Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

161–170 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#161
post #87

Earlier quoted context omitted.

Oh, man. That does seem likely. What a world. I wonder if eventually there won’t be a human in the loop, just a model trained to make money with a strategy like that, automatedly selecting victims and a person to be impersonated for each. Pre-render a few videos, place multiple calls in parallel. Basically a turnkey Docker container that takes a bitcoin address as a parameter and fills it with stolen money.

Long-term, it would mean that videos like that no longer function as a proof of life nor as a credible threat.

That only poisons the pool for actual kidnappers, not scammers.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#162

Earlier quoted context omitted.

> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”

The article makes a point of explaining how the world-renowned expert on identifying deepfake scams can no longer pass his own tests. If an expert can't distinguish, it has absolutely nothing to do with being "stupid" or not. So send them that, maybe. If they are still stubborn about it, then thank them for contributing to the future funding of Scam the World With AI.

Or maybe Deckard was a replicant the whole time.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#164
post #22

Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…

"Greasing the wheels" seems right in principle, but possibly putting the accelerant factor a bit... mildly. Like going from burning the turkey in the oven, to deep frying and burning your whole house down. > cybercrime losses across the United States rose 26 per cent in a single year > The FBI was candid that even these figures understate the problem. AI attribution in the report reflects only what victims recognised…

To build on your point, I have this comment I wrote months ago that I end up pasting (or pasting a bit altered) probably every week:

“Before LLM’s there was_____” I see this whenever an LLM’s impact is assessed. We know. The issue is scale and the ability for smaller and smaller groups (down to individuals) to execute at scale.

LLM’s are pouring massive amount of gasoline on existing issues and people just keep shrugging. Fake news always existed. Now one dude in India can flood multiple sock puppet media accounts with right wing content/images (actual example) at a scale previously unimaginable - or in this case, can target even more vulnerable elderly populations far more effectively.

People could always die crossing a street. Still, cars changed the discussion about pedestrian safety pretty materially. People didn’t simply throw up their hands and go “people have always been able to die crossing the street.”

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#165
post #64

Earlier quoted context omitted.

I somewhere read about a service that would use AI generated voices to combat these scam calls, basically talking to the forever. Forgot the name though...

It's Lenny

Thank you [0]. I searched and all I could find was Virgin Media's Daisy [1].

[0] https://en.wikipedia.org/wiki/Lenny_(chatbot)

[1] https://news.virginmediao2.co.uk/o2-unveils-daisy-the-ai-gra...

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#166
post #148

Earlier quoted context omitted.

Spam 0, you’ll eventually get some customer service agent

Fancy private bank so getting a human isn't the issue ...but I know one of the signals they use for authentication is voice analysis in background...which I do not love.

That’s the sneaky bit they don’t tell you when you hear the “This call may be monitored or recorded” part.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#167

Earlier quoted context omitted.

At some point, the scam evolves to a live video of a gagged loved one being tortured. "Stop wasting my time or they lose another finger." People aren't prepared for this shit.

I know lots of old people who have instant access to quite significant sums of money and many of them just don't need it. I don't need it. I'd be happy to opt-in to, say, a three day wait period on new payment recipients, but my bank doesn't offer that.

One of my banks as well as my investment broker have a three day wait to increase the maximum transaction limit.

I have them both set at about €150.

I think for the bank I can go to a branch to avoid the limit, but that will be with the full fraud suspicion of the teller.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#168
post #112

Everyone suffers from this, not just the scam victims. I opened a bank account for a new business this year, and the friction for doing perfectly normal things was ridiculous due to the bank’s paranoia about scams. I couldn’t even make an initial deposit from my previous business, or transfer money to my personal account, without triggering a fraud alert and freezing the entire account (couldn’t even log into the ban…

From a business perspective genuinely curious to know general location and bank name for this. In WA state I've only dealt with minor scrutiny (from credit union not bank) asking if the business is involved with cannabis otherwise it's been easy.

This was Chase, in WA. Part of the problem may be that I used an address on the account application that didn't match the one on the state company registration. Rather than let me update the application, they required that I update the state registration to match it ($50 fee btw). (To be clear, both addresses were current and valid.) That may have set some kind of risk flag that increased scrutiny later.

But they were specifically worried about the transfers being scams -- at least, that's what they said. They insisted on calling my other bank to verify that I was in fact the owner of the other business account. And I know there's been a big increase in things like fake real-estate scams, so paranoia is understandable.

However, the way bank fraud/risk departments work is generally completely opaque. I've previously had Bank of America refuse to open an account, with no reason given and no possible recourse. And I can't imagine a much more vanilla, boring, good-credit person than me, so I have no idea what set them off!

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#169

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI as instant messengers like Signal treat first messages. Probably this isn't enough, though, as it wouldn't have prevented the cases described in the article. Cold calling someone should probably require the caller to be traceable to a real, government-ID-verified person [2]. Even if that person is being defrauded themselves ("get a thousand bucks by installing this app and clicking a few screens") is would destroy the economics of the attack, as it would make each call expensive again.

[1] Structural inertia is the killer here. It will certainly not happen until the problem is huge enough.

[2] Exceptions can of course apply to numbers that are meant to primarily be cold called, like doctors offices. The callee possibly have to be specially trained to withstand this kind of attacks.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#170
post #90

Earlier quoted context omitted.

Sometimes if I’m suspicious about the number now, I just answer and say nothing. A human will get confused after 5 seconds and say “Hello?Hello??” But the very shitty bots that usually call, just wait patiently for a long time for your hello, and don’t seem at all fazed by it.

You get actual humans calling you from unknown numbers? Lucky! I only ever get "Chase" from "Home Security Solutions" or whatever.

Yeah, recently I've had quite a few legitimate ones, mostly having to do with home renovations or other transactions.

I like most am deeply unsatisfied with the archaic system though of a basically unchangeable 10-digit number granting permission for anyone to fill up my phone with messages and interrupt me with calls, and hate that I have to ever answer calls from a number I don't know.

I really would like a mutual opt-in system, where you have to pre-establish consent before it's even possible to message or call you, but it seems impossible to get there from here. We can't even get the stupid cell phone companies to strongly enforce that caller ID isn't spoofed!

Post reply on HN