Live data from Hacker News

British engineering giant Arup revealed as $25M deepfake scam victim

cnn.com

91–100 of 109 posts

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#91
post #54
post #48

Earlier quoted context omitted.

I know it's a meme and all, but doesn't blockchain solve this? Ok, Mr. Guy who looks like my boss on Video Call, I can send those funds, just sign the transaction with your private key and it'll all be done.

Blockchain does not authenticate the receiver, so there are all sorts of attacks involving substituting the payment address, from dumb (stickers over QR codes) to sophisticated.

That’s a completely different thing though. The problem here is deepfakes where someone pretending to have the authority to send money tells you to send money.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#94
post #2

I said this over a year ago elsewhere: Electronic engineers spent decades overcoming thermal noise floors so that humans could communicate over vast distances with small amounts of energy. AI researchers, in a few short years, undid all that by making computer-generated chatter and images indistinguishable from messages sent by humans. Until such a time as we live in a Bladerunner-like world of Replicants, being in-p…

Human written text has been indistinguishable from machine written text for a very long time. We've still managed to maintain chains of trust to discern legitimate messages with decent success rates.

Or we’re really bad at detecting fraud.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#95
post #52

Earlier quoted context omitted.

There are many secrets in business, especially in realestate. Found out, from some "unnamed source" that there will be a new bus stop and a new aldi store across the street from a building where some apartments are for sale? Don't mention it to anyone, secretly buy them, because their value will go up a lot, and do it discreetely, so other companies don't notice.

It's a bit surprising that Aldi (and other supermarket chains) generally don't invest in residential real estate.

Over half of Aldi's locations actually belong to them [1]. Keeps them safe from the usual landlord racket.

[1] https://www.lebensmittelzeitung.net/handel/nachrichten/immob...

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#96

Earlier quoted context omitted.

"in secret" is the issue

I guess a scammer can sell it as "we're buying something significant [another company?], this will affect our share price if the info goes out, so you need to sign this NDA and keep this quiet, you're only 1 out of 10 people who knows this...". They could also sell it as payment for an e.g. consulting firm for the above secret deal...

Arup is a private company

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#97

Earlier quoted context omitted.

If I was the attacker, I'd use credential-stuffing or something to get access to some random employee's account. Doesn't have to be anyone important. Then I'd set up a short-notice multi-way meeting between the target, the CEO and the hacked account. The deepfake 'CEO' then turns up with no alarms raised, except one wrong name - easily dismissed as a glitch, or an assistant having booked the meeting.

So your method assumes you can easily take over an employee account? Isn't that the hard part?

Employees are typically the weak point in corporate security.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#98
post #45

Earlier quoted context omitted.

When I'm on a company video call, the people I'm meeting with are logged into their company accounts, through the fancy company authentication system. Large warnings are displayed if there are any external participants, and I wouldn't be surprised if it's possible to disable the ability to even have guests. Third-party video conference software is banned and blocked from installation on work computers. I am not in th…

If I was the attacker, I'd use credential-stuffing or something to get access to some random employee's account. Doesn't have to be anyone important. Then I'd set up a short-notice multi-way meeting between the target, the CEO and the hacked account. The deepfake 'CEO' then turns up with no alarms raised, except one wrong name - easily dismissed as a glitch, or an assistant having booked the meeting.

But that CEO account would be marked as (guest/unverified) in Teams or Zoom.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#99
post #26

Earlier quoted context omitted.

What's wrong with good ol' private keys?

Same as with public transport. You can’t have because it’s haram for some political position

Nobody is anti-public-key crypto per se any more, the US government export control war ended long ago. It's just too much of a hassle to do the key management.

Re: British engineering giant Arup revealed as $25M deepfake scam victim

#100

I think the underlying problem is cultural: people have been conditioned to expect others to authenticate them (give me the last 4 digits of your SSN, tell me the last two transactions on your account), BUT they haven't been told they need to authenticate others. They just aren't thinking "how do I know this is who I think it is? How do I know they haven't been kidnapped?".

My personal protocol with my bank when they ring me is for me to call them back.

The bank workers are normally quite understanding - except when it is someone from fraud detection (and yes these are legitimate calls) and they tend to get odly defensive that I wont hand out my personal information.

Post reply on HN