Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

211–220 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#211

Earlier quoted context omitted.

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

Children are legally differentiated from adults purely based on age, not some formal verification. You get extra rights and obligations at 18, that’s a very objective criterion. Declaring someone mentally unfit is anything but objective and it’s very ripe for abuse.

I’m saying that old people should also be differentiated by age: once you reach some age (maybe 70 or 80, the same age for everyone) you lose certain rights. This is separate from the existing system.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#212
post #54

Earlier quoted context omitted.

A terse, altered "Hello" is all I say. Sometimes I don't say anything. Most humans would wait a few seconds then prompt with "...Hello?", whereas bots tend to hang up after ~2s silence

Don’t you guys have phones that screen calls?

Yes, but false negatives fall through. I don't pay for the call screening; maybe a paid version would be more successful.

Mostly ignore unknown numbers, but if I'm expecting a call, I will pick up.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#213
I'm kind of glad now that I had some really bad experiences in my career and experienced negative-trust environments.

When I told my parents some of what happened to me in my career, initially, I don't think they fully believed me because people in my stories behaved so differently than they're used to. My parents lived in an environment where they could expect reciprocity and money wasn't so difficult to come by that it would be worth risking prison time.

I kind of believe that a lot of people are essentially forced into fraud. I don't believe that they are necessarily bad people. A lot of people are just trying to get by.

So it's very important to convey to family members what kind of world we live in. I think most of my family members are essentially conspiracy theorists now.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#216

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

There's also the strain and discontent that comes with being the person who is taking away the rights and putting up guardrails for your loved ones. I opted not to do so for my mother shortly before she was scammed out of her life's savings, because I thought I could train her against scams.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#218

What’s terrible is each time I am forced to call the bank, the more they try to tell me voice ID is secure and want me to provide my voice to authenticate. Never. Did ya’ll never play Uplink? With voice cloning as good as it is now, there’s no way a voice ID is secure enough for authentication.

I find so many of these things utterly insane. Much like the way a fax of a signed document is considered legally meaningful. I think we have to stop pretending any kind of digital media presentation of a document, face, voice, etc. can be authenticated by its content. We really need to get to the point where any legally-binding digital authentication MUST be rooted in an in-person identity-proofing and authenticator…

I agree but this can be done today with current tech. All you need to do is incorporate the full picture.

Something you are (biometrics, voice id, whatever)

Something you know (PIN, super secret password, your dog's mothers maiden name)

Something you have (MFA, AuthCode, PushNotif)

And even then, be cautious of anything that would be deemed an "admin" operation. Such as transfering of funds, issuing a check, or adding an external account.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#219

Earlier quoted context omitted.

I'm usually not one to focus on technological solutions given sociological problems, but this one seems to be a good exception. If we "just wanted to" [1] all this fake calls could be stopped by requiring strong authentication/authorization. We are very much used to just anybody being able to call my number, but that doesn't need to be the case. At the very least, cold calls should be treated as skeptical in the UI a…

Speaking of which, what happened to SHAKEN/STIR? I thought the strong authentication requirements came down the pipe years ago and they were going to start turning off (or hiding by default) routes of low reputation. That was years ago, it was supposed to take years, but here we are years later and I still get loads of spam calls. What happened?

I worked on STIR/SHAKEN for the two biggest US operators. The techies tried very hard to make it work, and, indeed, there was a brief time when it worked pretty well, but, the incentives from Corporate were and are fundamentally misaligned.

Type A attestation is, generally, solved. Carrier A attests that the number is one of theirs, and they know that the caller is one of theirs too and attached to their network.

However: this is a fraction of calls. Carriers also sell blocks of phone numbers without the corresponding access network. This is what allows you to pick, say, a Twilio number with a local area code. In these cases the best that can be hoped for is a lesser attestation.

But it gets worse, because the operator can also sell blocks of numbers to people with no direct connection to the US carriers and who need to spoof US numbers. That call from Capital One comes from the Philippines via two or three intermediate operators, none of whom can attest to much of anything. And into that gap ride the spammers.

Furthermore, in an Experian-like twist, some carriers also realized that businesses would pay to have their calls show up as "trusted" on the recipient's phone. So the standards were enhanced to deliver 'rich call data'. However, in order to be something worth paying for you also need a baseline of calls that do not have that premium look. A scam? You decide.

Finally, one other misaligned incentive. All of this needs VoIP. Not TDM (classic legacy telephony). However, the big US carriers make bank selling TDM circuits to the hundreds of small regional telcos, and refuse to sell them SIP trunks, because it's s such an easy money maker. So again, technology loses to incentives. These incentives, to make money from phone numbers, vastly outpace what

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#220
post #170

Earlier quoted context omitted.

Yeah, recently I've had quite a few legitimate ones, mostly having to do with home renovations or other transactions. I like most am deeply unsatisfied with the archaic system though of a basically unchangeable 10-digit number granting permission for anyone to fill up my phone with messages and interrupt me with calls, and hate that I have to ever answer calls from a number I don't know. I really would like a mutual…

How do you meet people if it's pre-established consent. Eventually someone needs to say 'hi' without the consent of the other person. In all things.

Sure, I'd answer with an example of it done well. When "Instant Messaging" was a huge deal circa 2000, if you got a message from a new person on most platforms, you'd get a chat invitation. You could accept and allow them, or dismiss them and never hear from them again. (Of course this had a vulnerability if you could generate new accounts too easily, so spam activity varied depending on how easy it was to have bots sign up).

Phone calls and SMS should be like that, which, they almost could be today just with the phone OS keeping track of who you've previously "accepted."[1]

Except.

The identifiers (phone numbers) are nearly infinite, and nearly free, so the scammers just use a "new to you" number every time they call you, allowing each one to generate a new 'invitation.'

And of course to make it worse, the "numbers" are actually truly free since they can spoof any number they want all day long and to this day, most of those calls will go through and not even show a big red flag.

That last part is entirely reprehensible that our carriers haven't solved it by now, but apparently they don't want to.

[1] and also there's that sticky problem that some arbitrary company like say, a health insurance company or the state government, has 1000 departments who might call you, and they couldn't give you a full list if they wanted to.

Post reply on HN