Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

181–190 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#181

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI a…

Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#182

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I wonder what percentage of the US GDP is "Fooling old people"

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#183

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI a…

I never answer my phone if I don't know who is calling me.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#184

Earlier quoted context omitted.

I'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI a…

Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?

It is hard to get vendors to give up revenue no matter how illegal the source of revenue is.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#185

Earlier quoted context omitted.

Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?

It is hard to get vendors to give up revenue no matter how illegal the source of revenue is.

So lots of judicially-unreachable call centers under judicially-unreachable telecoms need to lose reputation score and get spam-binned by default, just like email. I thought that was going to happen by now. Did the US telecoms just chicken out?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#186

Earlier quoted context omitted.

Scammers can also trick the victim into reversing the roles and telling password to scammer. Even banks ocassionaly get this wrong. I have had my bank call me and ask me to read numbers from number card. If a trained bank employee following a script designed by (hopefully) an expert cant get it right, the chance of elderly relative spotting mistakes in protocol is close to 0.

The bank is trying to authenticate you, while you're trying to authenticate the bank. The bank calls and tries to authenticate themselves to the callee by saying "is your birthday such and such?", they're risking sharing PII with an unauthorized third-party. The solutions are a non-trivial amount of effort that no one really wants to put up with, unfortunately. I used to have a residential mortgage with two other peo…

Hah, I had a background check company for a previous employer send me an email saying:

"Hi Firebeyond, we're doing a background check. Can you confirm the following info you entered into our portal?" then proceeds to list full SSN, drivers license, DOB, etc., etc., etc.

"... and can you also confirm that this is the correct email address we have on file?"

All the while they had reached out by FB Messenger to my partner (not that she was in any of the info I submitted, and this was just a standard BG check, not a security clearance) to ask her if she knew me...

Luckily, my new employer was as horrified as I was, apologized profusely, and fired the background check company.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#187

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

Disempowering deputies is how you end up with customer service that can't actually provide service to customers. Low-trust societies are a huge efficiency loss, and just a general pain in the ass if you are acting in good faith.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#188
post #187

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

Disempowering deputies is how you end up with customer service that can't actually provide service to customers. Low-trust societies are a huge efficiency loss, and just a general pain in the ass if you are acting in good faith.

How much "customer service" are we getting today, and of what quality?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#189
post #54

Earlier quoted context omitted.

The only solution? Answer the phone in an over the top comedy accent, such as Simpsons characters, or just whatever comes to mind.

A terse, altered "Hello" is all I say. Sometimes I don't say anything. Most humans would wait a few seconds then prompt with "...Hello?", whereas bots tend to hang up after ~2s silence

That's my experience too. I mostly don't pick up calls from numbers that I don't recognize. On the very rare occasion that I am expecting such a call, I always stay silent after picking up. A real human will without fail start talking after a second or two.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#190

Earlier quoted context omitted.

"Greasing the wheels" seems right in principle, but possibly putting the accelerant factor a bit... mildly. Like going from burning the turkey in the oven, to deep frying and burning your whole house down. > cybercrime losses across the United States rose 26 per cent in a single year > The FBI was candid that even these figures understate the problem. AI attribution in the report reflects only what victims recognised…

To build on your point, I have this comment I wrote months ago that I end up pasting (or pasting a bit altered) probably every week: “Before LLM’s there was_____” I see this whenever an LLM’s impact is assessed. We know. The issue is scale and the ability for smaller and smaller groups (down to individuals) to execute at scale. LLM’s are pouring massive amount of gasoline on existing issues and people just keep shrug…

Don't worry, it's all worth it so long as we can get braindead summaries we didn't ask for, pretend to be the 10x engineer we always wanted to be, and generate fake videos for internet points!

(sarcastic rant over)

Most of the benefits of AI are being overshadowed by the lack of regulation and reckless abandon at which they are being developed.

Given the current trajectory I don't know if that's going to change before it's too late.

Post reply on HN