Source:
https://taiwan.postsen.com/world/10810/Beij...ology-News.html (and several other multiple sources)
QUOTE
If the face recognition system can be unlocked with photos, it may indicate a huge hidden worry in the current situation where cameras are all over the place.
Face recognition technology is widely used by the Bank of China, and various drawbacks have emerged. The facial recognition of some people in Beijing was breached, and nearly 430,000 RMB (about NT$1.892 million) was withdrawn from the bank account, but the IP of the registrant was displayed in Taiwan.
The latest report from China News Weekly describes what happened to Li Hong (pseudonym). The incident happened on June 19. She fell into the trap of fraudsters, her mobile phone text messages were intercepted, and her mobile phone number was set to call forwarding, so that her verification code fell into the hands of others, and she was unable to answer the bank’s confirmation call.
More seriously, her “face recognition” was broken. The backstage of the China Bank of Communications system shows that when resetting the password and transferring large amounts of money, “Li Hong” performed 6 face recognition comparisons, all of which showed “successful biopsy”.
But in fact, these face recognitions were not operated by Li Hong who was in Beijing. After investigation by the police, the IP address of the registrant was displayed in Taiwan, and the mobile phone model used was Motorola XT1686, which was also different from the Xiaomi Mi 8 used by Li Hong.
» Click to show Spoiler - click again to hide... «
Li Hong doubted the security of the Bank of Communications’ facial recognition system, and took the Bank of Communications to court on the grounds of a “debit card dispute”, demanding compensation. However, on June 30 this year, the Fengtai District People’s Court in Beijing rejected all Li Hong’s claims in the first instance. She is going to continue to appeal.
Banks believe that they have done their due diligence. Bank of Communications Beijing Changxindian Branch stated in court that “transaction passwords, dynamic passwords and customer authentication modes that assist face recognition” meet regulatory requirements, and they are in the process of Li Hong’s transfer. , the bank gave her a risk warning. After the big data analysis of the internal system found an abnormality, it called Li Hong’s mobile phone to verify the identity of the transferor and the transfer situation.
But Li Hong said that the bank claimed to have sent 22 SMS passwords and SMS risk alerts, but she only received 11 of them, and she did not receive the bank’s call. The reason behind this is that her text messages were intercepted by the scammers, and the calls were also transferred to the scammers’ mobile phones.
The report quoted Lao Dongyan, an expert who has long been concerned about personal information protection and a professor at the Law School of Tsinghua University in Beijing, who pointed out, “Facial recognition was introduced by banks as a participant in risk creation, and banks benefit more from this method. , should bear the risk responsibility proportional to the benefit it receives.”
She also pointed out that with the development of artificial intelligence, fraudulent methods are more high-tech, and banks should keep pace with the times so that their security technology exceeds that of criminal methods. If banks are held accountable for vulnerabilities in facial recognition technology, it will help urge banks to plug technical security loopholes and prevent possible fraud.
The report also pointed out that the difficulty of cracking facial recognition technology is sometimes unexpectedly simple. In 2019, several primary school students in Zhejiang used photos to crack the express cabinets in residential areas and easily take other people’s express delivery. In October 2021, a team of students from Tsinghua University successfully unlocked 20 mobile phones using only face photos.
Guo Bing, an associate professor at the School of Law and Politics of Zhejiang Sci-Tech University, believes that “photos of human faces are too easy to obtain.” If the face recognition system can be unlocked with photos, it may indicate a huge hidden worry in the current situation where cameras are all over the place.