this post was submitted on 05 Feb 2024
214 points (97.8% liked)

Technology

60052 readers
2966 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
 

Summary

OnlyFake, an underground website, employs neural networks to swiftly produce convincing fake IDs for just $15, potentially facilitating bank fraud and money laundering. Verified by 404 Media, the service allows users to input desired information and a passport photo, generating realistic IDs, even mimicking signatures. With its purported use of neural networks and generators, OnlyFake claims to churn out up to 20,000 documents daily, mainly for US identities. The IDs, backed by real-looking backgrounds, can pass online verification, posing challenges to platforms like OKX cryptocurrency exchange. While some companies, such as Jumio and Coinbase, aim to counter such fraud, OnlyFake's AI-powered IDs present a formidable challenge. Wick, the service's owner, aims to expand its capabilities, potentially including face and selfie generation. Discussions within OnlyFake's community suggest a pursuit of solutions for video verification challenges. Senator Ron Wyden warns of the growing threat posed by AI-based tools, urging the adoption of secure authentication methods. This revelation comes amidst a broader trend of AI-driven fraud, exemplified by AI-generated voices and images, highlighting the need for robust cybersecurity measures.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 14 points 10 months ago (2 children)

The military already has a solution to this. Smart card ID cards. So it acts like a hardware security key that you plug into your computer to verify it's you. Or at least the person possessing it. And it relies on the central authority to invalidate and verify the authenticity of that signature. Just like a yubikey

Combine the ID card with a fingerprint scanner built into the ID card. You get the best of the security enclave. And public key verification.

[–] [email protected] 14 points 10 months ago (1 children)

In Spain you just go to an office, show your ID and they give you a personal certificate you import into your browser. You can use the same cert on multiple computers and have multiple certs in the same browser. When you visit government pages it asks you which cert you want to use and voilà, you're authenticated. You can also use the same cert to sign files and it's a legally valid signature. It uses common standards and works on Linux.

[–] [email protected] 7 points 10 months ago

Or if you buy a card reader you can use your ID (DNI) as your certificate because it has one saved inside

[–] [email protected] 9 points 10 months ago (2 children)

Not disagreeing, but for the US:

  1. Yubikey 5c NFC costs ~30-55 USD. Not cheap.
  2. Yibikey BIO, with the scanner built in, will be even more expensive.
  3. Need a central registration authority or federated authorities to verify electronic ID. If the feds don't press the issue, this probably won't happen.
[–] [email protected] 17 points 10 months ago
  1. CA will get hacked and root certificate dropped because they paid morbillions to some credit card company to setup the system on windows server 2003 with password123
[–] [email protected] 4 points 10 months ago

And how much would a solution cost in bulk for millions/billions of people? Also you can always tack on $10-$20 as a fee and you're done.