“Identification of the human voice is one of the least reliable methods of biometric identification, recognized suitable for commercial use, – said Dmitry Kuznetsov, Director for methodology and standardization of Positive Technologies. In comparison with the facial image or fingerprint the human voice is highly susceptible to changes depending on the physical condition and the environmental factors (the person is sitting or moving, located indoors or outdoors, healthy or cold)”.
because Of this, the accuracy of voice identification is much lower than other methods of biometric identification. According to Kuznetsov, the main problem of all methods – increased risk of attacks using social engineering. “With voice identification such attacks are very simple. The Scam involves the victim, posing as Bank employees, and convince the person to pronounce any phrase they need. The phrase is recorded and used to confirm the theft of funds from victim’s account,” he says.
To protect against such attacks on the Bank’s side you need to use special techniques (for example, require the client to say aloud the part of the details of payment). In practice, such protection is rarely used, and without it, the biometric voice identification is not a barrier to intruders.
a member of the Council of the State Duma on information policy, information technologies and communications Evgeny Lifshitz recommends the use of a voice identification method only as a supplementary along with other. “Today, there are developed technologies of imitation of voice, by ear, almost indistinguishable, he reminds. – To synthesize speech using neural networks, only several samples of speech, so for public figures, of course, this method of identification just closed.”
For the average citizen, who does not act on radio and television, the situation with sight is safer. “But actually no, there are at least two possibilities for the attacker to get the voice of the ordinary man and based on it to forge this identity, he continues. – First of all, in the last year there have been reports of scammers who cold-call people and record samples of their voice, forming, probably, a database of sound samples. Secondly, when a voice identification sound is compared with a reference voice biometrics, when a citizen has passed, the sample is stored in a database, and from there it can be stolen”.
Lifshitz warns that such databases can be found on the darknet. “It can drain off disgruntled employees, or a separate record may get employee of the contractor that will be asked per dayKi-a person of interest. We saw the scandal with Apple, how this process works. Voice assistants are also a loophole. So the main means of identifying the voice can not be done, it is incomparably easier to forge than, for example, the retina of the eye,” he said.