Live data from Hacker News

The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

smarterarticles.co.uk

221–230 of 255 posts

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#221

Earlier quoted context omitted.

I think limited rights for old people are like limited rights for children: justified because there is cognitive decline, and every individual (except children who tragically die young) gets to live some life with full rights. The biggest problem is that it’s depressing. A child gets to look forward to growing up and having full rights, an old person is already looking forward to declining and dying and the loss of r…

Children are legally differentiated from adults purely based on age, not some formal verification. You get extra rights and obligations at 18, that’s a very objective criterion. Declaring someone mentally unfit is anything but objective and it’s very ripe for abuse.

> Children are legally differentiated from adults purely based on age, not some formal verification.

Often but not always: https://en.wikipedia.org/wiki/Emancipation_of_minors

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#222

Earlier quoted context omitted.

"Greasing the wheels" seems right in principle, but possibly putting the accelerant factor a bit... mildly. Like going from burning the turkey in the oven, to deep frying and burning your whole house down. > cybercrime losses across the United States rose 26 per cent in a single year > The FBI was candid that even these figures understate the problem. AI attribution in the report reflects only what victims recognised…

To build on your point, I have this comment I wrote months ago that I end up pasting (or pasting a bit altered) probably every week: “Before LLM’s there was_____” I see this whenever an LLM’s impact is assessed. We know. The issue is scale and the ability for smaller and smaller groups (down to individuals) to execute at scale. LLM’s are pouring massive amount of gasoline on existing issues and people just keep shrug…

As the quip goes, "Quantity has a quality all its own."

Although in this case, perhaps it's more like... throughput, capacity, or parallelism.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#223

Sad times are coming for a lot of families and individuals. It isn't just that technology is upending our naive ideas of trust and authenticity. This is, essentially, the broad class of "confused deputy" attacks. And the robust mitigation is to disempower the easily confused deputy, rather than to think you can block confusing signals. A looming problem with shifts in demographics and family structure is that many pe…

[dead]

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#224
post #147

This old post of mine may be of interest, where I point out: "After a bit of threat modeling, it becomes apparent that future spearphishing robocalls may not directly con you, but rather “farm” your voice data by asking you benign questions, and use that to train a voice model to penetrate more deeply into your network." A lot of this writing has been on the wall forever and many (I'm sure otherwise smart people in)…

Do not answer calls from random numbers. When has that ever been a benefit?

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#225
post #147

This old post of mine may be of interest, where I point out: "After a bit of threat modeling, it becomes apparent that future spearphishing robocalls may not directly con you, but rather “farm” your voice data by asking you benign questions, and use that to train a voice model to penetrate more deeply into your network." A lot of this writing has been on the wall forever and many (I'm sure otherwise smart people in)…

Do not answer calls from random numbers. When has that ever been a benefit?

Telcos need to implement STIR/SHAKEN in a binding way and it needs to be fully integrated into iOS/Android's UI. Spammers call from spoofed numbers, even numbers of, say, local schools (or from other people in your business) - so, if you get a call from a school and you've got kids, would you pick up? A couple of years ago I got a text that was "sent" from my boss (he didn't send it), etc.. The numbers aren't random.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#226

Earlier quoted context omitted.

Also education. No court or attorney is going to demand payment of any fines or bail in gift cards or send a courier to pick up cash. High schools should teach how to spot a scam. As others have observed, this is not a new one, it's just gotten more high-tech and convincing. This is one of many practical things our schools should teach about that they just don't.

Education can only do so much. And, really unfortunately, as people age their brains don't work as well as they once did in their youth. That's the primary reason why so many scammers target old people. It's less to do with education and more to do with the fact that as people age they become naturally more trusting.

When does that start. Because at 60 I'm far less trusting than I was at 30. Seen too much of the worst of people and less and less of the best.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#227
post #22

Sounds like AI is just greasing the wheels of a long established 'grandparent scam'... goes something like this: 1) voice one: young adult calls, sobbing 2) grandparent inquires with a name... "Ben, is that you?" 3) voice one: "Yes grandma, it's me, Ben... I'm in trouble, please don't tell mom 4) voice two: "Hello, I'm attorney..." My grandmother fell victim to this almost 20 years ago, which only stopped when Wester…

I told my parents that I will never ask for money, doesn't matter the situation, even with live video, it's trivial to generate live audio and video nowadays. I hope they got the message.

That wasn't enough for my mom. I went through an identical scenario, and about 6 months after we had the conversation she got hit.

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#228
post #93

Earlier quoted context omitted.

Key phrases make sense to put in place, but another easy safeguard is: "Before you send anything to anyone, ever, call them back. Doesn't matter if it's me, the bank, a lawyer, whatever... tell them 'hang on I have another call coming in, let me just call you back in a few minutes, okay?'"

I overheard a cab driver being scammed by someone claiming to be HMRC (UK version of the IRS), and when he asked to call them back they managed to convince him to call them back on Viber , and he was about to when I intervened and pointed out to him that 1) what I'd overheard was blatantly a scam, 2) if he was unsure, to go to their official website and find their number... If you're going to get people to call you b…

you need to be able to call them back on your own accord. not by them giving you a number to call or calling the same nr back again

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#229
So, full disclosure I’m a sec founder in the space, and was already planning on launching a solution deepfake “grandparent scams” right before hacker summer camp but this post was too on the nose to ignore so I ended up moving it up and launching the waitlist for dontscamgrandma.com tonight.

Long story short, some fraud associated events cropped up last year at work and I was concerned about my mom getting scammed, so we kitchen tabled it and I told her flat out will never ever call you asking for money" and walked her through some quick scenarios and left it there.

About 5 months later, someone called literally screaming, pretending to be me having just gotten into a car accident and killing a pregnant woman, then the phone transferred over to a 'lawyer' and she ended up getting scammed out of most of her life savings.

It sat really poorly with me, so I quit my dayjob at the end of last year and started silversight.ai to solve the ai scam / fraud problem for b2b, but I’ve been wanting to roll out something for regular people from the beginning. This post was the bump I needed to validate that other people were feeling the pressure.

So thanks for posting.

We have more features in the pipe, but as of today dontscamgrandma is backed by an engine that does regular recurring real time phone based training scenarios with an AI that roleplay's common grandparent scams with your loved one with the goal of getting them to recognize and defend themselves from sketchy calls.

Pretty excited to share it. Feedback welcomed https://dontscamgrandma.com

Re: The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence

#230
post #148

Earlier quoted context omitted.

Fancy private bank so getting a human isn't the issue ...but I know one of the signals they use for authentication is voice analysis in background...which I do not love.

That’s the sneaky bit they don’t tell you when you hear the “This call may be monitored or recorded” part.

Alas this was set up before good voice cloning happened. So was very much an active plan not covert. I asked if it can be disabled but apparently no.

Not end of world - it’s not the primary Auth means but still not ideal.

Post reply on HN