Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

111–120 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#111
post #108

One regulation i would like to see is some auditory fingerprint in an AI voice where any person can immediately recognize their speaking to a clanker but it's not unpleasant. It should be illegal to "impersonate" a human voice.

That ship has sailed, no? Plenty of code for voice generation out there already, you'd basically have to ban general computing.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#112
Everyone suffers from this, not just the scam victims. I opened a bank account for a new business this year, and the friction for doing perfectly normal things was ridiculous due to the bank’s paranoia about scams. I couldn’t even make an initial deposit from my previous business, or transfer money to my personal account, without triggering a fraud alert and freezing the entire account (couldn’t even log into the bank website) until I could call and verify that it really was me on both ends of the transaction.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#113
Arrange a secret phrase in advance- ideally generated randomly. Stick it up on the wall of the aging parent or grandparent- maybe in the bedroom, where guests are unlikely to go. Make it innocuous-looking (hidden in plain sight). Require that phrase to be said to prove identity. Reset it if it ever gets used on a call legitimately.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#114

One reasonably effective defense: "Okay, let me call you right back." Yes, there's always the whole "my phone is dead, I borrowed someone else's" or "I'm calling from a jail payphone", so I think it might become common practice to start making authentication phrases or "tell me something only we know". Another pillar of basic trust that's being eroded on an industrial scale. Sigh.

I mostly answer unknown calls with monotone "hello" and then wait for their introduction before talking normally.

I answer with silence. I wait for them to speak first. Not even once has a scammer ever spoken first. I say nothing, they say nothing for a full minute before they hang up.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#115
post #27

Earlier quoted context omitted.

Yet all of this can be easily defeated with soft language. The basic check "what's the password/verification word" will defeat this every time. This is basically opsec that we taught my grandparents, who were in their 90s. Its doable.

So they trick the kid out of the password first by calling them and pretending to be the parent.

How is that possible?

The procedure is:

1. Kid tells password to parent in person. 2. From then on: when kid calls parent, if kid requests anything sensitive, parent ask for the password, and kid must provide it. 3. Password is never mentioned over the phone in any other situation.

How would anyone be able to extract the password from the kid?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#116
post #50

Earlier quoted context omitted.

A few years back, I would talk with scammers for a while to waste their time. Now I don't. LPT: Please have a codeword or phrase that you use with your loved ones so even if the scammers use your voice, they won't know the phrase.

> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”

They might actually be a bit stupid, but maybe they'll do it if you tell them it's because you are worried that you would fall for a scammer impersonating them. That at least would let them keep their stupid pride.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#117
post #108

One regulation i would like to see is some auditory fingerprint in an AI voice where any person can immediately recognize their speaking to a clanker but it's not unpleasant. It should be illegal to "impersonate" a human voice.

These scammers are breaking the law already, why would breaking yet another law matter to them?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#118
post #41

Earlier quoted context omitted.

I remember my JROTC instructor also running into that and how she said afterwards they have a secret phrase between them two as a way of verifying it's truly them.

It's very, very hard for untrained people to be strict about verifying any secret phrase. The attacker can make all kinds of excuses, while creating urgency, and many people quickly abandon verifying the phrase. A scene in One Battle After Another comes to mind.

Scammers can also trick the victim into reversing the roles and telling password to scammer. Even banks ocassionaly get this wrong. I have had my bank call me and ask me to read numbers from number card. If a trained bank employee following a script designed by (hopefully) an expert cant get it right, the chance of elderly relative spotting mistakes in protocol is close to 0.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#119
post #50

Earlier quoted context omitted.

A few years back, I would talk with scammers for a while to waste their time. Now I don't. LPT: Please have a codeword or phrase that you use with your loved ones so even if the scammers use your voice, they won't know the phrase.

> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”

The article makes a point of explaining how the world-renowned expert on identifying deepfake scams can no longer pass his own tests.

If an expert can't distinguish, it has absolutely nothing to do with being "stupid" or not. So send them that, maybe.

If they are still stubborn about it, then thank them for contributing to the future funding of Scam the World With AI.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#120
post #53

What’s terrible is each time I am forced to call the bank, the more they try to tell me voice ID is secure and want me to provide my voice to authenticate. Never. Did ya’ll never play Uplink? With voice cloning as good as it is now, there’s no way a voice ID is secure enough for authentication.

My voice is my passport. (never heard of anyone actually using that in real life, sounds uttery insane)

Vanguard keeps pushing it. https://duckduckgo.com/?q=vanguard+voice+verification
Post reply on HN