Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

151–160 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#151
post #132

Earlier quoted context omitted.

That's a great idea. What do you use as your family password?

Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******

Joke's on you, now I know your password is 7 chars, but more importantly, I also know your password is not 7 stars.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#152
post #132

Earlier quoted context omitted.

Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******

********* Oh yeah! Neat.

This thread just gave me a pang of nostalgia. I think the first time I saw this interaction was in an AOL chat room, or maybe an early MUD. I miss the good old silly internet…

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#153
post #132

Earlier quoted context omitted.

That's a great idea. What do you use as your family password?

Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******

hunter2 my hunter2!

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#154

What’s terrible is each time I am forced to call the bank, the more they try to tell me voice ID is secure and want me to provide my voice to authenticate. Never. Did ya’ll never play Uplink? With voice cloning as good as it is now, there’s no way a voice ID is secure enough for authentication.

I find so many of these things utterly insane. Much like the way a fax of a signed document is considered legally meaningful. I think we have to stop pretending any kind of digital media presentation of a document, face, voice, etc. can be authenticated by its content.

We really need to get to the point where any legally-binding digital authentication MUST be rooted in an in-person identity-proofing and authenticator binding ritual. Something you perform in front of a trained official, where physical inspection and local demonstration/activation of the authenticator is possible. This should be the basic standard to associate digital authenticators used in KYC legal and financial scenarios. The outcome should be some kind of standard digitally-signed certificate which can then be presented to KYC-compliant vendors to link the authenticator to a legal identity when establishing or maintaining financial accounts and records.

Perhaps there could be tiered certificates, where a high-stakes one would require this to be done in a secure facility where you expose yourself to risk of immediate arrest if presenting falsifiable identity claims. A more typical and decentralized version might be an upgrade of the notary public system in the US. Some kind of public digital ledger should record these certifications as well as revocations done by complementary rituals.

For social or informal accounts without KYC goals, some of this same machinery could be adopted. Simply modify or downgrade the identity-proofing part of the ritual as appropriate. This could link into other strategies like PGP web-of-trust or lesser kinds of identifiers like possession of phone numbers, email addresses, etc.

There would need to be criminal liability for officials misbehaving and certifying such identity and authenticator bindings without performing the requisite identity-proofing procedures.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#155
post #54

Earlier quoted context omitted.

The only solution? Answer the phone in an over the top comedy accent, such as Simpsons characters, or just whatever comes to mind.

A terse, altered "Hello" is all I say. Sometimes I don't say anything. Most humans would wait a few seconds then prompt with "...Hello?", whereas bots tend to hang up after ~2s silence

When it is a human scam caller, what I sometimes do is to say "Hello" and then, when they start talking, and I can already guess they are full of shit, I act as if I am not hearing them properly and say "Hello?? Heeellooo? Hello?" Then they hang up lol.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#156
post #132

Earlier quoted context omitted.

That's a great idea. What do you use as your family password?

Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******

For any Hacker News users not aware of this security policy, it’s documented at https://news.ycombinator.com/item?id=38502985

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#157

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I think the hardest thing to come to terms with is not that this is the new reality, or even that this is soon going to be the new reality for our older relatives, but that this is coming for almost all of us.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#158
post #22

Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…

It's not "just" greasing the wheels, because previously each call required a human being to spend the equivalent amount of time on the phone with a victim, interacting with them - you couldn't just play a cassette tape at them, you know?

And it likely requires working with other people, your "employees", who are both a liability, and a cost.

With AI, you can make a thousand calls in parallel, for significantly cheaper, out of your own basement.

This greases the wheels of voice fraud like a gatling gun greases the wheels of hitting a guy with a rock.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#159
post #90
post #70

Earlier quoted context omitted.

I'm getting a lot of calls recently and don't give them more than a Hello and whatever music, radio show or Tour de France broadcast I'm listening to. Sometimes they hang in there for half a minute.

Sometimes if I’m suspicious about the number now, I just answer and say nothing. A human will get confused after 5 seconds and say “Hello?Hello??” But the very shitty bots that usually call, just wait patiently for a long time for your hello, and don’t seem at all fazed by it.

You get actual humans calling you from unknown numbers? Lucky! I only ever get "Chase" from "Home Security Solutions" or whatever.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#160
post #64

So, you answer your phone to the scam and… now they have your voice too. Talking on the phone is now an unmitigated liability.

I somewhere read about a service that would use AI generated voices to combat these scam calls, basically talking to the forever. Forgot the name though...

It's Lenny
Post reply on HN