Episode 205 - GluuFederation/identerati-office-hours GitHub Wiki

Title: The Authentic Identity Challenge

Channels

Description

Deepfakes are getting better. Are our identity defenses keeping up? In this episode, we explore the split between identity matching and liveness detection, why certifications don't tell the whole story, and the critical questions buyers should ask before trusting a vendor's claims.

Homework

Takeaways

  • Authentic identity is layered. Presentation Attack Detection ("PAD") covers physical presentation attacks (e.g. a mask), while deepfakes and injection attacks are digital threats; they need different controls. Deepfake attacks are about the media itself (e.g. image manipulation). Injection attacks are about how the media gets into the identity system, e.g. inject a pre-recorded video.

  • Certifications are necessary but not sufficient. They show minimum conformance, while head-to-head tests like DHS RIVR show comparative performance.

  • Deepfakes are outrunning standards. PAD standards are mature, but deepfake standards and benchmarks are still catching up to fast-moving AI attacks.

  • Buyers need to interrogate vendors. Ask how often models are updated, how systems are trained, and how diverse the benchmarks are.

  • Passive liveness can improve usability. A strong passive system can reduce friction, especially for older users, while still performing well if properly designed and benchmarked.

Livestream Audio Archive