Live data from Hacker News

4TB of voice samples just stolen from 40k AI contractors at Mercor

app.oravys.com

131–140 of 250 posts

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#132
post #2

Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insuranc…

[deleted]

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#133

Earlier quoted context omitted.

> biometrics aren't passwords. You can't rotate your voice. "My voice is my passport. Verify me." I have to renew my passport every 10 years or so. How do I do that with my voice? I guess it's time to take some vocal lessons.

just take up smoking heavily

Easier to inhale an undisclosed amount of helium before recording your password voice

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#134
post #97
post #44

> If you were a Mercor contractor and you believe your voice may already be in circulation, ORAVYS will analyze the first three suspect samples free of charge. Awesome, if you're a victim of an AI company having your voice, you can help yourself by sending another AI company your voice! > Audio is never used to train commercial models without explicit consent I'm sure Mercor has explicit consent as well, legal teams…

The irony runs deeper than the free analysis offer. The whole Mercor contractor relationship was this exact pattern: hand over studio-quality voice recordings and ID scans to get paid for data labeling work that didn't require either. "Explicit consent" was buried in the terms, and people clicked through because they needed the paycheck. Now 40k people have learned that biometrics aren't passwords. You can't rotate y…

> Now 40k people have learned that biometrics aren't passwords. You can't rotate your voice.

Voices aren't strong.

There just aren't that many unique characteristic parameters behind a voice - it's largely dictated by an evolutionary shared shared larynx and vocal tract. They aren't fingerprints.

The fact that human voice impersonation is not only widely possible but popular should give you an indication of this. Prosody, intonation, range, etc. - it's all flexible and can be learned and duplicated.

The signals are simple too, because we have to encode and decode them quickly. You may or may not be able to picture and rotate an apple tree in your head, but you can easily read this sentence in the voice of David Attenborough.

Moreover, you can easily fine tune a voice model to fit any other speaker. You can store the unique speaker embeddings in a very thin layer. Zero and few shot unseen sampling can even come close to full reproduction. You can measure this all quantitatively.

Voices are not, and never have been, fingerprints. They're just not that unique.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#136
post #133

Earlier quoted context omitted.

just take up smoking heavily

Easier to inhale an undisclosed amount of helium before recording your password voice

Excellent idea!

Do you need to calibrate it to be able to repeat it, and does that calibration change if you are at a different altitude and in different conditions, such as humidity?

Does merely changing altitude (or ambient pressure) change voice enough to be considered different by a recognition or synthesizing system?

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#137

Earlier quoted context omitted.

I think "CYA" is maybe a misleading or overflowery term. In the idealized world, the legal system is meant to provide an accessible alternative to violence for reconciling disputes, but it's increasingly wielded as an impossibly kafkaesque system meant to maintain corporate power over individuals. I think "CYA" is an overly-flowery term for the reality that they're blocking every avenue for legal recourse, while a va…

I'm taking some college courses, and one of them explicitly suggests to keep maybe-not-okay communications off of email so that "you don't expose your company to risks of litigation." Ah, I see. So, when discussing ways to ensure cuatomers cannot utilize our warranty process, I'll make sure to do so in ways that are not traceable and won't show up in discovery.

The general rule for email, text, and all other communications I've heard is: "Don't write anything that you wouldn't be comfortable seeing on the front page of the New York times."

Heard that first from a US mil commander who once ran for a minor political office like state rep.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#138

Earlier quoted context omitted.

just take up smoking heavily

Despite popular belief, even heavy smoking does not alter your voice in a significant way.

Despite popular belief, even heavy smoking does not alter your voice in a significant way.

I guess you don't listen to Sinatra.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#139
im the founder of a company that runs deepfake phishing simulations for enterprises, so biased on this one .. but the operational thing the piece misses is that this is the first widely circulated dump where voice, govt ID and selfie all came from the same onboarding session i.e. most enterprise call center auth still treats those as 3 independent factors ..

The scarier piece is that an attacker pulls a contractor from the dump, finds their employer on linkedin, then calls that companys IT helpdesk for a password reset with the cloned voice.

Fwiw we put up a free realtime face swap demo a while back at https://www.callstrike.ai/deepfake-security-training .. worth a look if you want to actually feel how trivial this has gotten.

Post reply on HN