Deepfakes: FIDO2 Keys and Passphrases to Secure Transactions

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Automated detectors are no longer sufficient against deepfakes. Following a counterfeit video call that led Arup to make 15 transfers totaling approximately $25 million, experts recommend that companies adopt hardware keys and passphrases. Their effectiveness depends on systematic application and their combination with other controls, such as out-of-band reminders and dual authorization.
For high-stakes operations, a passphrase is not enough
For high-value transactions in large companies, a verbal passphrase alone is not enough to ensure security. It needs to be supplemented by other measures, such as reminders conducted through an independent channel and validation by two people, to ensure robust authentication. CISA further advocates for the adoption of FIDO2 and PIV hardware identifiers as the new standard for multi-factor authentication. It is also recommended to systematically pair passphrases with other security devices. Making these checks automatic and without exception is advised, as attackers often seek to create a sense of urgency or social pressure.
Arup: 15 transfers and approximately $25M after a counterfeit call
In January 2024, an employee at Arup participated in a video call with someone he believed to be the company's CFO. Following this exchange, 15 transfers were made to third-party accounts, totaling approximately $25 million. The individuals on the other end of the call were AI-generated clones, assembled from public appearances and earnings calls of Arup executives.
Suspicions based on sight and sound no longer hold
Seeing and hearing a counterpart is no longer proof of authenticity, and any protocol based on facial and voice recognition is now considered outdated by Deepak Gupta. For the past five years, the use of live video and audio calls as a standard for identity verification has been undermined by deepfakes. Previously useful cues, such as background noise, certain synthetic vocal modulations, or the absence of breathing, are no longer sufficient. Researchers from University College London indicate that listeners correctly identify deepfakes only 73% of the time. The NSA, FBI, and CISA also dismiss traditional automated detections, which rely on the presence of statistical traces of manipulation, something that can no longer be guaranteed today.
Recommended procedures: hardware keys and verbal passwords
Fraud specialists encourage the use of physical security keys and verbal passphrases, following the recommendations of government agencies. CISA highlights FIDO2 and PIV hardware identifiers as the new standard for multi-factor authentication. A verbal passphrase consists of a secret word or phrase shared and verified live during a call, by asking the counterpart to state it. Deepak Gupta emphasizes the effectiveness of analog solutions based on a single controlled entry point and notes that defense against the most advanced AI attacks is often deliberately low-tech. Deepfakes are effective at replicating public appearances and voices but remain ineffective against what is not publicly accessible.
Application without exception and generation rules
Passphrases are only effective if applied consistently across the organization. According to Deepak Gupta's experience, employees sometimes skip security checks when they feel intimidated. Scobey recommends making these controls automatic and without exceptions, and simulating deepfake or voice phishing calls in security training. He advocates for generating passphrases randomly rather than manually, using unrelated words separated by numbers and symbols, distinguishing passphrases according to roles and transactions, and periodically resetting them without a fixed schedule. These passphrases should be combined with other security protocols. In this context, where employees handle significant amounts, mistakes can be costly, and loss of trust or compliance fines can jeopardize a profitable business.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.