New from 404 Media: inside the underground site where "neural networks" churn out fake IDs
- I tested the service, called OnlyFake, made two IDs in minutes
- I then used one to successfully bypass the identity verification check on a cryptocurrency exchange
- Massive implications for crime, cybersecurity. What does it mean for us when fake IDs are a mouse click away?

https://www.404media.co/inside-the-underground-site-where-ai-neural-networks-churns-out-fake-ids-onlyfake/

Inside the Underground Site Where ‘Neural Networks’ Churn Out Fake IDs

The site, called OnlyFake, threatens to streamline everything from bank fraud to money laundering, and has implications for cybersecurity writ large.

404 Media
@josephcox
If the OnlyFakes "documents" fool KYC-checks then these checks are bad.
Typical Video based services used by banks I know check for a physical card and the flip hologram etc.. No bank I know will accept an alleged photo of an ID card on a carpet. It may of course be possible to forge IDs which fool Video-Ident and similar services but that will need at least some printing etc. So right now it means: This will just force real weak identity verification checks to get a littel smarter.
@Ann_Effes @josephcox Video-Ident was hacked, too. And, according to the clever people at CCC, it was not too hard:
https://www.ccc.de/de/updates/2022/chaos-computer-club-hackt-video-ident
(English version available.)
In the end, waving identity tokens in front of a camera is a hack. The person doing the verification does not control the setup, and has very little time to do any verification. The attacker controls the whole process, can plan ahead, and can add social engineering skills to achieve his goal.
CCC | Chaos Computer Club hackt Video-Ident

Der Chaos Computer Club ist eine galaktische Gemeinschaft von Lebewesen für Informationsfreiheit und Technikfolgenabschätzung.

@ketchup71 @josephcox

Yes.

I did not say though that Video-Ident is not hackable or was not hacked.

I said that pictures of ID cards generated by some AI will pass only the simplest checks and will not pass Video-Ident.

The Video-Ident hack does need much more than just some printed picture. It is (in opposite to what CCC states - somewhat puffery) way more complicated than the discussed ID generation by AI. Ordering a fake ID which would pass KYC checks would be indeed a big threat.

@Ann_Effes @josephcox Agreed. Mostly. 😁

The whole AI angle is BS. IDs are very formal, there is no point in using image generators. Best use regular image manipulation, I guess. The real problem is that they can pump them out in numbers.

Still, since the video isn’t hack is basically video manipulation and social engineering, it works work with those fake IDs as well. 🙂

@Ann_Effes @josephcox However, the point is: it is an unreliable, expensive method, depending on highly trained, motivated employees. Who are working in a call center setup, so they are probably not overpaid, and on a per-case basis. 🤷‍♂️

@ketchup71 @josephcox

Yeah, but I commented just one aspect:

Are AI generated ID Pictures a particular threat?

And my answer was: No, even Video-Ident can't be fooled by those alone. If an ID check can be fooled by those AI generated IDcard-photos than that procedure is particularly unsuitable.

What you say beyond that is correct, but was not the subject of the post or my answer.

@Ann_Effes Sorry, I probably mistook your comment and answer as „video ident would prevent that“, and wanted to provide a counter example to dampen expectations.

Also: I agree the AI part is irrelevant for the fake card. It may help to create a large number of unique backdrops, which will help keeping the picture service alive, but is probably mostly to hype the service.

Anyway, there is no way around a cryptographic solution, sind everything else is way too easy to compromise. 🙂

@Ann_Effes Also: why do I write this in English?!? 🤦‍♂️😂