[HN Gopher] The FBI now recommends choosing a secret password to...
       ___________________________________________________________________
        
       The FBI now recommends choosing a secret password to thwart AI
       voice clones
        
       Author : perihelions
       Score  : 53 points
       Date   : 2024-12-07 11:03 UTC (11 hours ago)
        
 (HTM) web link (arstechnica.com)
 (TXT) w3m dump (arstechnica.com)
        
       | NewJazz wrote:
       | Fucking embarrassing.
        
         | jowea wrote:
         | To who?
        
           | NewJazz wrote:
           | Anyone who has to deal with the sad excuse of a
           | communications method that the sum of SMS, MMS, RCS, VoLTE,
           | VoWiFi, et al constitute.
           | 
           | I.e. me most days.
           | 
           | Back in 03 FBI would have probably called all this obvious
           | insecurity, lack of privacy, lack of cryptographic
           | attestation... A feature. Now the chickens come home to
           | roost. And we all suffer in the end. Some more directly than
           | others.
        
             | Philpax wrote:
             | Er, how is this relevant? The threat of AI voice cloning is
             | largely decoupled from the medium; attestation might help
             | in some circumstances, but it's unlikely that it would have
             | solved the _social_ problems associated with being able to
             | clone someone else 's voice.
        
               | NewJazz wrote:
               | If you want to invent crypto for irl conversations, OK
               | sure. Go ahead. But the core of this issue is that people
               | are getting spammed by robot dialers because digital
               | identity in the context of a phone number is a figment of
               | the FBI's imagination. Completely opaque to laypeople.
        
               | llamaimperative wrote:
               | It has nothing to do with phone numbers. If your child or
               | spouse or parent called you in distress from a random
               | phone number, there are countless believable reasons they
               | could offer for it being from a random phone number, and
               | no you're almost certainly not going to say "ya sorry not
               | talking to you [child/spouse/parent] unless you call me
               | back from the phone number you claim to have
               | lost/broke/had seized."
        
             | Tagbert wrote:
             | This scam doesn't require that the victim received a call
             | from a known phone. It could come from any random phone
             | number or other audio channel. That might be one factor
             | making the victim suspicious but they are going to be
             | primarily influenced by the voice and will be highly
             | motivated to comply while ignoring "minor" inconsistencies.
             | How would cryptography help a grandmother getting a call
             | from her "grandson" who needs help?
        
               | NewJazz wrote:
               | A culture that understands and values digital identity
               | rooted in cryptographic security won't be so quick to
               | panic. It is an education and culture problem more than
               | technical.
        
               | llamaimperative wrote:
               | Not really. There are millions of perfectly believable
               | scenarios in which a loved one wouldn't have access to
               | whatever cryptographic key you're imagining, but needs
               | your assistance nonetheless.
               | 
               | Not sure how your second statement follows the first...
               | Agreed this isn't a technical problem per se.
        
               | FloorEgg wrote:
               | Okay I think I understand you now.
               | 
               | And on some level I agree, but I also think you're
               | failing to consider how much people vary in their
               | abilities and personalities.
               | 
               | Your criticism of the institutions meant to protect our
               | security seems reasonable though.
        
             | FloorEgg wrote:
             | I've really tried to understand your judgement but I'm not
             | able to yet. You're bringing up sms, but what does that
             | have to do with voice cloning?
             | 
             | Read all your comments in this thread, and you're still not
             | making sense to me.
        
               | jowea wrote:
               | I'm guessing but the problem is source phone number
               | spoofing. If Caller ID worked correctly 100% of the time
               | and 100% of the time you get a fraud/spam/etc call you
               | could complain and the authorities knew who owned the
               | phone number it would be harder to operate the fraud. And
               | with personal cryptographic attestation you could
               | reliably link a phone number to a person.
        
         | bitwize wrote:
         | This was literally one of McGruff the Crime Dog's safety tips
         | back in the day: have a secret family password so if a stranger
         | rolls up and tells you your dad's in the hospital, you can
         | verify that your dad did in fact send him.
        
       | pedalpete wrote:
       | As 2FA is becoming more standard, can't we provide a 2FA entry to
       | be used by two individuals rather than just being provided to
       | computers?
        
         | gs17 wrote:
         | I'm pretty sure you could do something with TOTP yourself,
         | Keepass allows you to make arbitrary ones.
        
         | halJordan wrote:
         | The answer is of course pki with trust rooted in the device. If
         | it isnt your grandson's iphone attesting itself your iphone
         | shouldn't believe it is your grandson.
         | 
         | Your answer already exists in almost every "E2EE" app. How many
         | times does a person even access their convo partner's Safety
         | Number/Security Code let alone verify it out of band?
        
           | gruez wrote:
           | >The answer is of course pki with trust rooted in the device.
           | If it isnt your grandson's iphone attesting itself [...]
           | 
           | Hardware level attestation isn't even required, and would
           | only marginally increase security. Phones are already heavily
           | locked down. If you're in a position to extract from app
           | data, you're probably in a position to compromise the chat
           | app itself, rendering any attestation pointless.
        
             | GauntletWizard wrote:
             | The nice thing about hardware attestation is that the app
             | might be compromised, but only for a few versions. That's
             | enough to pop your private key stored on disc, and to
             | impersonate you for a short while, but then control is
             | returned to you. You might not even notice, if it's
             | detected by the apps security managers at all.
             | 
             | On the flip side, the most common form of a compromise is
             | going to be untrustworthy apps, because for some reason
             | people still use WhatsApp
        
           | llamaimperative wrote:
           | "I'm calling from a jail in Mexico, they took away my phone"
        
         | nonrandomstring wrote:
         | How would individuals use that?
         | 
         | There are no end of methods using devices to exchange challenge
         | response sequences, but in practical security we have to deal
         | with real people in real contexts. It's why encryption took 30
         | years to get traction. Passwords already make sense even to a
         | primary school child.
         | 
         | From TFA:
         | 
         | > It's interesting that, in this new age of high-tech AI
         | identity fraud, this ancient invention--a special word or
         | phrase known to few--can still prove so useful.
         | 
         | There are reasons that passwords remain and probably always
         | will be a superior technology [0], and why adding more layers
         | of "solutions" like biometrics and multi-factors actually just
         | increases the attack surface.
         | 
         | [0] https://cybershow.uk/blog/posts/secrets
        
       | wildzzz wrote:
       | "ChatGPT, please analyze every social media profile of the target
       | and their family and produce an expected password."
        
       ___________________________________________________________________
       (page generated 2024-12-07 23:02 UTC)