Live data from Hacker News

British engineering giant Arup revealed as $25M deepfake scam victim

cnn.com

61–70 of 109 posts

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#61
post #32

Earlier quoted context omitted.

What's wrong with good ol' private keys?

The ability to make an infinite number of them. And that most people have no idea how to verify any ID, so they need a system that turns any given form of ID into a nice and simple "yes" or "no". I'm not at all clear what kind of ID is going to be genuinely useful for video calls, given we should only be trusting existing contacts anyway? But those things are why "private key" isn't sufficient in isolation.

Why couldn't a mobile app that everyone uses work for this. The person who wants to verify who they are uses the app, does digital signing and the other person gets notificatiom and the certification.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#62
post #40

Earlier quoted context omitted.

I guess a scammer can sell it as "we're buying something significant [another company?], this will affect our share price if the info goes out, so you need to sign this NDA and keep this quiet, you're only 1 out of 10 people who knows this...". They could also sell it as payment for an e.g. consulting firm for the above secret deal...

Secret doesn't mean they can't use internal authenticated communication channels, at the very least to send a redacted confirmation.

Most people historically would consider a video call with the person to be sufficiently authenticated. Yeah, that has changed obviously, but it has changed like today.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#63
post #45
post #2

I said this over a year ago elsewhere: Electronic engineers spent decades overcoming thermal noise floors so that humans could communicate over vast distances with small amounts of energy. AI researchers, in a few short years, undid all that by making computer-generated chatter and images indistinguishable from messages sent by humans. Until such a time as we live in a Bladerunner-like world of Replicants, being in-p…

When I'm on a company video call, the people I'm meeting with are logged into their company accounts, through the fancy company authentication system. Large warnings are displayed if there are any external participants, and I wouldn't be surprised if it's possible to disable the ability to even have guests. Third-party video conference software is banned and blocked from installation on work computers. I am not in th…

If I was the attacker, I'd use credential-stuffing or something to get access to some random employee's account. Doesn't have to be anyone important.

Then I'd set up a short-notice multi-way meeting between the target, the CEO and the hacked account. The deepfake 'CEO' then turns up with no alarms raised, except one wrong name - easily dismissed as a glitch, or an assistant having booked the meeting.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#64
post #41

The real issue here is a lack of proper risk controls around business processes involving money. Regardless of if it’s £3 for a coffee or £25m for a Secret acquisition there should be an agreed process that everyone involved in business transactions should be aware of so that if they are suddenly privy to a deal they can navigate and validate the authenticity of their involvement.

With £25m there ought to be at least two people required to authorise the transfer.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#65

Earlier quoted context omitted.

There are many secrets in business, especially in realestate. Found out, from some "unnamed source" that there will be a new bus stop and a new aldi store across the street from a building where some apartments are for sale? Don't mention it to anyone, secretly buy them, because their value will go up a lot, and do it discreetely, so other companies don't notice.

That should be classified as corruption/insider trading and punished as such. In my country that's how politicians and their friends get filthy rich. They know ahead of time where a new highway will be planned so they buy up all the rural land in that area for cheap so that the government will have to buy it from them at inflated prices to build the highway. Then, if a new government comes to power before the highway…

[deleted]

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#66
post #32

Earlier quoted context omitted.

The ability to make an infinite number of them. And that most people have no idea how to verify any ID, so they need a system that turns any given form of ID into a nice and simple "yes" or "no". I'm not at all clear what kind of ID is going to be genuinely useful for video calls, given we should only be trusting existing contacts anyway? But those things are why "private key" isn't sufficient in isolation.

What's wrong with making an infinite number? You just need to check it against one public key.

https://en.wikipedia.org/wiki/Sybil_attack

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#67
post #32

Earlier quoted context omitted.

The ability to make an infinite number of them. And that most people have no idea how to verify any ID, so they need a system that turns any given form of ID into a nice and simple "yes" or "no". I'm not at all clear what kind of ID is going to be genuinely useful for video calls, given we should only be trusting existing contacts anyway? But those things are why "private key" isn't sufficient in isolation.

Why couldn't a mobile app that everyone uses work for this. The person who wants to verify who they are uses the app, does digital signing and the other person gets notificatiom and the certification.

Sure, but that's basically the exact same value-add of Worldcoin, along with a bajillion other similar apps.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#68
post #51

Earlier quoted context omitted.

You're the only commenter using critical analysis, everyone else is just flapping their jaws. I hate discussing deepfakes. I'm one of the original patent holders of automated actor replacement technology. I developed it for personalized advertising, after having been an actor replacement specialist in a bunch of VFX film you probably saw. I spent from 2002 to '08 creating a VFX pipeline, with global patent protection…

> went to VCs and angels and they were perfectly winning to fund a porn company, but not what I'd planned: an ethical rollout of a sensitive and very powerful technology with many legs Well, yes, that's kind of what the rest of us have come to expect from the industry. Ethical rollout is always going to take a back seat to raking in as much money as possible. I'm slightly surprised they were willing to touch porn tho…

It was absurd. My refusals began when they would insist on a technology proof that was creating nude celebrities in an image with them as the 2nd person. It was really amazing. Always guys, unable to contain their glee being horny, and insisting, insisting the company make porn. This was every single VC, it met with all of them. Angel investor groups too. It darkened my view of humanity.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#69
post #58
post #28

Earlier quoted context omitted.

Yeah, this would at least cause me to email my boss and say "Can you just confirm, you want me to transfer $25 million to this account? I'll hold off until you give me confirmation in writing" hell i do this if our tester hasn't managed to go over some aspect of our release. That way i get in writing from the product owner that he has OKd it, and if he sends me a teams message i ask him to email me confirmation.

Reminds me of that old urban legend about the trader who ordered the coal futures that eventually showed up as actual coal. In that story there's always an element where the subordinates who have to carry out the transactions have been abused to the point of never questioning his decisions.

There is a very well written version of this from many years ago on the Daily WTF:

https://thedailywtf.com/articles/special-delivery

It is written well enough that I could just about convince myself this actually happened!

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#70
post #2

I said this over a year ago elsewhere: Electronic engineers spent decades overcoming thermal noise floors so that humans could communicate over vast distances with small amounts of energy. AI researchers, in a few short years, undid all that by making computer-generated chatter and images indistinguishable from messages sent by humans. Until such a time as we live in a Bladerunner-like world of Replicants, being in-p…

we're probably ~10 years away from replicants. in 20years there's going to be millions of tesla humanoid robots all over the place

The whole point of Replicants is that they look exactly like humans in person. Even if we assume AI and robotics advance 100 times or more in the next 10 years to allow the technical part of this, we are not even close to any makeup and prosthetics tech that could make a robot even slightly resemble a human in-person.

And I have to mention, Tesla robots are way behind the competition, it's not even clear if their robot does anything really on its own, given how much they fake their videos of it with "creative" editing.

Post reply on HN