Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Either that, or it will train people to stop trusting a phone call as some sort of authentication. The whole social engineering problem is that when somebody gets a phone call, they trust that the person at the other end is who they say they are. Which can be a false assumption. When the robots start calling, maybe people will finally stop making that assumption automatically.


So what can you trust? The person calling you might be a simulated voice, crafted to sound like someone you know. The person texting/DMing/emailing you might be an attacker pretended to be someone you know. You can put trust in things like PGP, but they're sparsely adopted and still leave a huge attack surface.


You can trust that they have the private key corresponding the public key you associate with that entity.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: