[HN Gopher] The FBI now recommends choosing a secret password to...
___________________________________________________________________
The FBI now recommends choosing a secret password to thwart AI
voice clones
Author : perihelions
Score : 53 points
Date : 2024-12-07 11:03 UTC (11 hours ago)
(HTM) web link (arstechnica.com)
(TXT) w3m dump (arstechnica.com)
| NewJazz wrote:
| Fucking embarrassing.
| jowea wrote:
| To who?
| NewJazz wrote:
| Anyone who has to deal with the sad excuse of a
| communications method that the sum of SMS, MMS, RCS, VoLTE,
| VoWiFi, et al constitute.
|
| I.e. me most days.
|
| Back in 03 FBI would have probably called all this obvious
| insecurity, lack of privacy, lack of cryptographic
| attestation... A feature. Now the chickens come home to
| roost. And we all suffer in the end. Some more directly than
| others.
| Philpax wrote:
| Er, how is this relevant? The threat of AI voice cloning is
| largely decoupled from the medium; attestation might help
| in some circumstances, but it's unlikely that it would have
| solved the _social_ problems associated with being able to
| clone someone else 's voice.
| NewJazz wrote:
| If you want to invent crypto for irl conversations, OK
| sure. Go ahead. But the core of this issue is that people
| are getting spammed by robot dialers because digital
| identity in the context of a phone number is a figment of
| the FBI's imagination. Completely opaque to laypeople.
| llamaimperative wrote:
| It has nothing to do with phone numbers. If your child or
| spouse or parent called you in distress from a random
| phone number, there are countless believable reasons they
| could offer for it being from a random phone number, and
| no you're almost certainly not going to say "ya sorry not
| talking to you [child/spouse/parent] unless you call me
| back from the phone number you claim to have
| lost/broke/had seized."
| Tagbert wrote:
| This scam doesn't require that the victim received a call
| from a known phone. It could come from any random phone
| number or other audio channel. That might be one factor
| making the victim suspicious but they are going to be
| primarily influenced by the voice and will be highly
| motivated to comply while ignoring "minor" inconsistencies.
| How would cryptography help a grandmother getting a call
| from her "grandson" who needs help?
| NewJazz wrote:
| A culture that understands and values digital identity
| rooted in cryptographic security won't be so quick to
| panic. It is an education and culture problem more than
| technical.
| llamaimperative wrote:
| Not really. There are millions of perfectly believable
| scenarios in which a loved one wouldn't have access to
| whatever cryptographic key you're imagining, but needs
| your assistance nonetheless.
|
| Not sure how your second statement follows the first...
| Agreed this isn't a technical problem per se.
| FloorEgg wrote:
| Okay I think I understand you now.
|
| And on some level I agree, but I also think you're
| failing to consider how much people vary in their
| abilities and personalities.
|
| Your criticism of the institutions meant to protect our
| security seems reasonable though.
| FloorEgg wrote:
| I've really tried to understand your judgement but I'm not
| able to yet. You're bringing up sms, but what does that
| have to do with voice cloning?
|
| Read all your comments in this thread, and you're still not
| making sense to me.
| jowea wrote:
| I'm guessing but the problem is source phone number
| spoofing. If Caller ID worked correctly 100% of the time
| and 100% of the time you get a fraud/spam/etc call you
| could complain and the authorities knew who owned the
| phone number it would be harder to operate the fraud. And
| with personal cryptographic attestation you could
| reliably link a phone number to a person.
| bitwize wrote:
| This was literally one of McGruff the Crime Dog's safety tips
| back in the day: have a secret family password so if a stranger
| rolls up and tells you your dad's in the hospital, you can
| verify that your dad did in fact send him.
| pedalpete wrote:
| As 2FA is becoming more standard, can't we provide a 2FA entry to
| be used by two individuals rather than just being provided to
| computers?
| gs17 wrote:
| I'm pretty sure you could do something with TOTP yourself,
| Keepass allows you to make arbitrary ones.
| halJordan wrote:
| The answer is of course pki with trust rooted in the device. If
| it isnt your grandson's iphone attesting itself your iphone
| shouldn't believe it is your grandson.
|
| Your answer already exists in almost every "E2EE" app. How many
| times does a person even access their convo partner's Safety
| Number/Security Code let alone verify it out of band?
| gruez wrote:
| >The answer is of course pki with trust rooted in the device.
| If it isnt your grandson's iphone attesting itself [...]
|
| Hardware level attestation isn't even required, and would
| only marginally increase security. Phones are already heavily
| locked down. If you're in a position to extract from app
| data, you're probably in a position to compromise the chat
| app itself, rendering any attestation pointless.
| GauntletWizard wrote:
| The nice thing about hardware attestation is that the app
| might be compromised, but only for a few versions. That's
| enough to pop your private key stored on disc, and to
| impersonate you for a short while, but then control is
| returned to you. You might not even notice, if it's
| detected by the apps security managers at all.
|
| On the flip side, the most common form of a compromise is
| going to be untrustworthy apps, because for some reason
| people still use WhatsApp
| llamaimperative wrote:
| "I'm calling from a jail in Mexico, they took away my phone"
| nonrandomstring wrote:
| How would individuals use that?
|
| There are no end of methods using devices to exchange challenge
| response sequences, but in practical security we have to deal
| with real people in real contexts. It's why encryption took 30
| years to get traction. Passwords already make sense even to a
| primary school child.
|
| From TFA:
|
| > It's interesting that, in this new age of high-tech AI
| identity fraud, this ancient invention--a special word or
| phrase known to few--can still prove so useful.
|
| There are reasons that passwords remain and probably always
| will be a superior technology [0], and why adding more layers
| of "solutions" like biometrics and multi-factors actually just
| increases the attack surface.
|
| [0] https://cybershow.uk/blog/posts/secrets
| wildzzz wrote:
| "ChatGPT, please analyze every social media profile of the target
| and their family and produce an expected password."
___________________________________________________________________
(page generated 2024-12-07 23:02 UTC)