Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

201–210 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#201

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

> and not at the personal level of relinquishing control over our own lives

No one wants to do that. Once you give up control of your life you're essentially dead. Why would I want to voluntarily cede my rights so I'm relegated to being pushed around in a wheel chair while all my decisions are made by others? Because it makes my children, the people too young to have any perspective on the situation, feel better?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#202
post #170

Earlier quoted context omitted.

You get actual humans calling you from unknown numbers? Lucky! I only ever get "Chase" from "Home Security Solutions" or whatever.

Yeah, recently I've had quite a few legitimate ones, mostly having to do with home renovations or other transactions. I like most am deeply unsatisfied with the archaic system though of a basically unchangeable 10-digit number granting permission for anyone to fill up my phone with messages and interrupt me with calls, and hate that I have to ever answer calls from a number I don't know. I really would like a mutual…

How do you meet people if it's pre-established consent. Eventually someone needs to say 'hi' without the consent of the other person. In all things.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#203

Earlier quoted context omitted.

To build on your point, I have this comment I wrote months ago that I end up pasting (or pasting a bit altered) probably every week: “Before LLM’s there was_____” I see this whenever an LLM’s impact is assessed. We know. The issue is scale and the ability for smaller and smaller groups (down to individuals) to execute at scale. LLM’s are pouring massive amount of gasoline on existing issues and people just keep shrug…

Don't worry, it's all worth it so long as we can get braindead summaries we didn't ask for, pretend to be the 10x engineer we always wanted to be, and generate fake videos for internet points! (sarcastic rant over) Most of the benefits of AI are being overshadowed by the lack of regulation and reckless abandon at which they are being developed. Given the current trajectory I don't know if that's going to change befor…

And the crux of it all is people over promising and refusing to recalibrate expectations. LLM’s are kind of incredible, but we did not develop some magical tool that can do everyone’s job for them and/or answer every question with even semi-regular accuracy. it is a far more limited tool than any company, politician, or AI evangelist is willing to admit

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#204

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

Children are legally differentiated from adults purely based on age, not some formal verification. You get extra rights and obligations at 18, that’s a very objective criterion.

Declaring someone mentally unfit is anything but objective and it’s very ripe for abuse.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#205

Earlier quoted context omitted.

I'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI a…

Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?

It's worth noting that TFA addresses this in the context of the scam: When the scam depends on the emotional reaction in response to a loved one's distress, it doesn't matter if the number the scam is coming from is unfamiliar. This means that the scam can use "technically correct" numbers that pass SHAKEN/STIR with no loss in conversion.

TFA also mentions that by routing calls through older non-IP networks you lose the accurate information, although it sounds like the FCC is slowly cracking down on this.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#206

Earlier quoted context omitted.

Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?

It is hard to get vendors to give up revenue no matter how illegal the source of revenue is.

Why not fine vendors instead? They'll quickly change the tune..

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#207
post #170

Earlier quoted context omitted.

Yeah, recently I've had quite a few legitimate ones, mostly having to do with home renovations or other transactions. I like most am deeply unsatisfied with the archaic system though of a basically unchangeable 10-digit number granting permission for anyone to fill up my phone with messages and interrupt me with calls, and hate that I have to ever answer calls from a number I don't know. I really would like a mutual…

How do you meet people if it's pre-established consent. Eventually someone needs to say 'hi' without the consent of the other person. In all things.

In person or online.

How often have you met people over the phone in the past decade?

I will say that blocking all unrecognized numbers, though, is an unworkable idea. Any parent or caregiver knows that they need to be able to occasionally receive calls from a number they've never heard of before.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#208

Arrange a secret phrase in advance- ideally generated randomly. Stick it up on the wall of the aging parent or grandparent- maybe in the bedroom, where guests are unlikely to go. Make it innocuous-looking (hidden in plain sight). Require that phrase to be said to prove identity. Reset it if it ever gets used on a call legitimately.

Personally, I require all my aging grandparents to carry a Yubikey, with an identical one always stored in a safe-deposit box. Then, on demand, they simply mate their Yubikey with a specially-prepared GrapheneOS device, open their Firefox app, and connect to the dedicated mesh network, run by and for aging grandparents. Then they run their right ring finger over the fingerprint sensor, but it must be done in a Morse-…

Seriously though, I'd like to make two points:

1: Your family members already have shared "secrets" if they communicate regularly. It could be pet names, terms of endearment, shared experiences, unique monikers for things. It's language that is already familiar and you already use quite often. You should leverage that, and rely on that familiarity in a crisis, rather than trying to contrive something special for crisis-only ID. The attackers' greatest weapon is your own confusion, your own willingness to believe, and creating a sense of urgency. Your attackers' 3 greatest weapons. Don't panic.

2: My maternal grandmother was widowed and lived alone for decades. She had certain ways of knowing things. For example, every time we'd come home, she would test the doorknob. If some stranger had come and tried to jiggle the doorknob, we could tell by its feel. Just a simple mechanical giveaway. When Mom and/or Dad came by, they rang the doorbell by a special pattern. It wasn't complex, but it was distinct and recognizable from inside. It wasn't a securely encrypted ID, just a "secondary ring" that was unlike a stranger's touch on the doorbell button. And, of course, my parents can always interpret the antics of their indoor cat, in regards to who is approaching the house by car or on foot...

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#209
post #132

Earlier quoted context omitted.

Nice try, but our password is the same as the password to my HN account, and for security HN automatically censors your password if you type it in a comment. See: *******

For any Hacker News users not aware of this security policy, it’s documented at https://news.ycombinator.com/item?id=38502985

Yes, the bash.org IRC archive archive is hilarious:

https://web.archive.org/web/20230620135556/http://bash.org/?...

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#210

Arrange a secret phrase in advance- ideally generated randomly. Stick it up on the wall of the aging parent or grandparent- maybe in the bedroom, where guests are unlikely to go. Make it innocuous-looking (hidden in plain sight). Require that phrase to be said to prove identity. Reset it if it ever gets used on a call legitimately.

Personally, I require all my aging grandparents to carry a Yubikey, with an identical one always stored in a safe-deposit box. Then, on demand, they simply mate their Yubikey with a specially-prepared GrapheneOS device, open their Firefox app, and connect to the dedicated mesh network, run by and for aging grandparents. Then they run their right ring finger over the fingerprint sensor, but it must be done in a Morse-…

LOL.
Post reply on HN