Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

11–20 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#11

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

The example in the article says the police took her phone. Then her "attorney" gets on to talk instead. Yes, having a secret code is probably the right answer. My wife's family always has, but mine doesn't. I suppose we should probably fix that.

For extra security against these text-to-speech model zero-shot clones, you might also want to use made-up gibberish words for which the pronunciation can't be reliably inferred from the spelling

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#12

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

We're gonna need two-way passwords for conversations.

Fun.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#14

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

In practice this often doesn't work.

Article said the imposter in this case claimed her phone had been confiscated.

Fraudsters tend to also plan things such that the impersonated person can't be reached by phone at that time, either by choosing a time when they somehow know they're unavailable (e.g. impersonated person posted on social media they're boarding a plane) or in one case (12 years ago though) my SIL's parent's landline was bombarded with spam calls until they decided to leave the phone off the hook at which point the scammers phoned bank who couldn't reach the parents on their main line, of course this was the bank's problem (and there was probably an inside person facilitating) so they got their money back, but still a major inconvenience for the victim.

Probably the only sure advice is to be exceptionally wary of phone calls with supposed extreme time pressures to send the money now.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#15

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

our family has had a special 'code word' we have had since the kids were in elementary school. If someone ever needed to pick up our kids from school (they never did) our kids were taught to ask for that word.

This is a good reminder that we should review that, since its been 10 years or so.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#16

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

me and my wife made up a word in 2024 for this. the word doesn't exist in any language. we say it to each other all the time. even if i give you the spelling for it, you will say it wrong. i recommend everyone to do something similar. i should do it with my parents too.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#18
post #8

Earlier quoted context omitted.

I mostly answer unknown calls with monotone "hello" and then wait for their introduction before talking normally.

I mostly just don't answer them unless it seems like something that may be legit.

This is the only way to avoid validating your number for spam lists,

and receiving more.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#19

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

> Another pillar of basic trust that's being eroded on an industrial scale.

Remember, trust is like a rainforest: takes a long time to grow, provides a valuable ecosystem essential to human life, but can also be burned down for a quick profit.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#20
The problem described in the article is unsolvable, given that a mid-range desktop from a few years ago can easily clone a voice that's convincing enough and there are no guardrails to those. Some silly KYC laws might limit a highschool kid making deepfakes of his crush, but once a model exists it's trivial to spread it around, and for organized groups to get ahold of those. Similar will happen with images, it's just that nobody with any serious money bothered releasing image gen models that compete with gemini or chatgpt -- but it's just a question of time. A year or three, what difference does it really make?

As the cost goes down to near-zero you can scale it up almost infinitely, especially if the profits are high enough to get some smart people working on the problem, which going by the article is already the case ("INTERPOL's finding that AI-enhanced fraud is four and a half times more profitable than the traditional kind"; incidents rose by 26% last year). If AI does succeed on mutilating white collar work enough there will be a large supply of knowledge workers that might just join International Scam Co. rather than have their families go homeless. Drowning man clutching at straw and all.

So if technologically it's impossible to prevent and societally it's impossible to prevent (like the attorney that got pwned same as the grandma), I'm not sure if there exists an answer that isn't worse than the thing it's supposed to prevent. I suppose we'll soon be in a situation where nothing we don't directly perceive in real life is provably true. That journalism and media in general seem to be in a deep crisis of trustworthiness means that you won't even get the benefit of the chain-of-trust as a proxy for whether something is or isn't real.

Ignoring everything happening outside of your immediate surroundings is a choice, and probably even good for people's mental health, but my gut feeling is that it does make humanity as a whole dumber and disempowered. What does corruption matter if nobody cares, or even hears about it? It was AI generated by $current_enemy anyway; nothing to see here, citizen.

Post reply on HN