Deepfakes and Voice Cloning
What synthetic media can and cannot currently do.
22 minutes to read
What is actually possible now
A convincing clone of your voice needs seconds of audio, not minutes. A voicemail greeting, a video posted to social media, a short phone call. The exact threshold does not matter and chasing it is a waste of attention: assume any recording of you is enough.
Live video is the part most people have not caught up with. Face replacement in real time, on a video call, runs on consumer hardware with free software. The FBI has recorded criminals generating video for real-time chats and using it to prove to a victim that they are speaking to a real person.
The largest published loss of this kind was a finance employee in Hong Kong who joined a video call with what appeared to be his chief financial officer and several colleagues. All of them were synthetic. About twenty-five million dollars left the company in fifteen transfers in a single day.
Do not learn the tricks
There is a steady supply of viral tests — ask them to wave a hand in front of their face, turn side-on, count fingers. Do not build a habit on any of them.
The three-finger test worked because of one limitation in how the software handled objects passing in front of a face, and that limitation has been fixed. Two people who build detection systems for a living have said publicly that relying on it now gives false confidence, which is worse than performing no check at all.
There is a deeper reason not to bother. Every trick that goes viral becomes a specification for whoever is optimising against it. The tests decay because they are published, and the next one will decay the same way.
What to do instead
Nothing perceptual. Move to something the technology cannot reach:
A codeword agreed with family in advance, never shared electronically, used whenever money or an emergency is involved.
Shared private knowledge that could not be assembled from anybody's online footprint. Not your mother's maiden name — what went wrong on a particular holiday.
And the independent channel, every time. Hang up, ring back on a number you already had. A perfect deepfake of a person cannot answer their real phone.
What to carry out of this
- Seconds of your recorded voice is enough, so assume it exists
- Do not learn detection tricks; publishing one is what kills it
- Move the check to a codeword, private knowledge, or a call you place
Tactics covered