Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

241–250 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#241

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

> limited rights for old people

How old did you have in mind?

> an old person is already looking forward to declining and dying

All of my colleagues who have died in old age (at least late seventies) did so in full command of their senses, one of them still contributing to international technical committees into their eighties.

Age is not a useful measure in this field.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#242

Earlier quoted context omitted.

> LPT: Please have a codeword or phrase that you use with your loved ones They keep refusing ideas like these on the grounds of them being “not stupid” and “able to see through such attempts immediately, 100% of the time” and “do you think we’re stupid?”

The article makes a point of explaining how the world-renowned expert on identifying deepfake scams can no longer pass his own tests. If an expert can't distinguish, it has absolutely nothing to do with being "stupid" or not. So send them that, maybe. If they are still stubborn about it, then thank them for contributing to the future funding of Scam the World With AI.

Identifying the voice as fake is not the main defense against these scams, though. The main defence is recognising the situation and taking a step back to double-check. Primarily the scammers are trying to stop you from engaging your critical thinking by putting you under pressure and a very useful skill in life is recognising those situations and pushing back on them.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#243

Earlier quoted context omitted.

I worked on STIR/SHAKEN for the two biggest US operators. The techies tried very hard to make it work, and, indeed, there was a brief time when it worked pretty well, but, the incentives from Corporate were and are fundamentally misaligned. Type A attestation is, generally, solved. Carrier A attests that the number is one of theirs, and they know that the caller is one of theirs too and attached to their network. How…

So we can't block shady spammers because business wants shady customer support call centers? Ugh. It figures, but ugh. Thanks for the inside perspective.

I'm going to mangle the terms of art here, but the ur-problem is that labels of routing, like phone numbers and email addresses, get confused with labels of identity, and then with indicators of trustworthiness.

Everything is built to address that weakness - think DKIM, SPF, etc, plus STIR/SHAKEN, to say nothing of IP or ASN filtering, but they feel like bandaids on a very difficult problem. What you end up with are basically default-deny except for a personally curated trust set ("only accept calls from my contacts", "everything goes in spam unless I have previously corresponded with the sender"), etc.

One last robocall story. AT&T sat on their hands for years until consumer groups embarrassed the then-CEO enough to do something about it. There was a memorable interview in the Dallas Morning News where they called him on it instead of lobbing him softballs and I suspect that the embarrassment finally got through.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#244

Earlier quoted context omitted.

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

> limited rights for old people How old did you have in mind? > an old person is already looking forward to declining and dying All of my colleagues who have died in old age (at least late seventies) did so in full command of their senses, one of them still contributing to international technical committees into their eighties. Age is not a useful measure in this field.

> How old did you have in mind?

Somewhere between 70 and 80

> All of my colleagues who have died in old age (at least late seventies) did so in full command of their senses, one of them still contributing to international technical committees into their eighties.

Likewise, there are 14-year-olds and 16-year-olds smarter and more mature than most adults. Loss of rights doesn't mean they can't contribute, have others deny opportunities or abuse them; people would still look out for them, they would have more protection than children in this regard. Mainly, it makes it easier and more common to control finances, prevent from driving, and prevent from rotting in front of the TV old people who have lost their senses.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#245
post #15

Earlier quoted context omitted.

our family has had a special 'code word' we have had since the kids were in elementary school. If someone ever needed to pick up our kids from school (they never did) our kids were taught to ask for that word. This is a good reminder that we should review that, since its been 10 years or so.

This. All of this is a solved problem. It's just not a thing that most families do and do regularly. Code word, insider info, etc. "Oh I am so sorry you got arrested Tommy. Before I wire the $, where did we go on vacation last year?'

> where did we go on vacation last year?

...hoping it is not on Tommy's instagram?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#246
post #100

We all have a safe word in the family just for this issue to identify if it´s the real person or not.

Someone else pointed out how easy it would be to make a video of anyone having a finger cut off, or similar torture, to scare the victim into believing that the “grandchild” forgot their password and needs you to override the password protocol to save their other 9 fingers. I have to agree. That’s like 80¢ of compute to do. If that’s effective even 30% of the time, it means “just have a password” doesn’t make you saf…

I mean that's a pretty extreme example though. It can be mostly gotten past by using the method used with alarm companies. One "danger" password and one "safe" password.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#248
Sad sad times indeed, specially because AI empowers more those who seem to do wrong more than good. What we discovered is that implementing a double agent verification, specially in aging population is the way to mitigate. That is family members or more exposed members are required to have a double authorization notification for performing transactions. Banks are doing it quite well and is completely align with MFA. Of course this requires configuration of a trust circle among every person, and generates another avenues for abuse like was pointed. Sadly we are always running behind into protecting people.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#249
post #54

Earlier quoted context omitted.

A terse, altered "Hello" is all I say. Sometimes I don't say anything. Most humans would wait a few seconds then prompt with "...Hello?", whereas bots tend to hang up after ~2s silence

Don’t you guys have phones that screen calls?

Because Reasons I'm looking at several feature-phone / dumbphone options.

One feature that's conspicuously missing from many of these is "unknown call block" or equivalent.

Which is completely staggering to me.

I'm looking at other options, including VOIP / SIP Trunking, where it should in theory be possible to incorporate any arbitrarily complex call-screening feature(s), though Further Research is Needed.

Android / iOS phones typically have several available options for call screening. Unfortunately they include numerous other issues and negatives.

Sigh.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#250

This article is about the retail version of this kind of fraud. Impersonating CEOs is a thing, and the dollar amounts are much larger. The attackers created AI-generated video and audio replicas of the CFO and other executives of the global engineering firm. These deepfakes were deployed in a live video call – not as a pre-recorded video, but as a real-time conference with multiple participants. The finance employee…

The possible silver lining of enterprise-scale fraud is that it might be the pain which finally pushes telephony / voice comms to adopt true call-level authentication and security.

This need not be a centralised security / authentication / identification system, but the protocols must be standardised and near-universally applied. If these rely on some hardware token (YubiKey, NFC ring, RSA keyfob OTP, or even a smartphone's native ID features).

The other side of this is that networks and carriers who transact largely fraudulent traffic must be penalised for this. I'd like to see both financial and technical penalities, e.g., ruinous fines, with a sufficiently large balance disqualifying the carrier from interconnect rights, and the right for terminating / bridging carriers to reject traffic in proportion to the level of malicious traffic logged.

(This also implies some distributed facility for monitoring traffic from various comms networks and sharing that information with carriers and other security provisioning parties.)

A worse outcome would be a two-tiered system in which large enterprises have access to reasonably fraud-free comms, and the rest of the world does not.

Post reply on HN