OnlyFake: A site where ‘neural networks’ churn out fake IDs
404media.co
404media.co
OnlyFake lets essentially anyone generate fake IDs in minutes that may seem real enough to bypass various online verification systems. Or at least fool some people
Blocked by Signup: https://i.imgur.com/vrkQ8rS.png
Unblocked: https://i.imgur.com/R74nUPt.png
(This post was edited after Dang's comment)
Please don't respond to a bad comment by breaking the site guidelines yourself. That only makes things worse. I know the GP was provocative, but your comment would be fine without those bits.
> In December, we noticed that articles we spent significant amounts of time on ... were being scraped by bots, run through an AI article “spinner” or paraphraser, and republished on random websites.
> Requiring an email address to read our articles has, for the moment, stopped our content from being scraped and repurposed by AI.
JAN 26, 2024 AT 9:36 AM
Where AI could come into the picture, so to speak, would be in cleaning up a random selfie photograph that is not suitable as an ID photo, into an ID photo. Changing the lighting, removing the background, and perhaps adjusting the facial expression.
Using AI for the remaining textual parts of the ID would only lead to defects.
2. An image of ID printed on glossy photo paper (which I'm guessing this is) is not going to fool anyone who asks you to take your ID out of your wallet. This is only good for flashing in someone's face to get into a club.
Given how political a topic IDs are in the US even in their physical/offline variant, I'm not holding my breath for that.
However, in the banking case (and likely government, but I cannot speak to that directly) they are running your data against a KYC API so chances of your information being valid are low.
This flow was designed, and only works, for branch-based KYC: The bank employee physically looks at the ID, makes sure it's you, examines the many physically hard-to-forge elements on the card, and then queries an API that tells them whether the same ID was ever issued with that data on it (name and photo).
Bringing that flow online in the age of GANs is an absurd concept, right up there with using a short, unchangeable numeric personal identifier as a bearer token for authentication. The fact that financial institutions in some countries actually do both doesn't make it any less absurd.
They offer all validations behind an API, so you don’t need to know how a Nigeria driving license looks like.
Nice people and nice products.
Even if the rest of the ID is fake, at least you have a record of that person's face; you can attest to the fact that the person who gave you the ID, whoever they may be, looks like the picture you have.
This stuff would work decently well for the "send us a photo of your ID for verification" shit that is more and more common online.
In the UK, if I want to hire a car, I have to provide a code from a Government website which is tied to my driving licence. The hire company check the validity of my licence using that one-time code.
Similarly, the passport service provides an API which lets authorised organisations check the validity of a passport.
Relying on a photo of a document is as ridiculous as relying on a signature on a credit card receipt!
Seriously, this is not kind of shenanigans you want to be doing for no reason at all, simply because the reason would be invented by someone else.
It's probably well past time for legislation prohibiting anyone else for using it for that purpose, preferably with some teeth.
As you say, most people's SSAN has been compromised many, many times.
No, it is time for legislation prohibiting people from being held responsible for a business’s lack of due diligence. If the lender wants to use SSN to give out thousands of dollars, that is entirely on the lender.
The businesses will automatically stop using mechanisms of identity verification that cause them to lose money.
The only problem is the government has foisted the costs of the lender’s due diligence onto the general public. If a lender wants to collect on debts, they should need more proof than an SSN/DOB combo, and no one should have to spend time correcting their credit report from no fault of their own.
You could both limit the victim's responsibility for identity theft, and prohibit businesses for using the SSAN as a means of identification, with a whopping fine attached.
> The businesses will automatically stop using mechanisms of identity verification that cause them to lose money.
You mean like if they were forced to pay a gigantic fine?
https://www.neon-free.ch/en/blog/about-neon/identification-v...
I have a single proper horror story with otherwise flawless (yet nontrivial) Swiss bureaucracy - one of those situations where you are completely at the mercy of incompetent bureaucrat which couldn't care less, to allow just your basic existence in this country as a highly sought-after expat, since evidently solid past 12 years means nothing.
You see the process working on others within few weeks yet you are stuck there, without any info apart from 'wait', without any option to anyhow contact physical person handling your case, your main permit allowing your existence here expiring, yet the evidently lazy bureaucrat which sometimes picks up official phone for whole bureau doesn't bulge a bit, stating 'there is no time limit how long this could take, bye'. I tried naively to just go to the bureau but was literally kicked out of the building. Literally untouchable folks.
And then other bureaucrat by chance picks up a phone and takes a look after a year during one desperate final call, balks in horror and WTFs, goes on 5 minute tirade full of apologies (I guess I could sue Geneva canton for undue stress on me and whole family since that shit was real we could be easily forced out) promptly does everything in 5 minutes.
Yeah, using bad (phone) photo copies of IDs in 2024 is the least problem with Swiss bureaucracy for me here, there seems to be a lot of ingrained trust in the system (which is great when it works).
Most likely what happened is your case (in a physical form of a folder) was simply in a wrong physical place, forgotten, not transferred to a different case worker after a previous one retired/went on vacation/etc or otherwise slipped through the cracks.
Email response from filled cantonal online form came back after 3 months, with... 'wait'.
Till this day I believe this was an actual evil person getting kicks from this slow suffering of poor desperate foreigners who have absolutely 0 way of doing anything, even having decent polite conversation. And its hard to ignore the fact that suing an office which maybe will issue you most important papers in your life may not be the smartest course of action.
They say its roughly 1/20 sociopaths and 1/100 psychopaths in general population, not that hard to meet them if you are unlucky.
Have also had a provider that insisted on sending in a picture of a barcode for something (too many users entering in the values wrong), but on their side, it was just a human typing them in, and still made an error.
There is a non-profit, AAMVA (AMERICAN ASSOCIATION OF MOTOR VEHICLE ADMINISTRATORS) which provides some businesses with access to verify ids in some states. A list of states supported is here https://www.aamva.org/identity
That said, things are changing and hopefully more states will adopt something more standardized.
Adoption is painfully slow.
EDIT: Yes, there are other groups/ideologies that also think that having fifty or so separate state databases for a basic administrative function is better than having one federal database. Not sure how much political power sovereign citizens or libertarians have compared to evangelicals, but consider yourself counted, I guess.
And the gun people. And the sovereign citizens. And the "states rights" people. And the constitutional originalists. And the capital-L libertarians. If you don't want to carry an ID card, there is a variety of communities to help you amplify that opinion in the most annoying and disruptive ways possible.
Unless of course the real push to sabotage it comes from people actively interested in having fraudlent ids in circulation or rely on undocumented people to do low-paying jobs, or something.
Don't want to have a federal id? Sure, here is your federated id prefixed with TX-, with all the PII stored in a datacenter in your state. Don't want to have another id issued? Sure, type in the number of your driver license issued when you were 16 years old. Don't like numbers at all? Okey, type in your baptism name, dob and the name of the church or apply through a snail mail.
It's not like Europe has a pan-european id issuing authority or a single unique number to identify a person through all of the databases on a continent. Even if did, some people would still have another identity number in US to open an account there.
(Along with a surprising amount of stuff we still have like National Police, Mother's day, being on the UTC+1 timezone, the alarm siren we get every first wednesday of the month, Licence IV for opening bars, etc)
"Say what you want about the tenets of National Socialism, at least it's an ethos."
(Although a lot of these measures were pretty police-state-ish.)
Well that sounds as useless as it would be frustrating.
And yeah, the usefulness is dubious.
Or opposition who know just how many times national IDs have been used as a tool for oppression and murder.
Hint: a lot. Not just in Nazi Germany or the Soviet Union, either.
The Hutus and Tutsis in Rwanda look pretty much the same, and even speak the same language. Rwanda had a national ID card system that identified which one you were, which made matters much simpler for the genocidal murders.
South Africa had "passbooks", used to enforce the infamous "pass laws".
And so on.
Dismissing those concerned about privacy as "religious fanatics" is both unfair and incorrect.
I'm not sure how a state-level database is supposed to be safer in real life. The idea that state governments are somehow less dangerous to minority groups than the federal government conflicts with large swaths of US history.
[1] https://www.wired.com/2012/12/upc-mark-of-the-beast/
[2] https://www2.cbn.com/article/finances/are-credit-cards-assoc...
[3] https://www.usatoday.com/story/news/nation/2021/09/26/covid-...
It will be relevant in a very improbable case the states would be at war with each other. It's an odd threat scenario to optimize for, but maybe something like that happened already and people are still not happy about the result. I dunno.
You do realize that's actually happened before, right?
Yes, you are. You're lumping everyone opposed to a national ID into the category of "religious fanatics".
> I'm not sure how a state-level database is supposed to be safer in real life.
Because mitigates the potential number of victims. The population of the United States is about 330 million. The population of California (the most populous state) is only about 39 million.
Now, some states would cooperate with a potential tyranny, and hand over their databases.
Others... would not.
That is an extreme exaggeration and not even close to true. There a myriad of legitimate reasons to not want a national ID. My reason, for example, is that States are sovereign and identifying citizens is not a Constitutional power given to the Federal government.
I would also argue that the Federal government has sneakily made a national ID with the RealID initiative.
lol. come on. Passports the IRS, etc. The federal government implicitly and explicitly has the right to identify you.
Are you aware that not all rights granted to the government are in the constitution?
I can tell you are going to want to dispute that, but doing so would only be a display of ignorance.
Plenty of rights the government has are are a result of later caselaw or legislation, and not outlined in the constitution. If you want to say those don't count, then you're probably a 'sovereign citizen' type.
Way to attempt to be dismissive of a literal reading of the Constitution that ostensibly governs this country. If a sovereign citizen is somebody that believes in self-governance of the people then, thank you. This country was created and defended by people that believe this. I am proud to be part of that tradition.
10th Amendment The powers not delegated to the United States by the Constitution, nor prohibited by it to the States, are reserved to the States respectively, or to the people.
So, 10th Amendment says that later caselaw and legislation that gives more power to Federal government than was defined in the Constitution is illegal. The only way the Federal government can legally get more power is through Constitutional amendments.
lol, called it.
> All powers that the Federal government has are explicitly granted in the Constitution.
This is just incorrect. As I said, caselaw and legislation grant rights not explicitly in the constitution.
That's just a fact, and I'm not really interested in debating it or any various fringe theories of how some people think things ought to work, anymore than I have an interest in debating Pangaea existed or that the sky during daylight generally appears blue to humans.
Take care.
Seems like convincing that website I am you would be the weak point here. I'd be more concerned about that than someone spoofing my id like they are doing here. Because in the future I could almost definitely prove they spoofed my id. Not so with accessing a website.
Of course the government databases via APIs is more secure, but that doesn't make everything else ridiculous.
Saying the US isn't modern because of this one thing is silly. The US ostensibly leads technological investment, has the an advanced military, puts rockets in space and recovers them, had the internet before most of the world, iPhone, all the software we all use the world over, the list goes on.
Such a site/AI might put pressure on widespread usage for the same or a similar service but there will be political and ideological pushback - for sure.
So no I don't think this is an example of the US failing whatever it is this week. Even if it may be quicker or easier to push through such changes in wildly different political and cultural environments.
https://www.thetruthaboutguns.com/liberty-safe-changes-its-p...
there's a point to be made for expections of strong security where it's actually weak, but is no security at all really better than bad security?
Once it's good people will outsource the work to what is essentially a CA system where every BMV in America is an issuer and I expect it to hold up at best as well as SMS verification.
Why not let notaries or an authoritative agency issue cryptographically signed one time codes upon inspection of your physical ID? Frankly, it sounds like a superior system to me.
A government identity to do business with the government might just about be possible. A government identity to cover everything done by everyone everywhere is not. The value of cracking that system is just too high.
So the value of the system being broken is too high, yet we live in a world where it's broken, as anybody can make a photoshop of your driving license? I'm sorry I don't get the argument.
This is generally a counter to people using binary thinking and believing that a security system is broken if there is any way in at all, thus thinking things are either in the categories "secure" or "insecure" without any further qualification. In fact those categories don't exist. It is intrinsically at a bare minimum a spectrum of security, and one can slice & dice more finely if one likes based on what sort of attacks various different types of attackers can mount, e.g., defending against whole-internet scans is one thing, nation-state attackers specifically targeting you quite another.
I'm using it in a different way: When what you want to lock behind your security system is essentially "all economic value in the world", such as "we'll solve all identity problems on the internet by just having the government provide identities", that means you need to create a security system that is more expensive to break than "all economic value in the world". However, you can't. Any conceivable security system is easier to break than that.
There is a sense in which it is simply necessary that there be a wide variety of independent identification systems, each individually covering sufficiently small amounts of value that they are possible to exist at all, and with a diversity of costs and strengths to cover the various cases.
Do I really?
Let me send you that totally secure fax with my totally secure signature drawn by hand. Far more secure than a digital document signed by this scary, newfangled electronic signature, which could have been hacked and is therefore totally insecure.
On the other side of the spectrum, there is Dutch digi Id, which is the only way to use any government service online and works either with pure and simple username+password or a second factor through the app. There is no rocket since involved -- government agency sends you an activation code to your registered address and you activate the app.
Then there is Ukrainian Diia, which is kinda both and also bundles government services themsevles and a digital id generator into the same app. But it's all built on top of existing PKI infrastructure that is used for decades before to tackle the problem of district tax office doing shenanigans with your tax reports.
Add:
And of course the most no brainer way to roll it out in a fragmented landscape of US is to let banks be Oauth2 providers, as they are already tasked with KYC stuff and have a license to lose. See https://www.bankid.com/en/
refs:
https://www.concretecms.com/about/blog/devops/how-make-us-go...
That doesn't stop banks from pulling all kinds of shit with their customers' identity or what they believe to be that. The amount of credit scams possible in the US is mind-boggling for me as an European.
Such as?
[1] https://en.wikipedia.org/wiki/Wells_Fargo_cross-selling_scan...
Yeah, the same works in the Czech Republic, the banks provide an OIDC service, including document signing, see https://www.bankid.cz/en
It hasn't caught on for verification outside of government yet.
Everyone in possession of an ICAO 9303-compliant ID card / password (so, at least everyone in Europe) already has such a thing. These cards can be read by any NFC enabled smartphone that can act as a reader, and the chips themselves can act as a a secure element capable of a range of cryptography functions.
The problem is that while ICAO 9303 is a standard to retrieve and verify the data, it's fundamentally based on the assumption that it is just used to retrieve the data written in cleartext on the card as well as the biometric data so that you can build a staff-less boarding solution for air and sea ports. It's just a read-only dump of the data, signed with a certificate from the card issuer.
We'd additionally need a standard similar to what Germany and Croatia have done that allows a person to use their computer or phone as an NFC reader "proxy" to create a digital signature against a service-provided challenge that can then be traced back to the government's PKI.
Or, to put it in SSL terms, each government has a root CA, that issues a sub-CA certificate to the card producers ("can issue certificates for #.de"), who in turn have the card provision its own public/private keypair, and then sign the card's public key to use as a sub-CA ("can issue certificates for #.person-identifier.de").
Why bother with NFC if the phone itself has secure enclave and a biometry check to lock it down too?
And the best part of course, the federal government of US doesn't just have a standard, but actively uses all that for quite some time, just explicitly without NFC.
There have been a lot secure-enclave exploits against both Apple [1] and everyone else [2], and fingerprint readers can also be bypassed. The Secure Enclave itself has a giant attack surface and is highly complex. (That however does not stop dreams of "digital driver's licenses" and whatnot, though, but that's another question)
In contrast to that, ISO 7816 smartcard stuff has been in use for decades, and (unless it's Javacard...) a very limited complexity. It's rare to see something else other than sidechannel attacks.
[1] https://news.ycombinator.com/item?id=24025502
[2] https://www.zdnet.com/article/manual-code-review-finds-35-vu...
The German AusweisApp2 is fully open-source (to protect against the first scenario), and it might be possible to do it in a web app assuming Web NFC gets more widely supported [1].
The second scenario is protected against by the keys being provisioned on the smartcard during manufacture (or, if the user so desires, at the touchpoint where they get handed over the ID card) and being unable to be exposed, at least not without either destructive methods or side-channel attacks.
[1] https://developer.mozilla.org/en-US/docs/Web/API/Web_NFC_API
Never heard of any successful identity thefts in this system, except where someone has been tricked into signing something with their BankID that they shouldn't have. That's pretty hard to defend against on a systematic level though, at least in a way that's fool-proof.
It really doesn't take much to get to the "take a picture holding the ID" step, which can still be fooled but is much more difficult than this (especially for AIs when it comes to finger count lol). But "turn your head left and right" is also pretty easy to incorporate.
If you're not making even a basic effort to confirm the person submitting the ID actually exists, your customers are already screwed. They just don't know it yet.
I'll admit I don't do much with image generation, but hands still seem to be a weak point, which is why I added a parenthetical jab at the whole system.
Finger count problem has been basically solved since Fall 2023.
The simple truth is that remote identity verification of this sort may simply be impossible in the near future. There's nothing intrinsically identifying about a video stream. It's just numbers. It isn't something you have, are, or know. We were floating along on "it's really hard to forge" but that on its own is not one of the ways of authenticating someone.
They don't do this for their own security. They do it because they're required to. And the requirement is idiotic, which is why the result is... idiocy.
I've worked in this field specifically for most of the last 7 years. It's a problem on the order of tens to hundreds of millions of dollars annually if you get it wrong.
To put more meat on the bone: Plaid is basically KYC for any service that matters anymore, and this $15 autogen service doesn't help you when you get to the face-scan/hold your ID next to your face level, which is required for any serious crypto exchange you'd wnat to use if you're a money launderer.
While I'm sure Neural Networks bring this to a new level, I feel like this wouldn't be hyper difficult to automate without them.
What's more, $15 sounds like a lot. If this wasn't certainly going to be used for less-than-ethical purposes, I feel like it would be ripe for disrupting this market with $5 or $2 IDs of various quality.
Although I think you're right, the market tells us that this is likely either too high-skill and/or high-labour and/or easily detected.
It's all snake oil devised to shift the risk from a party who has a mandate to perform KYC to some broken by design AI woodoo, which will generate free money until it doesn't once the landscape or the legislator's will mood change.
They bank will then perform the actual KYC and will start asking questions once it sees something funny and will eat the cost of fraud at the end of the day.
It is.
Today.
Do not underestimate criminals. They have a full dark free market operating that you may be completely unaware of. The "Dark Web" is not just a media slogan. There is an entire economic ecosystem with high levels of specialization and structure already in it. There are already organizations smart enough to have people who can take this, productize it, and be the one selling the metaphorical shovels to the lower level criminals who buy this product and then take all the direct risks of doing the actual crime.
Today's high-skill attack is tomorrow's product.
I'm just not seeing why they would need to employ either great skill or motivation in this case. Just saying the task does not seem very difficult, but is described as being so.
Would be happy to learn why it would be though!
And even if a party does ask for doc verification, even if you fail - an account can still be opened.
Voter fraud? Single individual could go around to a bunch of different voting polls too?
A fake ID, let alone a photo of a fake ID, is not going to get you past the registration step nor the in-person verification step. At best a truly good physical fake ID might get you through to vote in another person's name, if you know where they were registered and beat them to it. But that is not what this tool enables.
This system is not without its flaws. Plenty of people are disenfranchised because they either failed to properly register ahead of time, or failed to show up at the correct polling location with proper ID on election day. But AI-generated photos of fake IDs is not one of this system's weaknesses.
More likely you would use them to gain access to someone's accounts and steal their money/credit/etc.
It’s bananas that a picture of an ID sent over the internet was ever considered identity verification.
Anyone who’s ever had their identity “stolen” knows how little effort banks and business will put into identity verification before making their mistake your problem.
Now we're conflating underground with darknets? Journalism at its finest. What exactly is an underground website? This website is public and very welcoming to all:
One definition when I looked up the word was "a group or movement seeking to explore alternative forms of lifestyle or artistic expression" which I think also applies here.
Not after HN frontpage!
Underground makes more sense here as they're clearnet but you have to be "in the know" to know about them.
adj. 3a: existing outside the establishment, as in "an underground literary reputation"
n. 3c: an unofficial, unsanctioned, or illegal but informal movement or group
The journalist might even have intended:
n. 3b: a clandestine conspiratorial organization set up for revolutionary or other disruptive purposes especially against a civil order