Live data from Hacker News

4TB of voice samples just stolen from 40k AI contractors at Mercor

app.oravys.com

201–210 of 250 posts

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#201
post #2

Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insuranc…

> Self-audit your public audio footprint. Search YouTube, podcast directories, and old Zoom recording This is suggestion #1 on your list of remediation steps for victims, but you didn't provide any information on how anyone would actually do that. How exactly would I search the internet for copies of my voice? Please don't tell me the solution is giving an embedding of my voice to another third party.

Great question. There's no "reverse voice search" yet the way there is for images — that's genuinely a tool the world needs. In the meantime, the most useful thing is searching your name across YouTube and podcast platforms to map out what's already public. And for Mercor contractors specifically, the California AG breach notice gives you a solid legal basis to request full deletion. Worth doing today.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#202
post #97

Earlier quoted context omitted.

The irony runs deeper than the free analysis offer. The whole Mercor contractor relationship was this exact pattern: hand over studio-quality voice recordings and ID scans to get paid for data labeling work that didn't require either. "Explicit consent" was buried in the terms, and people clicked through because they needed the paycheck. Now 40k people have learned that biometrics aren't passwords. You can't rotate y…

> Now 40k people have learned that biometrics aren't passwords. You can't rotate your voice. Voices aren't strong. There just aren't that many unique characteristic parameters behind a voice - it's largely dictated by an evolutionary shared shared larynx and vocal tract. They aren't fingerprints. The fact that human voice impersonation is not only widely possible but popular should give you an indication of this. Pro…

[dead]

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#203
post #3

The only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies. Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.

Do Germans have lots of words or just a lack of spaces?

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#204
post #3

The only data that cannot be stolen or leaked is data that doesn't exist. Hard lesson for both users and companies. Germans (because of course) have a word for this: "Datensparsamkeit". Being frugal with your data.

Data can never be stolen, because it is not a physical thing. Data can be copied, and it can be erased - sometimes both happens at the same time. Data can be lost, that is when its last existing copy was erased.

Money is not a physical thing.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#205
post #2

Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insuranc…

One more data point for why sueing companies should lead to CEO getting prison time as well. And ideally invent some kind a of equivalent of pruson for non human persons like organisations.

Because right now the incentive to do what's right are so low. Taking a risk with other's people lives is becomming the norm for companies.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#206
post #2

Author here. Wrote this after watching Lapsus$ post the Mercor archive on their leak site earlier this month. The thing that struck me is the combination: voice samples paired with ID document scans. Most breaches leak one or the other. This one ships a deepfake-ready kit. Tried to keep the writeup practical: what an attacker can actually do with this combo (banking voiceprint bypass, Arup-style video calls, insuranc…

HSBC offered voice verification years ago and I just laughed and said nope. I don’t even use biometrics on apple devices, I use a 6 digit pin. It was always a stupid idea. The thing about been willing to trade convenience for security is you get called paranoid and then when the other shoe does drop and you are still doing that you still get called paranoid for the current thing you are not doing that “everyone does”…

[dead]

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#207

This is exactly why "voice as authentication" feels like a dead end to me

It feels like a dead end because it's being used wrong. "Is this John's voice?" is the wrong question. "Does this call look like how John normally calls?" is way more interesting. Same device, same time of day, same way of starting a sentence. That whole pattern is much harder to fake than a voice alone. The authentication isn't dead, it just needs to grow up from a single check into a full picture.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#208
post #62

The biometric pairing is what makes this particularly bad. A leaked password is recoverable. A leaked voiceprint combined with ID scans is permanent, you can not rotate your voice. The deeper problem is that most of these companies collected this data because they could, not because they needed it for the core service. 'Datensparsamkeit' is the right frame: the voice samples were a liability sitting on a server waiti…

[dead]

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#209

im the founder of a company that runs deepfake phishing simulations for enterprises, so biased on this one .. but the operational thing the piece misses is that this is the first widely circulated dump where voice, govt ID and selfie all came from the same onboarding session i.e. most enterprise call center auth still treats those as 3 independent factors .. The scarier piece is that an attacker pulls a contractor fr…

Great point about the helpdesk vector. The LinkedIn-to-IT-reset path is a brilliant illustration of how social engineering chains work. And you're right that audio is the frontier video deepfake detection has gotten really good, lots of great tools out there. Audio is the next wave, and the teams building solutions for real-world call quality are going to unlock a massive market. Exciting space to be in.

Re: 4TB of voice samples just stolen from 40k AI contractors at Mercor

#210

Earlier quoted context omitted.

> biometrics aren't passwords. You can't rotate your voice. "My voice is my passport. Verify me." I have to renew my passport every 10 years or so. How do I do that with my voice? I guess it's time to take some vocal lessons.

Vocal lessons are both a lot of fun and a lot of work. I haven't been using any voiceprint systems but I know most humans are unable to tell that my trained voice is the same physical person as my old voice. Would be curious to find out if an AI voiceprint system can discern whether it's the same or not.

[dead]
Post reply on HN