Live data from Hacker News

NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

cisa.gov

11–20 of 195 posts

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#12

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

Really? How about not using unofficial channels for statements? I mean, what is new to this problem. Other than it is somewhat cheaper to pair the fake statement with the person responsible reading it out laud. Department press release -> Reuters -> News paper -> reader No signing required. The reader can verify the press release of he wants to.

You rarely need a perfect fake because you rarely need to convince everyone, you can often achieve the same goal by just convincing a large group of people.

Also, official channels get hacked too.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#14
post #8

Earlier quoted context omitted.

Relevant XKCD https://xkcd.com/2650/

I think that's a really bad take. The difficulty of making many categories of lies is radically decreasing. That it has long been possible for a well-funded vfx team to do something doesn't mean nothing will change when it becomes possible for anyone with a cellphone and five minutes of free time to do the same thing.

> anyone with a cellphone and five minutes of free time

One could argue that this will be a good thing because deep fakes will be so prevalent (e.g. kids making videos of their parents saying and doing funny things) that the default assumption is that everything is fake until proven not fake.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#15

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

Really? How about not using unofficial channels for statements? I mean, what is new to this problem. Other than it is somewhat cheaper to pair the fake statement with the person responsible reading it out laud. Department press release -> Reuters -> News paper -> reader No signing required. The reader can verify the press release of he wants to.

It is different in my opinion.

* Text: You have little (definitive) clue who wrote what. You essentially have to ask the (apparent) writer.

* Photo: You used to have high confidence that a picture shows who appears to be shown. Not 100%, sure, but it's high.

* Video & Audio: You used to have very high confidence that the video including its audio are genuine. It was very difficult to replace video and/or audio.

Nowadays, none is trustworthy by default anymore. You can say: Well, just trust the company or Reuters. Sure, but I don't think anyone cares about this case. It's not controversial. But how will they be able to verify controversial sources?

If they get sent a video claiming to be about Ukrainins killing civilians, and outfits & speech matching that, how can Reuters be sure about anything now? Trust can't be given to the source, nor to the video, nor to the audio, nor to the metadata.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#16

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

Really? How about not using unofficial channels for statements? I mean, what is new to this problem. Other than it is somewhat cheaper to pair the fake statement with the person responsible reading it out laud. Department press release -> Reuters -> News paper -> reader No signing required. The reader can verify the press release of he wants to.

Whistleblowers also can't use official channels.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#17

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

Really? How about not using unofficial channels for statements? I mean, what is new to this problem. Other than it is somewhat cheaper to pair the fake statement with the person responsible reading it out laud. Department press release -> Reuters -> News paper -> reader No signing required. The reader can verify the press release of he wants to.

What happens when the news paper just makes stuff up because they need a more click baity article? People click links on emails without verifying the sender what makes you think readers will track back through the chain you describe to verify anything?

Don't roll your own authentication.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#19

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

All official materials should primarily be posted on the original authors' websites and signed using asymmetric cryptography. Furthermore, new open standards should be established to enable the presentation of such signatures/verification on well-known platforms like YouTube, FB, etc. These platforms should always provide a clear reference to the original material along with its digital signature.

For example, when watching a video on YouTube containing a speech by the president (provided on an official channel like the White House's), there should be a clear indication that the video has a digital signature and the option to verify it on an independent government website.

Post reply on HN