of my voice to another third party.

Great question. There's no "reverse voice search" yet the way there is for images — that's genuinely a tool the world needs. In the meantime, the most useful thing is searching your name across YouTube and podcast platforms to map out what's already public. And for Mercor contractors specifically, the California AG breach notice gives you a solid legal basis to request full deletion. Worth doing today.

Note, this comment and your other one (https://news.ycombinator.com/item?id=47931838) were autokilled by HN, because it (rightly) detected that you're using AI to write your comments. I vouched this one to unkill it before I realized it was AI and supposed to be dead. I unvouched it, but your comment's still alive. So now I'm leaving a note saying mea culpa, and to suggest not using AI in your comments unless you want to be autokilled.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#213

Earlier quoted context omitted.

Biometrics are "what you are", not "what you know" or "what you have". Voice fingeprinting is essentially useless because it is easily recorded and reproduced.

I have been telling people for years that biometrics (face, fingerprint, voice) is your username, not your password. But people are easily swayed by convenience.

If your user name is tattooed on your forehead, yes.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#214

Earlier quoted context omitted.

I probably agree with you but what on earth are phones and cars doing in this list? They solve obvious physical problems not caused by a company.

My interpretation would be that cars are necessary to live in places where urban design assumes that we'll use cars to get around. Many cities are designed this way. Similarly, phones are required now for some activities, like online banking. First it was an option, then it became the norm.

Exactly.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#215

Earlier quoted context omitted.

just take up smoking heavily

Despite popular belief, even heavy smoking does not alter your voice in a significant way.

Do you have a source for that? I can tell with pretty good accuracy whether my students smoke from their voices (adult language learners, we take smoke breaks together and they have no reason to conceal it), and would be very surprised if I’m just that lucky and there’s nothing a person can pick up on acoustically.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#216
If you had a company, why not just tell all customers that their data is save but don't waste any money on security at all: in case of a breach, just write an apology email to your clients, promise a full investigation, and move on.

Obviously, you don't have to face any legal consequences, so why worry?

Sorry for the rant... but I just find this lack of liability frustrating.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#217
post #2

Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insuranc…

HSBC offered voice verification years ago and I just laughed and said nope. I don’t even use biometrics on apple devices, I use a 6 digit pin. It was always a stupid idea. The thing about been willing to trade convenience for security is you get called paranoid and then when the other shoe does drop and you are still doing that you still get called paranoid for the current thing you are not doing that “everyone does”…

> I don’t even use biometrics on apple devices

Assuming Apple is truthful on this matter (so far it seems so), Apple devices store a mathematical representation of the data, not the data itself (i.e. not a picture of your finger) and keep it only on device on a special hardware section designed for extra security. When apps ask for authentication, they can never inspect the data, they can only ask “does this match?”.

Even if you were somehow able to exfiltrate the data and find some way to transform it for something nefarious, you’d still need to first attack and bypass a specific hardware feature of the target’s device.

So sure, not having any representation of the data anywhere is technically more secure (maybe, as typing your code could be intercepted by a shoulder surfer or a camera), but biometrics on Apple devices are fundamentally not the same as having your raw data available on a random server somewhere.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#218

If you had a company, why not just tell all customers that their data is save but don't waste any money on security at all: in case of a breach, just write an apology email to your clients, promise a full investigation, and move on. Obviously, you don't have to face any legal consequences, so why worry? Sorry for the rant... but I just find this lack of liability frustrating.

I like this. I'm genuinely curious whether you could create a Delve [0] for security. Companies could pay for the "security review and package and dashboard" virtue signal, put an impressively secure looking logo on their site and effectively whitewash needing to do anything else. I suspect a sufficiently expensive law firm could draft the requisite legals to shield the principals SecCo from the eventual unveiling, but not before SecCo could make hundreds of millions and the rest of the industry could save hundreds of millions on their shit-as-fuck security practices anyway. Call the spade a spade.

0 - https://techcrunch.com/2026/03/22/delve-accused-of-misleadin...

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#219

Earlier quoted context omitted.

Despite popular belief, even heavy smoking does not alter your voice in a significant way.

Do you have a source for that? I can tell with pretty good accuracy whether my students smoke from their voices (adult language learners, we take smoke breaks together and they have no reason to conceal it), and would be very surprised if I’m just that lucky and there’s nothing a person can pick up on acoustically.

20 years of heavy smoking :)

Although it does seem to affect some people more than others for sure, I guess it depends how and what you're smoking.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#220
post #64
post #44

> If you were a Mercor contractor and you believe your voice may already be in circulation, ORAVYS will analyze the first three suspect samples free of charge. Awesome, if you're a victim of an AI company having your voice, you can help yourself by sending another AI company your voice! > Audio is never used to train commercial models without explicit consent I'm sure Mercor has explicit consent as well, legal teams…

Reminds me of my experience when trying to remove my Airbnb account, they require my ID card scans of both sides. I said fuck it and never touch this company again

Quickly, extract some more money from this customer and hold their data hostage!
Post reply on HN