As Predicted: Scammers Are Now Scanning Faces To Defeat Biometric Security Measures

from the another-vulnerability dept

For quite some time now we’ve been pointing out the many harms of age verification technologies, and how they’re a disaster for privacy. In particular, we’ve noted that if you have someone collecting biometric information on people, that data itself becomes a massive risk since it will be targeted.

And, remember, a year and a half ago, the Age Verification Providers Association posted a comment right here on Techdirt saying not to worry about the privacy risks, as all they wanted to do was scan everyone’s face to visit a website (perhaps making you turn to the left or right to prove “liveness”).

Anyway, now a report has come out that some Chinese hackers have been tricking people into having their faces scanned, so that the hackers can then use the resulting scan to access accounts.

Attesting to this, cybersecurity company Group-IB has discovered the first banking trojan that steals people’s faces. Unsuspecting users are tricked into giving up personal IDs and phone numbers and are prompted to perform face scans. These images are then swapped out with AI-generated deepfakes that can easily bypass security checkpoints

The method — developed by a Chinese-based hacking family — is believed to have been used in Vietnam earlier this month, when attackers lured a victim into a malicious app, tricked them into face scanning, then withdrew the equivalent of $40,000 from their bank account. 

Cool cool, nothing could possibly go wrong in now requiring more and more people to normalize the idea of scanning your face to access a website. Nothing at all.

And no, this isn’t about age verification, but still, the normalization of facial scanning is a problem, as it’s such an obvious target for scammers and hackers.

Filed Under: , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “As Predicted: Scammers Are Now Scanning Faces To Defeat Biometric Security Measures”

Subscribe: RSS Leave a comment
40 Comments

This comment has been flagged by the community. Click here to show it.

This comment has been deemed insightful by the community.
MrWilson (profile) says:

Re:

It is functionally impossible. Any method can be circumvented. That doesn’t mean parents should give up. It’s their responsibility to protect their children from harm and educate their children on how to filter the things that can’t be avoided. It’s not a third party’s responsibility to give up their privacy or security because you have adopted a moral panic authoritarian battle cry and a soapbox.

There’s also a lot of things some people want to “protect” children from that they don’t need protecting from, such as the fact that gay and transgender people exist. Would you be okay with society restricting children’s access to religions that have notoriously been involved in child abuse?

“By all means necessary” functionally means either killing the internet or keeping children from communication devices until they’re adults, neither of which are tenable options.

This comment has been flagged by the community. Click here to show it.

This comment has been flagged by the community. Click here to show it.

This comment has been flagged by the community. Click here to show it.

This comment has been flagged by the community. Click here to show it.

BernardoVerda (profile) says:

Re: Re: Re:4

Jewish scholastic and legal tradition has recognized eight (8) genders, and the fact that not everyone fits neatly into a binary male/female biological sex, for well over two (perhaps even three) millennia.

Other cultures have, historically, have also noticed these manifestations of a more complicated reality, that don’t fit neatly into a strictly binary, XX/XY or male/female paradigm.

In modern times, scientists are discovering the concrete, physiological/biological underpinnings of this observable reality.

It would appear that your personal prejudices and cultural preconceptions are blinding you to observable facts.

MrWilson (profile) says:

Re: Re: Re:4

There are only two sexes in humans,

There are chromosomally more than two sexes.

https://en.wikipedia.org/wiki/Sex_chromosome_anomalies

Gender identity ideology is a deranged spiritual belief system.

It has nothing to do with spirituality. It’s a social observation regarding the perception of gender roles and efforts to change or restrict those. You are practicing “gender identity ideology” by making assertions about it. Your ideology just differs from the people you disagree with. That you think it must be tied inextricably to biological sex is just your particular bent.

You’ll never be other than your sexed body.

Apparently you aren’t familiar with the concept of people feeling disconnected from a sense of identity with their body, not related at all to a perception of gender, and even feeling disconnected from a sense of identity with their brain.

You’re a ghost sending out electrical signals from the gray matter you haunt to run a meat sack with a skeletal framework. Your ghost is just particularly hateful and confidently incorrect.

This comment has been flagged by the community. Click here to show it.

BernardoVerda (profile) says:

Re: Re: Re:

You can teach your children to swim, or you can try to scare/keep them away from/ “protect them from” open water till they are mature adults (or longer).

One of these approaches to keeping young people safe from drowning, though not perfect, is vastly more effective than the other one is (and helps them actually become functional adults with mature sound judgement as well).

Anonymous Coward says:

We’ve known that biometric”security” is anything but for quite some time. It’s trendy, it’s sexy, it’s all kinds of things, but one thing it isn’t is reliable. And it suffers (badly) from the key revocation problem.

Meanwhile, group-ib are all over the logs of my servers, attacking DNS and SMTP services. Oddly enough, I don’t recall giving them permission to conduct penetration tests of my operation.

Iain Corby (user link) says:

Phishing for faces

Phishing is a risk associated with the Internet as a whole, as the author rightly explains.

Facial Age Estimation can be conducted on-device, so the image need never leave the user’s control.

But just as when it is processed on a server, users must still trust the provider to manage data as they declare they will eg to delete images immediately or to process locally on device.

For that reason, we support close regulation of our sector with providers securing certification through independent audits to resssure users about data security, privacy and accuracy etc. Thess requirements are being documented in the latest IEEE and ISO standards.

So while phishing is a risk when accessing any secure or age restricted websites, it is manageable and we are doing more than many sectors to mitigate that risk.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Subscribe to Our Newsletter

Get all our posts in your inbox with the Techdirt Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...