Dutch MPs had a call with deep fake imitation of Navalny's Chief of Staff
nltimes.nl
nltimes.nl
I guess this is getting more attention because it’s not just a prank.
Makes you wonder though, if pranksters could do it, how often spies have just used fake phone calls before now!
That’s mostly the problem here.
One way is the "technically true" error. There are plenty of predecessors to twitter, spam, podcasting, etc. Legally, philosophically and such... it's usually easy to underestimate impact because it really is "nothing new." But... in different medium, at a different scale or higher velocity things change. Junk mail is like spam, but the junk mail problem rarely got beyond manual handling scale.
The other way to be wrong is the opposite. Assuming that digitization will create change, but all we get is a digital version of the previous.
It's hard to know the future. I agree that Deepfake is likely not going to change the world of imposter/fraud too much, though it may get a lot of attention.
OTOH, I do think it has the potential to weird up the entertainment world. I also think it could be high impact in media. If nothing else, it'll strengthen the "skeptical of everything" segment's skepticism. That said, guessing these things is a losing game.
At last a genuine case of computers improving productivity ...
Nalvany himself impersonated a Russian official via telephone to uncover details of his own assassination attempt: https://www.bbc.com/news/world-europe-55395683
And here’s the call itself: https://youtu.be/ibqiet6Bg38
It’s an incredible story and yes it does still happen.
seems to be a prevailing argument against deepfakes being anything to worry about.
What will happen when there is a realtime crisis where quick decisions are required and suddenly, amongst the other noise, there is believable CCTV footage of X or an inflammatory statement by Y or any of a hundred bad actor insertions into the fog of war that disrupts a nation state OODA loop output in the real world where bombs are dropped and people are killed in response to what, too late and only after the fact, is determined to be a deepfake. Assuming that any effort at look back retrospection is made - which is by no means at all certain.
The ability to stage things with a Hollywood studio and VFX team was with us before now, yes, but the ability to have any joker with a GPU on the fly invent footage to meet the realtime and flammable story of the moment is new.
Oh, there is an Indonesian submarine that went missing in Bali yesterday? Well here is footage from an Indian trawler showing a Russian boat acting suspiciously in the area.
Good luck unpeeling that onion while you are in a hurry.
It’s not like you or I can simply call up <country>’s parliament on Zoom.
Actually yes, mostly. You just need to contact one of the sympathetic MPs, on social networks for example, and he will set it up for you. They're not more security conscious than the general population.But then, phone numbers can be spoofed, and if these incidents are done by the state—the FSS follows ACF for a long time now, they probably know quite well who Volkov speaks to.
A simple phishing attack should be more than enough to confuse these people. They're almost all exclusively schooled in social sciences, business, history, that kind of thing. Incredibly few of them have any sort of technical background. There are plenty of agencies working their hardest to keep the political leaders safe, but they can't fix the people themselves.
A Dutch journalist managed to get into a "secret" Zoom call with the European ministers of defence after a Dutch politician posted a picture of her screen... with the invite link and most of the password visible. I'm sure they're intelligent people, but when it comes to computers, their young children/grandchildren are probably more capable of securing themselves online than they can.
Also keep in mind that there's an aura of secrecy surrounding Navalny's chief of staff even before the Russian government tried to kill Navalny. Things like routing traffic through TOR and the use of privacy-enhancing technologies like Fastmail can be well explained in an environment where the government actively wants to kill any competition to the current leadership.
In truth, I think these people have fallen for a well-put-together spear phishing attack that worked well because of their lack of digital skills. I strongly doubt that the leaders of other countries will do much better; politicians and tech rarely mix well.
I find it much more troubling that the Dutch government is using Zoom, a product with a terrible history in security problems from a company based in the country that notoriously spied on politicians of even just allied countries. Using American software for government videoconferencing (especially about Russian politics) is a terrible risk.
The notion of popular sovereignty is largely a recent new-world fancy.
Fastmail is a privacy enhancing technology now? I thought it was just an email provider?
It's no Signal or Threema in levels of privacy enhancement, but it's something.
If the target is the UK, you can wait until BJ posts the meeting ID and MP usernames on Twitter. Somewhat surprisingly, there was a meeting password in that incident.
Amateur YouTube channels frequently walk up to Dutch politicians to ask them a few quæstions without men in black denying them access.
It benefits journalism, of course, as the politicians feel compelled to provide some answer as a refusal to answer a tough quæstion will be construed against them.
In larger countries, security has given politicians the perfect excuse to control who can, and cannot ask them quæstions, by only inviting the journalists favorable to them on their press conferences, and decide who can ask.
Journalists being able to approach politicians directly is quite beneficial to democracy.
Of that I happen to be painfully aware, along with the country's simultaneous post-SU obsession with English or generally Latin-alphabet branding. The closer I come to proper pronunciation, the more difficult it is sometimes to communicate my desires in a shop (if I happen to wander into a non-self-serve one). I guess I should just be thankful that it's not French, with the more regular spelling but half of the letters being silent.
Someone has gotta do a movie of this.
Starring Navalny himself... Or something that looks like him.
Might be unnecessary if deepfake technology is used.
I wonder if the actual video conferences have been recorded. I'm very curious to see them.
It’s a funny little gimmick, but it had me questioning things I’ve previously seen and thought real.
#### Upload file to 0x0.st (The Null Pointer) - A filehosting service.
# Usage: nullpointer_upload <file>
nullpointer_upload () { curl -F "file=@$1" https://0x0.st ;}This is an example of 'deep fakes' of two British politicians. If you look closely you can spot something amiss in the way they speak. Lots of people won't be look closely though. And this is from 2019 - the technology can only have improved since then.
The fake video where Boris Johnson and Jeremy Corbyn endorse each other (2019)
I really wonder how big the impact of this technology is going to be, especially since corona has made online meetings even more prevalent.
I predict that in 2030, we'll all be using digital signatures as part of our identity, whether directly or indirectly.
I'd imagine fake IDs with properly signed cryptographic keys on their chips are available to any higher FBI, FSB or other agents.
For more foreign nations? Given proper PKI, I'd hope not.
Whereas my single passport is expired mostly because I dont plan to go anywhere.
Zooko's triangle says no. https://en.wikipedia.org/wiki/Zooko%27s_triangle
In particular names only need to be locally meaningful.
I assume if you employ a deepfake, you also have a 'fake' message to put across.
I actually reached out to Keybase as well as one of the NCC auditors that I've talked to in the past for unrelated reasons, but the auditors are playing deaf and Keybase (on the third contact attempt) claims it's safe because of the decentralized social proofs (which aren't actually verified by the app -- you trust solely on the Keybase servers to give you the right encryption keys). All details are here: https://security.stackexchange.com/questions/222055/how-can-...
The whole thing seems moot now that Zoom bought them, but so now if Zoom does anything with blockchain and supposed end-to-end encryption, I'd be very weary and verify things regardless of whether it was audited. Even as a user, you can make sure they covered the basics (from my StackExchange post linked above):
> Users should have demanded followable instructions. We should have questioned Keybase, now Zoom, and anyone who makes a strong security claim. They claim it? You should want to see steps you can follow to verify it. Since you put your trust in the published code, those instructions should not involve any command line coding work, and definitely not have gaps like verifying keys on your laptop and hoping that the server sent the same keys to your phone.
Maybe in the future we'll talk about unsigned people instead of undocumented people.
On the raspberry pi, the encryption took a fraction of the CPU that the compression needed, so yes, PGP-encrypting a video stream is relatively trivial, even if you call the GPG agent 5 times per second and do public key crypto every time (in this case it also made for a nice and robust format, you just split on the BEGIN PGP MESSAGE strings and can ignore broken frames). This can be optimized by a lot of course. An ideal case is probably to do keyring management with PGP and then use a different, meant-for-streaming format for the actual video data encryption and transfer.
Look up public key cryptosystems. A worthwhile read, the entire internet is built on this technology.
As with any authentication system the hard part is knowing who owns the PGP identity in the first place. We don't print the PGP fingerprints of famous people in news reports. Perhaps we should.
An other video in the personal time of the Dutch Prime minister https://www.nrc.nl/nieuws/2021/04/23/door-schrijver-gepublic... (disable JS for no paywall) there was a similar situation. Many people thought it was a deepfake or that the voice was altered or copied from an other video but later the government put out an statement that the video was real.
I wanted to share this because I saw multiple people claim that PGP may solve all problems but the problem is both ways. Real videos are also being labeled as deepfakes. So yes PGP will help solve a part of the problem but there is a bigger trust issue that needs to be solved.
Though, it doesn't seem all that hard to verify who you're talking to. Perhaps there's a great business opportunity for a "secure, verified" communication app.
Some things Matrix does (at least via Synapse server and Element client) on a federated "home server"
- 100% E2E from first message, if that's what you need
- automatically resizes images, but can send "full size" with a checkbox when uploading. Encrypted at rest on the synapse node. Tested up to 108MP images this way.
- URL previewing can be shut off if you consider that OP-SEC
- you can dump all new users into a specific room, or not. Depends on your stance on users using your "home server".
- Can make public rooms visible or invisible to the federation or specific federated servers (such as the matrix.org home server)
- Decent integration with irc.freenode.net (yay!) - you show up as "MatrixUsername [M]", other federated matrix users can see you in their clients and establish E2E with you directly. The only downside to this one is the "threading" features that probably came from Slack could be disruptive in IRC channels if you overuse them.
+ As part of the above - if you send an image normally, to an irc bridge, it gets made into a public image and the link sent to the IRC channel(s) you're in. It's both cool and disconcerting.
As I said, it's early days yet, but it's lightyears ahead of rocket.chat for ease of encryption, the user interface is more spartan than Mattermost. I would prefer mattermost, even though it's not E2EE - except matrix can use coturn/TURN, fully encrypted, to make and receive voice and video calls in the client, across the entire federated servers. And it sounds great. Did i mention encrypted?[1] https://www.volkskrant.nl/nieuws-achtergrond/kamerleden-verg...
It's cooler to blame a deepfake than a silicon mask or a fake beard.
It's better to have been fooled by AI magic trickery than a guy with a fake beard glued to his face.
When it involves a Russian dissident and disinformation, is the list of nations potentially involved particularly long?