Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is both fascinating and a scary reminder of what the future has in store for us in a deepfake world.


What's scary to me isn't the scammers using deep fakes to get jobs, but the mid managers dumb enough to fall for it.


add non optimal lightning and compression and you would fall for it too

state of the art deepfakes are pretty much indistinguishable from reality


I don't pay attention to lighting when I interview candidates for a technical position.


well exactly, you wouldn't notice the tricks used to make it completely indistinguishable from reality, you wouldn't notice the pitch perfect voice, you wouldn't notice anything if it's done by a professional


Sure, but we're not talking about professionals spending hours perfecting takes, we're talking about people supposedly manipulating their own voice - probably to represent a completely different accent - in real time whilst being interviewed by someone probably paying an unusual amount of attention to tone of voice, possible hesitation etc. If people have the skills to do that near-flawlessly for 30 minutes, they probably don't need to bid on random non-deepfake work using someone else's ID...

Even if interviewers don't suspect deepfakes, the audio artefacts of deepfakes (odd intonation, mispronunciation and pauses) are going to sound suspiciously like someone who isn't very confident in their answers or is bullshitting. Much easier for poor English speakers just to draft in a person who speaks better English and maybe knows more about the actual work for the interview...


The point they are making is that if you’re hiring a fake person for a job who can’t do the job, some of the screening questions should’ve let you pick up on that. And if you don’t you’re at best a bad interviewer.


Especially with people who speak broken English, this is easy to game though. Multiple people could be sitting behind a voice obfuscator and responding to questions as-needed. Inconsistencies are explained as nervousness. Video and voice desync can be handwaved away by poor connection.

You dismiss people who fall for this as bad interviewers but I don't think you appreciate how sophisticated fraud has become-- with teleconferencing (anything internet-based, really), you never truly know you're interacting with who you think you are. You may not find out until they've collected a few paychecks, made copies of all your IP and disappeared into the night.


They are bad interviewers who should not be interviewing technical candidates if they fall for any such scheme, which is impractical and unrealistic in practice. I don't care about their broken english, I care about their technical competency. I'm sorry, but they aren't going to dupe me out of my expertise, unless they are actual software developers. But even an actual developer with the right experience could steal anything you give them access to. If you have concern about that, then you hire domestic and you require ID verification and you avoid contractors, so you know that you can at least prosecute them if they do.

Any company who is hiring off the internet, internationally, on the basis of a deepfake and a resume and is granting them elevated access to client PII on day one deserves to be exploited and deserves to be sued by their clients.


Who says they can't do the job? It would be easy for a tech-knowledgeable scammer to interview at 100 companies, collect 100 pay-cheques and then dissapear.


I think that's a more realistic possibility. That you have an actual software engineer with tech knowledge doing old fashioned social engineering and doesn't care how many times they get fired. But the AI in this case is just providing a fake profile pic. It's not that deep, as the commenters in this thread are suggesting.


Everything you think you know about a person when remote hiring can be expressed as a series of bits. You aren't above falling for it either. This will become much more difficult to detect.


A series of bits can be enormously complex, so you aren't saying much with that statement. You act as if checking the right bits off is some trivial thing for a sufficiently long chain of bits. Even guessing something as small as 16 bits in a row correctly is non-trivial, but scale it up to 256 bits and you've got yourself state of the art security. I don't care how much AI you have. No AI or assembled team of scammers short of having an outright social engineer who is also a real software engineer is going to pull that off against a technical interviewer with critical thinking and interpersonal skills.


>mid managers dumb enough to fall for it

There are a lot of dumb middle managers out there. In some cases, the position and the intelligence are co-dependent, I suspect. It's truly terrifying, if you think about it.


> This is both fascinating and a scary reminder of what the future has in store for us in a deepfake world.

Social engineering has always been a thing, check out this Darknet Diary podcast about the Lazeraus hacking collective group (suspected to be N. Korean digital Army) and how they have try/tried to infiltrate their way into crytocurrency based exchanges--and have succeeded in the past--using all kinds of methods including hijacking CVs from Linkedin.

The truth is that while the advent of deepfakes and even text to image AI/ML based tech has muddled the waters even more, it's always been a challenge to not encounter some level of difficulty when dealing with verification. Fraud is and will always remain a component in daily operations of any organization.

We have a saying in the Bitcoin space that i think applies here: Do not trust, verify.

And this is why I think people need to understand that the usecases for an immutable ledger can and will go beyond just a digital token (it's only the backbone), and these usecases (the limbs and appendages to continue with the body metaphor) will become more imperative in the 21st Century: you can manipulate all you want via social media and many have, but if verified sources with proper validation is stored on an immutable ledger with a cryptographic proof of work blockchain that is impossible to alter then you can essentially have the closest thing to verifiable truth Online.

Jacob Applbaum said it best when he said that to maintain security online you'll likely have to adopt 2 or more identities separate from each other to continue to have some level of assurance that your personas are not traceable to your real ID in a World where Doxxing became 'a thing' Online. I wonder hat he has to say about the OPSEC/INFOSEC space now that we have the ability to mimic people Online so closely with very little resources.

0: https://darknetdiaries.com/episode/119/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: