Live data from Hacker News

NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

cisa.gov

31–40 of 195 posts

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#31

Earlier quoted context omitted.

Really? How about not using unofficial channels for statements? I mean, what is new to this problem. Other than it is somewhat cheaper to pair the fake statement with the person responsible reading it out laud. Department press release -> Reuters -> News paper -> reader No signing required. The reader can verify the press release of he wants to.

It is different in my opinion. * Text: You have little (definitive) clue who wrote what. You essentially have to ask the (apparent) writer. * Photo: You used to have high confidence that a picture shows who appears to be shown. Not 100%, sure, but it's high. * Video & Audio: You used to have very high confidence that the video including its audio are genuine. It was very difficult to replace video and/or audio. Nowad…

>>>> Nowadays, none is trustworthy by default anymore.

Perhaps that is a good thing. Maybe this is a good excuse to stop and consider multiple news outlets, even if it conflicts with our own opinions, for our news sources.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#32

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

All official materials should primarily be posted on the original authors' websites and signed using asymmetric cryptography. Furthermore, new open standards should be established to enable the presentation of such signatures/verification on well-known platforms like YouTube, FB, etc. These platforms should always provide a clear reference to the original material along with its digital signature. For example, when w…

There are already coming cameras which sign the data on the fly with help of hardware security modules. Only that can be truly verifiable.

Adding signature after recording works to certain degree, but it still does not guarantee that the content is what the camera saw.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#33

Earlier quoted context omitted.

Really? How about not using unofficial channels for statements? I mean, what is new to this problem. Other than it is somewhat cheaper to pair the fake statement with the person responsible reading it out laud. Department press release -> Reuters -> News paper -> reader No signing required. The reader can verify the press release of he wants to.

It is different in my opinion. * Text: You have little (definitive) clue who wrote what. You essentially have to ask the (apparent) writer. * Photo: You used to have high confidence that a picture shows who appears to be shown. Not 100%, sure, but it's high. * Video & Audio: You used to have very high confidence that the video including its audio are genuine. It was very difficult to replace video and/or audio. Nowad…

> You used to have very high confidence that the video including its audio are genuine.

The physical artifacts yes, but not the narrative they were portraying. The “news” media has been spinning fictional narratives with physically authentic video and audio for a long time.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#34
post #32

Earlier quoted context omitted.

All official materials should primarily be posted on the original authors' websites and signed using asymmetric cryptography. Furthermore, new open standards should be established to enable the presentation of such signatures/verification on well-known platforms like YouTube, FB, etc. These platforms should always provide a clear reference to the original material along with its digital signature. For example, when w…

There are already coming cameras which sign the data on the fly with help of hardware security modules. Only that can be truly verifiable. Adding signature after recording works to certain degree, but it still does not guarantee that the content is what the camera saw.

…what the camera saw.

Cameras can record screens.

Perhaps adding a signed channel for depth and/or non-visible light would be the next step.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#35
post #32

Earlier quoted context omitted.

All official materials should primarily be posted on the original authors' websites and signed using asymmetric cryptography. Furthermore, new open standards should be established to enable the presentation of such signatures/verification on well-known platforms like YouTube, FB, etc. These platforms should always provide a clear reference to the original material along with its digital signature. For example, when w…

There are already coming cameras which sign the data on the fly with help of hardware security modules. Only that can be truly verifiable. Adding signature after recording works to certain degree, but it still does not guarantee that the content is what the camera saw.

How would that work with video editing? Like if someone records something and then trims it for length or needs to combine multiple streams. Seems like hardware level verification only goes so far.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#36
post #14
post #8

Earlier quoted context omitted.

I think that's a really bad take. The difficulty of making many categories of lies is radically decreasing. That it has long been possible for a well-funded vfx team to do something doesn't mean nothing will change when it becomes possible for anyone with a cellphone and five minutes of free time to do the same thing.

> anyone with a cellphone and five minutes of free time One could argue that this will be a good thing because deep fakes will be so prevalent (e.g. kids making videos of their parents saying and doing funny things) that the default assumption is that everything is fake until proven not fake.

The default assumption will be, as it mostly is already, that anything you want to believe is true, and anything you don't, is fake.

Thanks to a businessman/politician who turned "news about me I don't like" into "fake news", we got a jump start on that.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#37

Entities like CFOs and political leaders will have to start cryptographically signing their statements. There is no practical way to detect fakes after the fact.

The vast majority of uses for deep fakes is not for content that would appear on an official site: surreptitious videos of CEO/Politician doing illegal or embarrassing behaviour, racist tweets and emails from when they were college students etc.

At the same time, now when a sex tape comes out for someone they can claim it's a deepfake.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#38

Earlier quoted context omitted.

But that is out of scope of what you are replying to. If a CFO makes a statement and that is on the company's website we can have reasonable confidence that the CFO made that statement and we can act on it. Reporting on a video of unknown (possibly unknowable) provenance is a different kettle of fish.

Ah I see, I forgot the topic of this specific comment thread. Political Leaders could also have similar problems though. Example - Dictator A says terrible things on video/audio. Of course it's not going to be shown on their nations' broadcast website or in media. How can the rest of the world make sure the video that was recorded is trustworthy?

The same way we did in the days of print media being the only media?

A network of trusted sources, reporters and newspapers that the public trusts. Eye witness accounts, a preponderance of evidence.

Basically it boils down to the reputation of the individuals involved in the chain of trust.

Personally I'm excited by the prospect that we might get mainstream investigative journalism back in some form.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#39

Images and video that goes against the approved government and/or media narratives == 'deepfake' .

Yes, the featured article makes that clear the tools are not the threat, the “democratization of” the tools is the specific threat they are alerting people to. Hollywood and big brother have been doing propaganda and fake photos since forever, that’s not the problem CISA is reporting.

Re: NSA, FBI, and CISA Release Cybersecurity Information Sheet on Deepfake Threats

#40
post #32

Earlier quoted context omitted.

All official materials should primarily be posted on the original authors' websites and signed using asymmetric cryptography. Furthermore, new open standards should be established to enable the presentation of such signatures/verification on well-known platforms like YouTube, FB, etc. These platforms should always provide a clear reference to the original material along with its digital signature. For example, when w…

There are already coming cameras which sign the data on the fly with help of hardware security modules. Only that can be truly verifiable. Adding signature after recording works to certain degree, but it still does not guarantee that the content is what the camera saw.

Really?? I imagined this product but thought there must be some reason it’s a bad idea
Post reply on HN