Summary

OnlyFake, an underground website, employs neural networks to swiftly produce convincing fake IDs for just $15, potentially facilitating bank fraud and money laundering. Verified by 404 Media, the service allows users to input desired information and a passport photo, generating realistic IDs, even mimicking signatures. With its purported use of neural networks and generators, OnlyFake claims to churn out up to 20,000 documents daily, mainly for US identities. The IDs, backed by real-looking backgrounds, can pass online verification, posing challenges to platforms like OKX cryptocurrency exchange. While some companies, such as Jumio and Coinbase, aim to counter such fraud, OnlyFake’s AI-powered IDs present a formidable challenge. Wick, the service’s owner, aims to expand its capabilities, potentially including face and selfie generation. Discussions within OnlyFake’s community suggest a pursuit of solutions for video verification challenges. Senator Ron Wyden warns of the growing threat posed by AI-based tools, urging the adoption of secure authentication methods. This revelation comes amidst a broader trend of AI-driven fraud, exemplified by AI-generated voices and images, highlighting the need for robust cybersecurity measures.

  • jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    9 months ago

    The military already has a solution to this. Smart card ID cards. So it acts like a hardware security key that you plug into your computer to verify it’s you. Or at least the person possessing it. And it relies on the central authority to invalidate and verify the authenticity of that signature. Just like a yubikey

    Combine the ID card with a fingerprint scanner built into the ID card. You get the best of the security enclave. And public key verification.

    • ExLisper@linux.community
      link
      fedilink
      English
      arrow-up
      14
      ·
      9 months ago

      In Spain you just go to an office, show your ID and they give you a personal certificate you import into your browser. You can use the same cert on multiple computers and have multiple certs in the same browser. When you visit government pages it asks you which cert you want to use and voilà, you’re authenticated. You can also use the same cert to sign files and it’s a legally valid signature. It uses common standards and works on Linux.

      • LemmyRefugee@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        9 months ago

        Or if you buy a card reader you can use your ID (DNI) as your certificate because it has one saved inside

    • Squire1039@lemm.eeOP
      link
      fedilink
      English
      arrow-up
      8
      ·
      9 months ago

      Not disagreeing, but for the US:

      1. Yubikey 5c NFC costs ~30-55 USD. Not cheap.
      2. Yibikey BIO, with the scanner built in, will be even more expensive.
      3. Need a central registration authority or federated authorities to verify electronic ID. If the feds don’t press the issue, this probably won’t happen.
      • mlg@lemmy.world
        link
        fedilink
        English
        arrow-up
        17
        ·
        9 months ago
        1. CA will get hacked and root certificate dropped because they paid morbillions to some credit card company to setup the system on windows server 2003 with password123
      • Landless2029@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        9 months ago

        And how much would a solution cost in bulk for millions/billions of people? Also you can always tack on $10-$20 as a fee and you’re done.