One regulation i would like to see is some auditory fingerprint in an AI voice where any person can immediately recognize their speaking to a clanker but it's not unpleasant. It should be illegal to "impersonate" a human voice.
The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
111–120 of 255 posts
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#112Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#113Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#114One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.
I mostly answer unknown calls with monotone "hello" and then wait for their introduction before talking normally.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#115Earlier quoted context omitted.
Yet all of this can be easily defeated with soft language. The basic check "what's the password/verification word" will defeat this every time. This is basically opsec that we taught my grandparents, who were in their 90s. Its doable.
So they trick the kid out of the password first by calling them and pretending to be the parent.
The procedure is:
1. Kid tells password to parent in person. 2. From then on: when kid calls parent, if kid requests anything sensitive, parent ask for the password, and kid must provide it. 3. Password is never mentioned over the phone in any other situation.
How would anyone be able to extract the password from the kid?
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#116Earlier quoted context omitted.
A few years back, I would talk with scammers for a while to waste their time. Now I don't. LPT: Please have a codeword or phrase that you use with your loved ones so even if the scammers use your voice, they won't know the phrase.
> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#117One regulation i would like to see is some auditory fingerprint in an AI voice where any person can immediately recognize their speaking to a clanker but it's not unpleasant. It should be illegal to "impersonate" a human voice.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#118Earlier quoted context omitted.
I remember my JROTC instructor also running into that and how she said afterwards they have a secret phrase between them two as a way of verifying it's truly them.
It's very, very hard for untrained people to be strict about verifying any secret phrase. The attacker can make all kinds of excuses, while creating urgency, and many people quickly abandon verifying the phrase. A scene in One Battle After Another comes to mind.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#119Earlier quoted context omitted.
A few years back, I would talk with scammers for a while to waste their time. Now I don't. LPT: Please have a codeword or phrase that you use with your loved ones so even if the scammers use your voice, they won't know the phrase.
> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”
If an expert can't distinguish, it has absolutely nothing to do with being "stupid" or not. So send them that, maybe.
If they are still stubborn about it, then thank them for contributing to the future funding of Scam the World With AI.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#120What’s terrible is each time I am forced to call the bank, the more they try to tell me voice ID is secure and want me to provide my voice to authenticate. Never. Did ya’ll never play Uplink? With voice cloning as good as it is now, there’s no way a voice ID is secure enough for authentication.
My voice is my passport. (never heard of anyone actually using that in real life, sounds uttery insane)