Earlier quoted context omitted.
That's a great idea. What do you use as your family password?
Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******
The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
151–160 of 255 posts
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#152Earlier quoted context omitted.
Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******
********* Oh yeah! Neat.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#153Earlier quoted context omitted.
That's a great idea. What do you use as your family password?
Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#154What’s terrible is each time I am forced to call the bank, the more they try to tell me voice ID is secure and want me to provide my voice to authenticate. Never. Did ya’ll never play Uplink? With voice cloning as good as it is now, there’s no way a voice ID is secure enough for authentication.
We really need to get to the point where any legally-binding digital authentication MUST be rooted in an in-person identity-proofing and authenticator binding ritual. Something you perform in front of a trained official, where physical inspection and local demonstration/activation of the authenticator is possible. This should be the basic standard to associate digital authenticators used in KYC legal and financial scenarios. The outcome should be some kind of standard digitally-signed certificate which can then be presented to KYC-compliant vendors to link the authenticator to a legal identity when establishing or maintaining financial accounts and records.
Perhaps there could be tiered certificates, where a high-stakes one would require this to be done in a secure facility where you expose yourself to risk of immediate arrest if presenting falsifiable identity claims. A more typical and decentralized version might be an upgrade of the notary public system in the US. Some kind of public digital ledger should record these certifications as well as revocations done by complementary rituals.
For social or informal accounts without KYC goals, some of this same machinery could be adopted. Simply modify or downgrade the identity-proofing part of the ritual as appropriate. This could link into other strategies like PGP web-of-trust or lesser kinds of identifiers like possession of phone numbers, email addresses, etc.
There would need to be criminal liability for officials misbehaving and certifying such identity and authenticator bindings without performing the requisite identity-proofing procedures.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#155Earlier quoted context omitted.
The only solution? Answer the phone in an over the top comedy accent, such as Simpsons characters, or just whatever comes to mind.
A terse, altered "Hello" is all I say. Sometimes I don't say anything. Most humans would wait a few seconds then prompt with "...Hello?", whereas bots tend to hang up after ~2s silence
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#156Earlier quoted context omitted.
That's a great idea. What do you use as your family password?
Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#157Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#158Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…
And it likely requires working with other people, your "employees", who are both a liability, and a cost.
With AI, you can make a thousand calls in parallel, for significantly cheaper, out of your own basement.
This greases the wheels of voice fraud like a gatling gun greases the wheels of hitting a guy with a rock.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#159Earlier quoted context omitted.
I'm getting a lot of calls recently and don't give them more than a Hello and whatever music, radio show or Tour de France broadcast I'm listening to. Sometimes they hang in there for half a minute.
Sometimes if I’m suspicious about the number now, I just answer and say nothing. A human will get confused after 5 seconds and say “Hello?Hello??” But the very shitty bots that usually call, just wait patiently for a long time for your hello, and don’t seem at all fazed by it.
Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
#160So, you answer your phone to the scam and… now they have your voice too. Talking on the phone is now an unmitigated liability.
I somewhere read about a service that would use AI generated voices to combat these scam calls, basically talking to the forever. Forgot the name though...