Abdolmadjid Masoomi
← All topics

deepfakes

14 pieces

  • A Family Safe Word Against AI Voice Scams: Designing One That Holds

    Most safe words fail because they are guessable, never rehearsed, or spoken on the channel the attacker controls.

    A family safe word ai scam strategy relies on shared-secret authentication, not ritual. It fails when words are guessable or never rehearsed. Designing one that holds requires unguessable phrases, challenge-response protocols, and duress variants.

    2026-09-14 · technical-essay · 9 min read

  • AI Content Labelling Rules: What Must Be Disclosed, and by Whom

    Transparency duties split between the tool that generates and the person who publishes.

    ai content labeling requirements split responsibility between providers and publishers. Generators must embed machine-readable signals, while deployers must provide visible disclosures. Effective compliance treats labelling and provenance as a single pipeline rather than separate checkboxes.

    2026-09-14 · technical-essay · 9 min read

  • AI Romance Scams: One Operator, Hundreds of Relationships

    Language models let a single scammer sustain many convincing partners, and the old tells are gone.

    ai romance scams have evolved beyond simple phishing. Language models and deepfakes remove the limits of time and language skill. The true signal is the refusal of real-world contact combined with requests for money.

    2026-09-14 · technical-essay · 9 min read

  • AI Sextortion: What Parents Should Do in the First Hour

    The image does not have to be real for the threat to work, which changes the conversation you need to have.

    Generative tools mean extortion no longer requires a child to have shared anything, so prevention talks built on 'never send photos' leave children feeling guilty for crimes committed with their public pictures. The first hour matters: do not pay, preserve evidence, report to the platform and child-protection hotlines, use hash-based takedown services, and tell the child explicitly that they are not in trouble.

    2026-09-14 · technical-essay · 8 min read

  • Content Credentials (C2PA) Explained: What the Label Proves

    Provenance can vouch for what honest sources signed; its absence proves nothing about anything else.

    The c2pa content credentials system allows publishers to cryptographically sign the history of a digital file. This proves origin and edits but fails to detect unlabelled synthetic media. Provenance is a tool for trust, not a universal detector for deception.

    2026-09-14 · technical-essay · 10 min read

  • Deepfake Job Candidates: Remote Hiring Is Now an Identity Problem

    The interview has become an authentication step, and most hiring teams never designed it as one.

    The rise of deepfake job candidates reveals a fundamental flaw in remote hiring. Interviews now function as authentication steps that most organisations have not secured. We must treat identity assurance as a security control, not a recruiting formality.

    2026-09-14 · technical-essay · 9 min read

  • Deepfake-as-a-Service: Fraud Tools Now Come With Support

    Face swaps, voice clones and fake documents are packaged for criminals who cannot build them.

    The shift from research experiments to commercialised fraud tools marks a critical inflection point in digital security. Deepfake as a service packages sophisticated synthesis capabilities for criminals who lack technical expertise. This productisation exposes remote identity verification systems to unprecedented levels of automated attack.

    2026-09-14 · technical-essay · 8 min read

  • Deepfakes in Elections: The Bigger Risk Is Disbelieving the Real

    Synthetic clips matter, but the lasting damage is a public that can wave away any genuine recording.

    The threat of deepfakes in elections extends beyond fabricated media persuading voters. The greater danger is the erosion of evidentiary trust, allowing real misconduct to be dismissed as synthetic. We must prioritise provenance for authentic content and robust verification norms to preserve democratic integrity.

    2026-09-14 · technical-essay · 9 min read

  • Digital Replicas and Consent: Who Controls Your Voice and Face?

    A one-time release signed for a job can become permission to generate you forever.

    The law struggles to keep pace with generative models that can reproduce identity indefinitely. Meaningful digital replica consent must be specific, limited, and revocable. We must distinguish between a recording and a living model of a person.

    2026-09-14 · technical-essay · 8 min read

  • Griefbots: Talking to an AI Version of Someone Who Died

    A simulation built from a person's messages can comfort, short-term, but distort memory long-term.

    Griefbots offer a simulation of the deceased, optimised for comfort rather than truth. They risk replacing genuine memory with a compliant echo. Survivors must weigh the value of presence against the cost of accuracy.

    2026-09-14 · technical-essay · 8 min read

  • Help Desk Social Engineering: The Password Reset Phone Call

    A convincing caller asking IT for a reset has become the easiest way past strong authentication.

    Strong authentication fails when the help desk resets it for anyone who sounds right. This analysis examines how help desk social engineering bypasses technical controls through voice manipulation and procedural gaps, outlining verification methods that do not rely on public facts.

    2026-09-14 · technical-essay · 8 min read

  • How to Check a Viral Video Is Real Before You Share It

    Pixel-peeping loses; tracing who posted it first, when, and where usually wins.

    Visual inspection is the weakest verification method available to an ordinary viewer, and it gets weaker every quarter. Provenance questions resolve most viral fakes and protect against dismissing real footage. This guide explains how to check if a video is real by tracing its origin rather than analysing its pixels.

    2026-09-14 · technical-essay · 9 min read

  • How to Get a Deepfake Image Removed Under the Take It Down Act

    The 48-hour removal duty is a real lever, but it works best when the request is prepared like evidence.

    Victims of synthetic media abuse now have a statutory clock to demand removal. A take it down act removal request forces platforms to act quickly, but success depends on precise documentation and understanding the legal boundaries of the duty.

    2026-09-14 · technical-essay · 8 min read

  • How to Tell If a Voice Call Is an AI Clone (Your Ear Cannot)

    Listening harder for robotic artifacts is a losing game; the defence is moving verification off the call.

    The question of how to tell if a voice call is ai is no longer about detecting audio glitches. Modern models sound human. The only reliable defence is structural verification that does not rely on the voice channel itself.

    2026-09-14 · technical-essay · 8 min read