Op-Ed: AI, deepfakes, biometrics, and human rights are the next apocalypse for security


Biometrics have become a crucial part of functional identity. This particular fix for security credentials is showing signs of increasing strain even as adoption of biometrics reaches almost obsessive levels

The theory of biometrics is simple enough. Unique characteristics including everything from fingerprints to facial topography and even behaviour define who you are. It’s a pretty cumbersome system, in fact. You and the security system need devices to collect and send biometric data just to do business.

There’s another issue, and it’s much more significant to just logging on somewhere.

Your biometrics are your default identity.

As ID, they’re also your legal identity for doing business.

As far as anyone else knows or can know, that information is you.

If that information can be “borrowed”, stolen, or copied, it’s also you, as far as any system can find out using biometrics alone.

Naivete and biometrics, a summary

See any gaping holes in this logic so far? Most systems process “credentials” including biometrics. It’s a slight step up from the old 100 points of ID, but very similar. It’s a checklist.

The trouble is that automated credential theft is now rampant. Biometric Update.com has a shudder-worthy piece on the subject of analyses by Google Threat Intelligence Group of an AI-driven systematic credential fraud that “compromised thousands of third-party credentials”.

I asked Gemini if AI could copy biometrics and got an instant “Yes”. The response included the interesting sentence,

Because biometric data is permanent and cannot be changed like a password, this has become a major focus for global cybersecurity experts.”

That’s not an argument you often see rattling around the online information about biometrics.  Your biometrics won’t change. It follows that any breach of biometric security could be effectively permanent.

Current news now includes a lot of muttering about these issues. Notably, an article from Insight Magazine saying that biometrics are more valuable than cash.

The no-brainer element in this situation is hard to miss.

AI can process huge volumes of data in less than a second. The highest data load volume I could find for a full set of biometrics as data was 5MB.

Is anyone seriously suggesting that AI can’t instantly generate 5MB of biometrics whenever it feels the need from any available source? A deepfake could do that easily.

Or, perhaps, an AI agent could simply take its pick from a portfolio of stolen or otherwise faked biometrics? All it would need is an old photo to create a plausible set of biometrics. That’s about 50% of an ID, without even trying.

Synthetic identities are dangerous

ID theft has been big business for decades. The new wrinkle is “synthetic identity”, a fake identity created from real information and turned into a new fictitious identity, as FICO Blog puts it.

In a very useful “you need to know this stuff” article (and you do), the machinery of synthetic identities is explained and fleshed out. FICO Blog goes on to point out that:

“Because synthetic identities are not tied to a real person, there is nobody to notice unauthorized activity and raise an alert, allowing fraud to go undetected for months or years, often only coming to light when it is too late to recover losses.”

This is all about the practical realities of AI-generated identity. It means biometrics alone aren’t much of a defence against AI fraud, even at the fictional level.

The much bigger issue with biometrics for personal security is human rights

The problems with biometric data and ID data in general are:

The legal status of personal ID information isn’t clear. Is it property? Is it an inalienable right to have legal protection for your ID, of whatever type of data?

Do you own your biometrics? You should, but do you? Does anyone know?

Does anyone else have any right to use your biometrics or other ID data, like movies, media, promotions, etc.? They might have. Bear in mind that your biometric data can also be uplifted from these sources.

What if you can’t prove who you are, based on any compromised data related to you? Don’t want to think about it? You’re quite right.

The identity of any human is the basis of their property ownership, commerce, and simply being alive. You have the inherent right to your own identity. If your ID gets stolen, it’s the functional version of you that’s being stolen.

If these aren’t human rights, what are?

There are more holes by volume than the size of the bucket in the current situation.

Biometric rights

It’s not a sparkly catchphrase, but “biometric rights” may define the future of human identity. These rights need to be codified and backed up by law.

This can’t be easy. There’s not much in the way of legal precedents. The evidence requirements could be very ponderous. There may or may not be a way of creating an audit trail of AI actions regarding ID fraud.

It has to be done because there are no options.

This isn’t “regulation”. This is now about the survival of your identity.



Op-Ed: AI, deepfakes, biometrics, and human rights are the next apocalypse for security

#OpEd #deepfakes #biometrics #human #rights #apocalypse #security

Leave a Reply

Your email address will not be published. Required fields are marked *