Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

191–200 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#191
post #50

Earlier quoted context omitted.

A few years back, I would talk with scammers for a while to waste their time. Now I don't. LPT: Please have a codeword or phrase that you use with your loved ones so even if the scammers use your voice, they won't know the phrase.

> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”

You don’t even need this. You just ask “what did we do last Tuesday”. A scammer will hang up, even if the actual answer is “I haven’t seen you in two years”.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#192
post #84

Earlier quoted context omitted.

Key phrases make sense to put in place, but another easy safeguard is: "Before you send anything to anyone, ever, call them back. Doesn't matter if it's me, the bank, a lawyer, whatever... tell them 'hang on I have another call coming in, let me just call you back in a few minutes, okay?'"

Not a thorough safeguard, if scammers have half a brain cell they can provision a VOIP number for such a request. They’re nothing if not accommodating.

You call them back on the actual number - e.g. the official number of the bank, or the contact number of your friend, or the phone of your kid, etc, that you know or can find independently.

Not any old random number they give you.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#193

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights.

The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of rights reflects that. Another problem is that, just as some old people are scammed, taking away rights will have other old people abused by their “caretakers” (e.g. one relative hurting them and stealing from them even against other relatives, which already happens).

So I want to see it implemented but tied with our culture restoring respect for old people, giving them a sense of purpose, and looking out for those who aren’t our relatives. Specifically including reforming retirement homes, many which take advantage of their residents, and stronger safeguards against abusive relatives who (already are seizing and) abuse POA. I’d like to hear what old people themselves think, because maybe I don’t (empathetically) understand the consequences, but although maybe outside the Overton Window logically it seems reasonable.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#194

A year ago I promoted the idea among my wife's family that we should establish a sign/countersign system for the family and use it regularly so that in the event of something like this we could positively identify a legit request. Would have come in handy when our niece was traveling in Asia and asked for money a few times, but in this case it wasn't a scam. I got no traction with it, which I was a bit surprised by b…

A shared TOTP in an app could also work.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#195

Arrange a secret phrase in advance- ideally generated randomly. Stick it up on the wall of the aging parent or grandparent- maybe in the bedroom, where guests are unlikely to go. Make it innocuous-looking (hidden in plain sight). Require that phrase to be said to prove identity. Reset it if it ever gets used on a call legitimately.

Personally, I require all my aging grandparents to carry a Yubikey, with an identical one always stored in a safe-deposit box. Then, on demand, they simply mate their Yubikey with a specially-prepared GrapheneOS device, open their Firefox app, and connect to the dedicated mesh network, run by and for aging grandparents. Then they run their right ring finger over the fingerprint sensor, but it must be done in a Morse-code pattern that matches their unique tattoo (I am unable to divulge the location or encoding of this tattoo). Once these conditions are met, their physical presence is confirmed by the Yubikeys of at least 2 other aging grandparents of equal or higher reputation.

It's really simple and straightforward, and there is no need to really document the workflow here, because all the aging grandparents are extensively trained and drilled every two weeks, by the aging great-grandparents who've been using this same exact system for the past 50 years.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#196
Does anyone know if Ben Jordan's AI generated music algorithm would work here to spot fake voices? He's looking for compression artifacts introduced from the training data in the output music. I'd expect similar compression was used for training general voice data. Only issue I can think of is the compression of the audio link most of these scams are going to be using might mask the training data compression.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#197

A year ago I promoted the idea among my wife's family that we should establish a sign/countersign system for the family and use it regularly so that in the event of something like this we could positively identify a legit request. Would have come in handy when our niece was traveling in Asia and asked for money a few times, but in this case it wasn't a scam. I got no traction with it, which I was a bit surprised by b…

A shared TOTP in an app could also work.

My concern there is that the friction is too high: it wouldn't be something that family members would use in casual conversation, and could also be written off by the AI: "They won't give me my phone", "I lost my phone", etc...

"Did you see that game last night" replied to with "The Visitors are my favorite team" is something you could say instead of "hi" as a family.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#198

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

Nothing to do with cognitive decline. From the article:

>> It is tempting, and wrong, to attribute the targeting of older adults to naivety. The brief that prompts this article identifies a more uncomfortable truth: the characteristics that make older people disproportionately vulnerable are not deficiencies of intelligence but features of a life well lived. They tend to hold higher average savings balances, the accumulated product of decades of work, which makes them efficient targets — a single successful call can yield far more than one aimed at a younger person. They were raised in, and still operate within, established patterns of trust-based communication, in which a phone call from a distressed relative is answered as a genuine emergency rather than interrogated as a potential attack. They are, through no fault of their own, relatively unfamiliar with the existence of AI voice synthesis, having spent most of their lives in a world where a voice on the line was definitionally a person on the line. And they are exposed, like every parent and grandparent, to the particular emotional architecture of the family-emergency scenario, in which the instinct to protect a child overrides every slower, more sceptical faculty.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#199

Earlier quoted context omitted.

> The problem described in the article is unsolvable Well, not completely unsolvable. But nobody would like the solution. What all these scams rely on is a way to transfer money in an irrevocable fashion. Restrict that in meaningful ways and you end a lot of the abilities for these scams to operate. You could, for example, outlaw gift cards as a start. You could force the likes of Western Union to have a holding peri…

Also education. No court or attorney is going to demand payment of any fines or bail in gift cards or send a courier to pick up cash. High schools should teach how to spot a scam. As others have observed, this is not a new one, it's just gotten more high-tech and convincing. This is one of many practical things our schools should teach about that they just don't.

Education can only do so much. And, really unfortunately, as people age their brains don't work as well as they once did in their youth.

That's the primary reason why so many scammers target old people. It's less to do with education and more to do with the fact that as people age they become naturally more trusting.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#200
post #22

Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…

Sounds like something gogograndparent can add as a VAS
Post reply on HN