    Fooling a Voice Authentication System with an AI-Generated Voice / Schneier · Monday, 27 February, 2023 - 20:49

A reporter used an AI synthesis of his own voice to fool the voice authentication system for Lloyd’s Bank.

    Experian Privacy Vulnerability / Schneier · Wednesday, 11 January, 2023 - 20:53

Brian Krebs is reporting on a vulnerability in Experian’s website:

Identity thieves have been exploiting a glaring security weakness in the website of Experian, one of the big three consumer credit reporting bureaus. Normally, Experian requires that those seeking a copy of their credit report successfully answer several multiple choice questions about their financial history. But until the end of 2022, Experian’s website allowed anyone to bypass these questions and go straight to the consumer’s report. All that was needed was the person’s name, address, birthday and Social Security number.

    Using Pupil Reflection in Smartphone Camera Selfies / Schneier · Tuesday, 3 May, 2022 - 16:17

Researchers are using the reflection of the smartphone in the pupils of faces taken as selfies to infer information about how the phone is being used:

For now, the research is focusing on six different ways a user can hold a device like a smartphone: with both hands, just the left, or just the right in portrait mode, and the same options in horizontal mode.

It’s not a lot of information, but it’s a start. (It’ll be a while before we can reproduce these results from Blade Runner .)

Research paper .