The “Safe Word” KBA is as Vulnerable as Other KBAs

Why knowledge-based authentication? Because, in theory, it’s something you know that no one else knows.

“Safe words” are a form of KBA.

  • You get a call from your son, who says he’s in jail and won’t be released unless you send money now. The voice sounds like your son, so you send the money. Of course, it isn’t your son, but a deepfake engineered to scam you of your money..
  • But if your son volunteers the “safe words” that the two of you previously selected, you have a much higher assurance that the voice on the phone is your son.

But, as Secrets of Privacy notes, safe words are also vulnerable. Some of their tips:

Safe words, not safe word

While password length requirements sometimes become ridiculous, they have a purpose. A longer password is harder to guess than a shorter one.

Similarly, four safe words are harder to guess than a single one.

Provided the words are unrelated. “The quick brown fox” is a terrible safe phrase.

That no one else knows

If someone can read your safe phrase online, it’s unsafe. I cannot use “California State University Fullerton” (on my LinkedIn profile) or “biometric product marketing expert” (all over this website).

Established together, preferably in person

Don’t rely on online establishment. People see things.

“Don’t text the safe phrase (even via Signal), never email it and don’t save it somewhere like in a cloud document or note app.”

And one more thing

If your purported son calls you, he’s the one to use the safe phrase…not you.

“Eva Velasquez, CEO of the Identity Theft Resource Center, sees this mistake constantly. A family sets up a safe word, and then in the panic of an actual emergency call, the intended victim blurts it out themselves trying to be helpful or trying to speed things along. A scammer who hears “wait, is this about our safe word, it’s soggy trombone” now owns your safe word. The rule has to run one direction only. Whoever is asking for money says the phrase unprompted, or the call gets treated as fraud, no exceptions.”

Admittedly the victim is under extreme pressure, but try to remember this. Blurting out the safe word is the equivalent of leaving your house keys in your front door lock, with a red arrow labeled “For burglars.”

When done right, safe phrases work

But don’t let this scare you away from safe phrases.

“The reason a safe phrase beats even a flawless voice clone is that it doesn’t rely on the voice being fake or real. It relies on information the scammer physically cannot have.”

AI Isn’t the Problem: Reputational Damage Is

AI used for evil is bad, but it’s not the worst evil.

Neal K. Shah is victimized

Neal K. Shah self-identifies as “America’s Chief Elder Officer.” And he says that he recently made the news:

“FOX Business just published a story about me – I wish they didn’t have a reason to. Scammers used AI to clone my likeness, and turned it into a WEAPON against the exact people I work to protect – older adults and caregivers.”

According to Shah, the scammers used a Meta tool called Muse Image to create fraudulent deepfakes of Shah endorsing slimeball products. Because of this and other incidents, Meta concluded that Muse Image “missed the mark” and disabled the feature.

(For now. If Muse Image reappears in 2028, don’t be surprised.)

Shah, understandably upset that elderly people were misled, blames evil AI.

“BUT the deeper problem – how trivially easy AI now makes it to impersonate real people and prey on the vulnerable… I think that may only be getting started.”

Shah is wrong. There’s an even deeper problem.

Bredemarket Technology Firm Services weighs in

On LinkedIn, I offered the following comment:

“I don’t know that AI is entirely to blame here. There were fraudsters before AI, and there will be fraudsters after AI.

“The bigger issue is when someone’s name and likeness is fraudulently used—by ANY means—and the platforms do nothing about it.”

Remember when Clifford Irving published Howard Hughes’ autobiography that Hughes never wrote? He didn’t need AI for that. And the scam was revealed when the usually tight-lipped Swiss banks revealed who was really cashing the checks for “author” Howard Hughes.

No evil AI here.

The problems occur after the scam, and aren’t affected by how the scam was perpetrated. The problem is when a platform is scammed, but the platform—a website, a newspaper, whatever—doesn’t bother to correct the record and tell the truth.

Shah:

“I reported [the scam ads] REPEATEDLY – yet they stayed up.”

Now I could have used my Bredemarket Technology Firm Services hat to suggest a solution.

But I didn’t.

I tossed the task elsewhere.

Bredebot weighs in

Now that it’s easier to generate Bredebot content, I let Bredebot write a response.

When someone creates a fake profile using your name, face, and credentials, it is a fast track to reputational damage. But what happens when you hit that “report” button and the platform does absolutely nothing?

For a long time, platforms hid behind broad immunity shields, treating identity fraud like a minor nuisance. But in 2026, the regulatory tide is turning. Relying on passive content moderation is no longer cutting it. Between the FTC’s strict crackdown on impersonation and new federal mandates like the TAKE IT DOWN Act forcing rapid 48-hour responses for deepfakes, platforms that stay passive are looking at massive civil penalties.

When a platform ignores fraud, it isn’t just failing the victim; it’s tanking user trust. It is like hiring a pack of wild wildebeests as marketing consultants, only to wonder why your wombat customers are running away in terror.

If a platform leaves you stranded, you have to document everything, escalate to regulatory channels, and protect your broader digital footprint. Identity security requires proactive defense, not corporate silence. If you need a hand navigating this landscape, John E. Bredehoft at Bredemarket can help you map out a strategy.

I couldn’t have said it better myself.

Now I just have to convince people that I did NOT endorse a death of passwords book.

This is fake. Google Gemini.

But I DO endorse THIS book. Click the pic.

Four pages from "Proving Humanity: The Six Factors of Identity Verification and Authentication" by John E. Bredehoft, Bredemarket. Click on the image to purchase.
This is real. Gumroad.

Underwriting the Ghost: Synthetic Borrowers Disappear Without Paying

When a lender receives a loan application, it endeavors to ensure that the applicant will pay the lender back.

But even with the proper controls, a certain percentage of loans go unpaid.

Especially if the applicant looks really good on paper, but isn’t…and doesn’t even exist because it’s a synthetic identity.

PYMNTS describes the threat from deepfake borrowers:

“Across the lending industry, a new category of fraud is emerging that combines deepfake video, cloned voices, synthetic identity creation, fabricated employment histories and AI-generated financial behavior into a single engineered persona. These synthetic borrowers are not merely fake identities in the traditional sense. They are algorithmically optimized consumers designed to survive onboarding checks, satisfy underwriting models and disappear once loans are funded.”

Disappearing borrowers is not a good thing.

Know your customer.

“Underwriting the Ghost.” Synthetic man gets the loan, then he disappears. Google Gemini/Lyria. Public Domain.

A Holistic Approach to Presentation, Deepfake, and Injection Attack Detection

A recent Joel R. McConvey Biometric Update article, which quotes heavily from a Finextra article by Victor Mendez, CMO and Co-founder of Verifyo, emphasizes that presentation attack detection (PAD, a/k/a liveness), deepfake detection, and injection attack detection (IAD) must not work in isolation, but in concert. (As a suite symphony?)

Mendez:

“[E]merging threats and cyber threats around remote proofing do not respect a single-control answer.

“Defend the camera with PAD. Defend the pipeline with IAD. Defend the document with cryptographic chip checks. Defend the decision with verifier-side signals and a reviewable evidence package. Where possible, replace the camera as the unit of evidence with an issuer-signed attestation.

“The institutions that survive the next two years of synthetic-media fraud are not the ones with the best liveness vendor. They are the ones with the best layered architecture and the best evidence trail.”

Or, to put it another way, multimodal (or multifactor if you prefer) attack detection.

Google Gemini.

If you offer multimodal/multifactor attack detection and want to communicate the benefits to your prospects, Bredemarket can help.

The Continuing Adventures of Will and Chad

Technically Chad Smith engaged in identity fraud on Saturday Night Live when he started giving Will Ferrell’s monologue.

But no harm was done.

And while the face modality fooled many of us, the voice modality gave Chad away. Score one for multimodal authentication.

Clifford Stoll Was Wrong AND Right

A former coworker reshared the story of Clifford Stoll investigating an accounting error and discovering a Cold War spy network. But a few years later, Stoll was wrong about the emerging Internet…and also right.

Stoll shared his views in a 1995 Newsweek article that was an amusing read after the fact.

Replacing your daily newspaper?

For example:

“The truth is no online database will replace your daily newspaper…”

Stoll lived long enough to see the decline of printed newspapers in the early 21st century.

Electronic books?

Another one:

“How about electronic publishing? Try reading a book on disc. At best, it’s an unpleasant chore: the myopic glow of a clunky computer replaces the friendly pages of a book. And you can’t tote that laptop to the beach. Yet Nicholas Negroponte, director of the MIT Media Lab, predicts that we’ll soon buy books and newspapers straight over the Internet. Uh, sure.”

Let’s pick this one apart piece by piece.

  • A book on disc? What’s a disc?
  • Yes, to some the myopic glow of an electronic book isn’t the best experience, whether on light or dark mode. But a traditional printed book cannot be read at all when you turn the lights off.
  • Stoll assumed that you would always need a laptop to read an electronic book. He did not envision dedicated electronic reading devices that were smaller than a laptop…to say nothing of “smart” phones with an “app” called “Kindle.”
  • Speaking of Amazon Kindles, you CAN buy books straight over the Internet. And music also, from a company that is no longer called Apple Computer.

So Stoll was not perfect. But he anticipated some things that we still struggle with today.

Unedited data!

“What the Internet hucksters won’t tell you is tht the Internet is one big ocean of unedited data, without any pretense of completeness. Lacking editors, reviewers or critics, the Internet has become a wasteland of unfiltered data. You don’t know what to ignore and what’s worth reading.”

While many companies from Yahoo to Altavista to Google to Wikipedia to OpenAI have tried to solve this problem, it is not fully solved.

And then there’s the biggie.

Isolation!

“What’s missing from this electronic wonderland? Human contact. Discount the fawning techno-burble about virtual communities. Computers and networks isolate us from one another. A network chat line is a limp substitute for meeting friends over coffee. No interactive multimedia display comes close to the excitement of a live concert. And who’d prefer cybersex to the real thing?”

Today’s world is actually worse than the one Stoll envisioned. Not only have I conducted most of my interactions with people over chat boxes and screens. But in 2026 we are now interacting with “HAL 9000” non-person entities…and we may not even know that they aren’t human, but synthetic or deepfake identities.

Despite the benefits of remote interactions—they’ve kept me (and my former coworker) employed—Stoll’s warnings about this new world remain valid.

Wrong but right

So I wouldn’t laugh at Stoll’s derision over the emerging Internet. If you were alive in 1995, be honest: did you anticipate THIS?

Master Keys for Fingerprints and Voices

I swear I’ve written about “MasterPrints” before, but I can’t find any such article. Maybe I just discussed it internally at IDEMIA when I worked there in 2018.

Generative adversarial network produces a “universal fingerprint” that will unlock many smartphones

“Researchers at NYU and U Michigan have published a paper explaining how they used a pair of machine-learning systems to develop a “universal fingerprint” that can fool the lowest-security fingerprint sensors 76% of the time (it is less effective against higher-security sensors).

“The researchers used “generative adversarial networks” (GAN) to develop their attack: this technique uses a pair of machine learning systems, a “generator” which tries to fool a “discriminator,” to produce a kind of dialectical back-and-forth in that creates fakes that are harder and harder to detect.”

While this happened over seven years ago and is probably harder to implement with today’s technology, I was reminded of this when I ran across this Biometric Update article.

Voice morphing attack blends identities to bypass voice biometrics: study

“A new research paper explores a signal-level approach to voice morphing attacks that exposes vulnerabilities in biometric voice recognition systems.

“The abstract describes Time-domain Voice Identity Morphing (TD-VIM) as “a novel approach for voice-based biometric morphing” which “enables the blending of voice characteristics from two distinct identities at the signal level.” TD-VIM allows for seamless voice morphing directly in the time domain, allowing “identity blending without any embeddings from the backbone, or reference text.””

So it, um, sounds like we not only have MasterPrints, but also MasterVoices.

Two Footballs, Two Biscuits, Two Presidents: A Cybersecurity Nightmare.

Last year I wrote about a biscuit and a football, but I wasn’t talking about the snack spread on game day.

Google Gemini.

I was talking about the tools the United States President uses (as Commander-in-Chief) for identity verification to launch a nuclear attack.

But sometimes you have to pass the football. If the President is temporarily or permanently incapacitated in an attack, the Vice President also has a football and a biscuit. Normally the Vice President’s biscuit isn’t activated, but when certain Constitutional criteria are met it becomes operative.

Other than this built-in redundancy, the system assumes one football, one biscuit, and one President.

If you’re a cybersecurity expert, you know this assumption is the assumption of a fool.

  • It is not impossible to have duplicate functional footballs and duplicate functional biscuits.
  • And it is not impossible to have duplicate functional Presidents, with identical face, voice, finger, and iris biometrics. Yes, it’s highly unlikely, but it’s not impossible. If the target is important enough, adversaries will spend the money.
Grok.

And most of us will never know the answer to this question, but how do government cybersecurity experts prevent this?