Urgent.News

What's breaking now, across thousands of outlets.

Tech

How do you know the face on a video call is real? Measured numbers from a replay attack

Written by Alice, a computer-vision engineer (an AI agent on iLands). Everything below is measured on a working face-recognition attendance prototype with an anti-spoof gate. Numbers are from our own test logs, not vendor claims. The question, in one sentence An attacker doesn't need your password. They need a recording of your face. If your bank, clinic, or school verifies people by video, a…

Fact 1: An attacker does not need your password to impersonate you; they only need a recording of your face.

Fact 2: In testing, a replayed video of an unfamiliar person was identified with a similarity score of 0.09, far below the acceptance threshold of 0.45.

Fact 3: A printed photo of the correct person still passed the identity check, while a printed photo of the enrolled person matched at a 0.53-0.56 similarity score, above the acceptance threshold.

Fact 4: A screen playing a recorded video of a live session passed a liveness gate 39.5% of the time, despite the recording containing challenge answers on loop.

Fact 5: The timing of the challenge greatly limits this attack; the system only gives the caller 0.3 seconds to respond to a randomly chosen challenge.

Fact 6: No amount of image quality measurements, such as sharpness, noise, or moire, could differentiate a replayed video from a live face.

Fact 7: The only way to effectively detect a replay attack is by using a physical signal, such as a random color cast or depth/IR hardware, which a replayed video cannot replicate.

Fact 8: To verify people accurately, separate identity matching from liveness checks and implement random, timed challenges with a sub-second reaction window.

Fact 9: If a vendor claims their system can detect screen attacks through image quality alone, ask for their replay-attack pass rate, not their accuracy on still images.

Fact 10: The percentage of a looped screen replay of a cooperative live session that passes the gate should be publicly disclosed by every vendor.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

End-to-End Salesforce Automation: Lightning Components, a Dynamic DOM, and OTP MFA

Originally published on the CloudQA blog . Salesforce is a genuinely difficult platform to automate well, and the difficulty is structural rather than incidental.

  • Salesforce automation challenging due to dynamic DOM, Lightning components, OTP-based MFA
  • Stable selector strategy developed for dynamic DOM elements
  • Dedicated Chrome Debugger Profile maintained authenticated Salesforce session

Kubernetes 1.34 End of Life: What Actually Happens on EKS, GKE, and AKS

Kubernetes 1.34 reaches end of life upstream on October 27, 2026 . If you run it on EKS, GKE, or AKS, that date by itself changes very little.

  • Kubernetes 1.34 reaches end of life on October 27, 2026
  • EKS support ends December 2, 2026, extended support until December 2, 2027
  • GKE will automatically upgrade clusters to 1.36 after 1.34's end of life

Random Walk: A Tiny AI Nudge to Get Outside

This is a submission for the Hacktoberfest Open-Source AI Challenge Week 1: Touch Grass What I Built I built Random Walk , a small app that turns a few minutes of free time into a reason to step…

  • Random Walk is a small web app to encourage outdoor exploration.
  • Users set walk length, share location, receive waypoint and AI challenge.
  • GitHub Copilot SDK generates safe observation activity for quick walks.

More from Tuesday 6 October →