The FBI now recommends choosing a secret password to thwart AI voice clones
arstechnica.com
arstechnica.com
Your answer already exists in almost every "E2EE" app. How many times does a person even access their convo partner's Safety Number/Security Code let alone verify it out of band?
Hardware level attestation isn't even required, and would only marginally increase security. Phones are already heavily locked down. If you're in a position to extract from app data, you're probably in a position to compromise the chat app itself, rendering any attestation pointless.
On the flip side, the most common form of a compromise is going to be untrustworthy apps, because for some reason people still use WhatsApp
There are no end of methods using devices to exchange challenge response sequences, but in practical security we have to deal with real people in real contexts. It's why encryption took 30 years to get traction. Passwords already make sense even to a primary school child.
From TFA:
> It's interesting that, in this new age of high-tech AI identity fraud, this ancient invention—a special word or phrase known to few—can still prove so useful.
There are reasons that passwords remain and probably always will be a superior technology [0], and why adding more layers of "solutions" like biometrics and multi-factors actually just increases the attack surface.
Haven't read the FBI guidance yet, but it seems they're suggesting we start teaching this outside of professional scope, to everyone.
I think that's a jolly good idea and will be thinking of how to build it into civic cybersecurity syllabus.
Duress signals and a challenge-response for identification are different beasts, but if we're going to teach people verbal signalling to thwart generative scams then may as well teach the whole gamut of craft.
I mean literally, we both open our phones, what is the number that is linking the 2FA between our two devices. Voice authentication of a rotating password.
I.e. me most days.
Back in 03 FBI would have probably called all this obvious insecurity, lack of privacy, lack of cryptographic attestation... A feature. Now the chickens come home to roost. And we all suffer in the end. Some more directly than others.
Not sure how your second statement follows the first... Agreed this isn't a technical problem per se.
And on some level I agree, but I also think you're failing to consider how much people vary in their abilities and personalities.
Your criticism of the institutions meant to protect our security seems reasonable though.
Read all your comments in this thread, and you're still not making sense to me.
or something like that. Remember this is mostly to defeat casual one-off scams.