What Is Synthetic Identity Fraud? How Users and Businesses Get Fooled
Here's a fact that should bother you more than it probably does: a security system can be completely accurate and completely obsolete at the same time.
Not broken. Not hacked. Just... tested against the wrong threats. Certified in January against fraud methods that fraudsters abandoned by March. Still displaying its "99% accuracy" badge while the people it's supposed to stop have already moved on to six new techniques it's never seen.
That's not a hypothetical. That's the current state of identity verification, the systems that decide whether the face on your screen is really you.
Identity fraud now evolves faster than the tests used to catch it, so an "AI-powered" accuracy claim tells you almost nothing unless you also know when it was last tested against current fraud methods.
Online Identity Verification Methods: Tested Against Old Threats
Imagine a company makes a door lock. They test it in January against every known break-in technique. It blocks all of them. They announce: "99% secure." Great.
Starts at 01:54 — this story3:13
Watch this story, in under a minute
A new briefing every weekday — three stories, three minutes.
Subscribe on YouTubeBy June, burglars have moved on. They're using six new tools the lock company never tested against. The lock hasn't changed. The threat has.
Now ask yourself: does that 99% number still mean anything?
That's exactly what's happening with identity verification right now. The tools that check whether you are who you say you are, the face scans, document checks, and "selfie match" steps you do when you open a bank account or verify your age, get tested, scored, and certified. Then they go live. And fraud keeps moving. This article is part of a series, start with Face Detection Before Identification How Facial Analysis Act.
The gap between those two things is the problem nobody talks about when an app brags about being "AI-powered."
Why Fraud Now Moves at Machine Speed
Here's what changed. Fraud used to require effort. A criminal had to manually create a fake ID, scout a target, figure out what worked. That took time. That time gave defenders a chance to catch up.
Not anymore.
Today's fraud operates more like a startup running A/B tests (that's the practice of trying two slightly different versions of something to see which one performs better, except here, "performing better" means getting past your bank's security). Attackers deploy hundreds of variations simultaneously. They adjust the lighting on a fake selfie, tweak a synthetic identity's address, change a payment method. Automation tracks which variations slip through. The ones that work get scaled immediately across thousands of targets.
This is what researchers call a "continuous test-and-learn cycle." And it's not a metaphor, it's literally how modern fraud operations run, according to reporting from Adyen's 2026 Fraud Report. The fraudsters are running experiments. The defenders are reading last quarter's results.
The cost collapse made this possible. Deepfake images, fake voices, synthetic identities built from scratch, you can access all of that for as little as $5, according to Protegrity's 2026 analysis. When attacking costs almost nothing, attackers can afford to try everything. When defending costs millions in engineering time, defenders can't possibly match that pace with old-school annual reviews.
Let that sink in. Deepfakes went from "a thing we're worried about" to "one in every five fraud attempts" in less than two years. And injection attacks, where fraudsters bypass the camera entirely and feed a fake video stream directly into the verification system, surged 40% year-over-year, according to Entrust's 2026 Identity Fraud Report. These aren't slow trends. This is a monthly redraw of the threat map. Previously in this series: A Fake Video Of Your Boss Just Dropped Do These 3 Things Bef.
Why 99% Accuracy Claims Mislead in Identity Verification
Here's why people trust accuracy numbers, and why that trust is misplaced in this specific situation.
When you hear "99% accurate," your brain does something totally reasonable. It treats accuracy like a physical property. A thermometer that reads temperature correctly in January still reads it correctly in June. A ruler that measures twelve inches in 2024 measures twelve inches in 2025. Accuracy sounds stable, like a fact about the tool itself.
That instinct is correct for most things. It's wrong for identity verification.
In this context, accuracy isn't a fixed property of the technology. It's a score the technology earned against a specific set of fraud methods that existed at a specific point in time. Train a system to catch stolen photos and document forgeries, test it against those threats, and it might genuinely score 99%. Then a new attack category appears, say, AI-generated synthetic faces that don't belong to any real person, and suddenly the system is evaluating something it was never taught to recognize. The accuracy hasn't "dropped." The system has been outmaneuvered by something outside its test parameters.
Researchers call this "signature drift", the idea that fraud patterns shift so fast that the rules a system learned become outdated before teams even have time to update them. As Protegrity puts it, static defenses expire not because they fail, but because the threat moves past them.
It's not that the tool got worse. It's that the world changed around it.
"What worked yesterday can be bypassed tomorrow, with patterns of fraud changing so rapidly that rule engines expire before teams have time to update them." Protegrity, AI Fraud Detection in 2026
The Real Question Nobody Thinks to Ask
So what do you actually do with this information? Up next: Before Facial Recognition Names You It Has To Find You And T.
The shift happening across the identity verification industry right now, documented in detail by Biometric Updateis a move away from one-time accuracy claims toward continuous testing. Instead of "we scored 99% in our last evaluation," the better question is: "how often do you re-test against new fraud methods, and when was the last time you did?"
Think of it like food safety. You wouldn't trust a restaurant that says "we passed a health inspection in 2022." You want to know when the last inspection was, and whether the inspector knew what to look for this year.
Identity verification is heading toward the same logic. Static certifications are losing meaning. The tools that deserve trust are the ones that can show their testing is ongoing, continuously updated against the fraud techniques that exist today, not the ones that existed when the product launched.
At CaraComp, this is exactly the kind of gap that matters when evaluating any system making facial comparisons, whether that's verifying someone's identity at account opening or checking whether two images are the same person. A system's accuracy in controlled conditions can drop anywhere from 10% to 40% in real-world production environments, according to TechnoLynx research on facial recognition deployment. Add an evolving fraud environment and that gap gets wider. The right question was never just "how accurate?" It was always "accurate against what, and when?"
What You Just Learned
- 🧠 Accuracy is conditional, not fixeda tool's accuracy score is tied to the fraud methods it was tested against, not a permanent property of the technology
- 🔬 Fraud now runs like softwareattackers use automated test-and-learn cycles to find weaknesses faster than defenders can update their defenses
- 💡 The speed is the problemdeepfakes went from emerging to one in five fraud attempts in under two years; annual testing cycles can't keep pace with that
- 🧠 The right filterdon't ask "how accurate is this system?"; ask "when was it last tested against fraud methods that exist right now?"
"AI-powered" tells you nothing useful about a security system. The question that actually matters is whether it's being tested against the fraud methods that exist this monthnot the ones it was designed to catch two years ago. Accuracy expires. Testing schedules don't lie.
Next time an app or service asks you to verify your identity and drops some version of "advanced AI security" in the fine print, know that this phrase tells you almost nothing. A system trained on last year's attacks, tested once, and left untouched is still "AI-powered." It's just AI-powered against threats that might not be the ones trying to get through the door anymore.
The badge that would actually mean something? "Last tested: this quarter, against current methods." You'll almost never see it. But now you know to wonder why.
What Is Synthetic Identity Fraud? The Short Answer
What is synthetic identity fraud? It's a form of identity fraud where a criminal builds a brand-new, fabricated person instead of stealing someone's whole identity. The fraudster combines a real Social Security number, often one that belongs to a child, an inmate, or someone who rarely uses credit, with a made-up name, address, and date of birth. Because no real person matches that exact combination, there's no victim checking a credit report for early warning signs, which is exactly what makes synthetic identity fraud harder to catch than classic identity theft.
Synthetic Identity: A Person Who Doesn't Exist
A synthetic identity is the fabricated profile itself, the blended file of real and invented details that lenders and verification systems treat as a genuine applicant. Unlike a stolen identity, a synthetic identity has no original owner who can report it missing or dispute a charge, so it can operate undetected for months or years. Fraudsters often nurture a synthetic identity slowly, using it to pay small bills on time and build a thin but believable credit history before striking with a large, unpaid balance.
Fraud, in the plain sense that applies here, means using deception to obtain money, credit, or access that wouldn't otherwise be granted. Synthetic identity fraud is one category of fraud among many, but it's distinct because the deception isn't aimed at impersonating a specific victim, it's aimed at inventing an applicant that looks statistically normal to a lender's systems. Credit card issuers, auto lenders, and other credit-granting businesses are common targets, since a synthetic identity's whole purpose is usually to open a credit line, run it up, and disappear before the debt comes due. Understanding fraud this way helps explain why fixes built for one type of fraud, like classic account takeover, often fail to catch synthetic identity fraud at all.
Identity theft is the term most people already know, and it's worth separating clearly from identity fraud built on a synthetic person. Identity theft happens when a criminal steals a real, living person's actual information, their name, Social Security number, and existing credit history, and uses it to open accounts the real victim never approved. Synthetic identity theft is a related but less common variation, where pieces of a real person's identity are blended with fabricated details rather than used wholesale, which is part of why some fraud teams treat it as its own category worth tracking separately from both classic identity theft and fully synthetic identity fraud.
Credit is the resource nearly all of this activity is aimed at, whether the credit takes the form of a credit card, an auto loan, or a line of credit at a bank. A synthetic identity typically applies for credit repeatedly across different lenders, since each approved credit line adds to the illusion of a legitimate borrower with a growing credit history. Lenders that pull credit reports as their main check can be fooled because a synthetic identity's thin credit file often looks like a young, first-time borrower rather than an obvious fake, especially before enough shared data points accumulate across the industry to expose the pattern. This is part of why credit-granting businesses increasingly pair credit report checks with device intelligence and identity data verification rather than relying on credit history alone.
Personal data sits at the center of every synthetic identity, since the fabricated profile is built by combining fragments of real personal data with invented details rather than inventing everything from scratch. A Social Security number is the single most valuable piece of personal data in this scheme, because it's the anchor that lets a fabricated name and address get treated as a real, credit-eligible person. Businesses that verify personal data against issuance records, confirming a Social Security number was actually issued to the age group and timeframe claimed, catch synthetic identities that a simple name-and-address check would wave through.
Banking systems face the same exposure as consumer lenders, since a bank account is often the next step after a synthetic identity has built enough credit history to look trustworthy. A fraudster may open a checking account, layer in a credit card, and use the banking relationship itself as further evidence of legitimacy for later, larger credit applications. Banking fraud teams that share data on suspicious identity patterns across institutions have a better chance of spotting a synthetic identity than any single bank checking its own records in isolation.
Credit scores are supposed to summarize a borrower's reliability, but a synthetic identity can build a respectable credit score precisely because credit scoring models reward on-time payments and account age without asking whether the underlying person is real. A synthetic identity's credit scores often climb steadily for months, which is what allows the eventual default to cause outsized damage, lenders extended more credit because the credit scores said this looked like a safe, seasoned borrower. That gap between a rising credit score and an entirely fabricated person is one of the clearest reasons synthetic identity fraud demands checks that go beyond the score itself.
Legal consequences for synthetic identity fraud can be harder to pursue than for classic identity theft, in part because there's no single victim demanding justice the way a real person would after having their identity stolen. Prosecutors still treat synthetic identity fraud as a serious financial crime, but building a legal case often requires piecing together a paper trail across multiple lenders and years of activity rather than relying on one victim's complaint. This legal complexity is another reason prevention, catching a fabricated identity before credit is extended, matters more here than in cases where a legal remedy is more straightforward to pursue after the fact.
Data sharing among lenders, credit bureaus, and identity verification vendors is one of the more effective tools against synthetic identity fraud, since a single fabricated identity often leaves small, inconsistent traces of data across multiple applications that no one lender would notice alone. When one business flags suspicious data tied to a Social Security number or address, sharing that data with industry partners helps other businesses avoid extending credit to the same fabricated identity. This kind of coordinated data use doesn't stop synthetic identity fraud completely, but it shrinks the window during which a fabricated identity can operate undetected across an entire industry rather than just one company.
Identities built through this method are deliberately designed to be forgettable, not flashy, not obviously suspicious, just ordinary enough to pass a routine check. That ordinariness is the whole strategy behind synthetic identities: a fabricated file that draws no attention is far more valuable to a fraudster than one that raises red flags on the first application. Businesses that specifically train their systems to look for identities with no history anywhere else, rather than identities that look actively suspicious, catch far more synthetic identity fraud than those looking only for obvious red flags.
Information gaps are often the clearest tell that an identity is synthetic rather than real, since a genuine person usually has some digital footprint, a previous address, an old utility bill, a prior credit inquiry, that a fabricated identity simply doesn't have. When identity verification and identity data checks turn up information that doesn't connect to anything before the current application, that absence of information is itself a meaningful fraud signal. Businesses that treat a total lack of prior information as suspicious, rather than assuming no history simply means a young or new customer, are better positioned to catch synthetic identity fraud before it results in a financial loss.
Answering "what is synthetic identity fraud" completely also means understanding why it keeps growing: it's cheaper to fabricate a synthetic identity than to steal a real one, and the payoff, months of undetected credit access, can be larger. As long as credit-granting businesses reward thin, quiet credit histories with more credit, synthetic identity fraud will keep finding lenders willing to extend it. That's why the same principle from earlier in this article applies here too: a verification system that hasn't been retested against current synthetic identity fraud patterns is checking for yesterday's fabricated identities while today's walk right through.
Digital Identity Verification: Where the Terminology Gets Confusing
Digital identity verification is the umbrella term for any process that confirms a person is who they claim to be using electronic means rather than a face-to-face check at a counter. It covers document scans, selfie checks, database lookups, and behavioral signals, all combined into a single decision about whether to let someone in. The practical consequence is that a weak link anywhere in that chain, say, a document check that hasn't been updated against new forgery techniques, can undermine an otherwise strong system, because customers and fraudsters alike only need to find the softest point.
Digital Verification: Convenience Built on a Moving Target
Digital verification replaced in-person checks because it's faster and cheaper for both the business and the customer, but that speed depends entirely on the underlying models staying current. A digital verification step that hasn't been retrained against this year's fraud methods can approve a fraudulent applicant just as quickly as it approves a genuine one. That's the tradeoff nobody mentions in the marketing copy: convenience scales instantly, but so does the risk when the system falls behind.
Verification Online: Why the Setting Changes the Risk
Verification online happens without a human in the room, which means the system has to do, entirely on its own, everything a bank teller or notary used to do by eye. There's no one to notice that the applicant seems nervous, or that the ID looks slightly off in a way a scanner might miss. That's precisely why online checks need constant retesting, the absence of a human backstop means the automated system is the only line of defense.
Digital Identity: A Concept Bigger Than Any Single Check
A digital identity is the full collection of data points, credentials, and behavioral patterns that represent a person online, not just one selfie or one document, but the accumulated digital trail. Verification methods only ever check a slice of that identity at any given moment, which is why a single passed check doesn't guarantee the identity behind it is genuine forever. Treating digital identity as something to verify once, rather than something to monitor, is part of why static accuracy badges mislead people.
Biometrics: Useful, But Not a Silver Bullet
Biometrics, fingerprints, face geometry, voice patterns, feel more trustworthy than a password because they're tied to a physical person rather than something memorized. But biometrics can be spoofed too, and the deepfake and injection attack numbers cited earlier show that fraud against biometric systems is rising, not falling. A biometric check is only as strong as its ability to tell a real face from a synthetic one, and that ability degrades the moment fraud techniques move past what the system was trained to catch.
Digital Identity Verification Methods: Layering Instead of Relying on One Check
Most serious digital identity verification methods today combine more than one signal, a document scan plus a selfie match plus a database cross-check, because relying on a single method leaves an obvious gap for fraudsters to exploit. Layering doesn't make a system immune to drift, but it does mean an attacker has to defeat multiple checks simultaneously rather than just one weak link. This is part of why the "how often is it retested" question matters more than the accuracy badge on any single component.
Document Verification: The Oldest Check With New Problems
Document verification checks whether a government-issued photo ID is genuine, unaltered, and actually belongs to the person presenting it. It used to be the hardest step to fake convincingly, but cheap synthetic media has made forged or fully fabricated documents far easier to produce than they were even a few years ago. A document verification step that hasn't been updated to catch AI-generated fakes is checking for yesterday's forgeries while today's walk right through.
Methods of Identity Verification: There Is No Single Best Option
There are several broad methods of identity verification in use today: document checks, biometric matching, database and credit-bureau lookups, and behavioral analysis that watches how someone interacts with a device. None of these methods is complete on its own, and the right combination depends on what a business is trying to protect and how much fraud risk it's willing to accept. Understanding that tradeoff is more useful to a reader than memorizing which method claims the highest accuracy score, since that score is only ever a snapshot in time.
Identity Data Verification: Checking the Details Behind the Face
Identity data verification confirms that the personal details someone provides, name, address, date of birth, government ID number, actually match records held by a trusted third party, like a credit bureau or government database. It's a different check from a selfie or document scan because it's verifying the data itself rather than a physical artifact or biometric trait. When identity data verification and biometric checks disagree, that mismatch is often the clearest early signal that something in the application isn't what it claims to be.
Identity Verification Solutions: What Businesses Are Actually Buying
Identity verification solutions are the packaged products a business licenses instead of building document checks, selfie matching, and database lookups from scratch. A business shopping for identity verification solutions is really deciding how much fraud risk it can tolerate versus how much friction it can put in front of a genuine customer during signup. Compliance requirements in regulated industries often force this choice, since a business may need to prove to auditors that its verification process meets a minimum bar, not just that it feels secure.
Confirm User Identities Remotely: The Core Job of Every Method
Every method discussed here exists to confirm user identities remotely, without a human present to catch what a machine misses. That single requirement, proving a real person is who they claim to be, over a screen, in seconds, is what forces document checks, selfie verification, and database lookups to work together instead of alone. When a business can confirm user identities remotely with confidence, it can open accounts, approve transactions, and onboard customers without the delay and cost of an in-person visit.
Selfie Verification: Fast, But Only as Good as Its Last Update
Selfie verification asks a user to take a live photo, then compares it against the photo on their submitted identity documents to confirm a match. It's popular because it's quick and doesn't require special hardware, but selfie verification is also the exact step that deepfake and injection attacks target, since it's the point where a synthetic face has the best chance of slipping past automated review. A selfie verification step tested only against last year's fraud techniques is, in practice, checking for threats that customers rarely use anymore.
Automated Verification: Speed Without a Safety Net
Automated verification removes the delay of waiting for a human reviewer, letting a customer open an account or complete a purchase in minutes instead of days. That speed is valuable for legitimate customers and businesses alike, but automated verification also means there's no person double-checking an edge case before a decision gets made. Compliance teams increasingly ask vendors how automated verification systems are retrained over time, precisely because a fast wrong answer is still a wrong answer.
Government-Issued Photo ID: The Anchor Document, Now Easier to Fake
A government-issued photo ID has long served as the anchor document in identity verification because it's issued by an authority with its own vetting process before the card or license ever reaches the applicant. That assumption is weaker than it used to be, since synthetic media tools can now generate convincing fake versions of a government-issued photo ID without needing a real template to copy. Any process that leans on a government-issued photo ID as its primary check needs a way to verify the document itself hasn't been fabricated.
Identity Documents: One Piece of a Larger Puzzle
Identity documents, passports, licenses, national ID cards, provide a physical or digital artifact that a verification system can inspect for signs of tampering or forgery. Checking identity documents in isolation misses fraud that doesn't involve a fake document at all, such as a stolen but genuine identity paired with a synthetic selfie. That's why identity documents are treated as one input among several, not the final word on whether an applicant is who they claim to be.
None of this means businesses should give up on verification, or that customers should assume every online process is unsafe. It means both sides benefit from understanding that verification, authentication, and compliance checks are processes, not one-time events. A business that treats identity verification as a continuous process, retesting, updating, and monitoring, protects its customers and its own compliance posture far better than one that certifies once and moves on. Users who understand this can also ask better questions of the services holding their information, like when a bank or app last updated the process behind its email confirmation and identity checks.
Secure identity verification methods are only as good as the last threat they were tested against, which is why a single accuracy score can never tell the whole story. When a business talks about secure identity verification methods, it should mean an ongoing process of checking documents, matching selfies, and verifying identity data against fraud patterns that exist right now, not a certificate earned once and never revisited. A supervised remote identity verification session, for example, adds a trained reviewer watching the process in real time, which can catch things a fully automated check misses, though it adds cost and time that not every business can afford for every signup.
Authentication and verification solve related but different problems, and mixing them up is a common source of confusion. Verification confirms who someone is at a single moment, usually at signup or account opening, using a document, a selfie, or identity data checked against a trusted source. Authentication happens every time afterward, confirming that the person logging in is the same one who was verified originally, typically through a password, a one-time code, or a login step tied to a device. A system can have excellent verification and weak authentication, or the reverse, and both gaps get exploited by fraudsters looking for the softest point of entry.
Authorization is a third piece that often gets confused with the first two. Once authentication confirms a returning user is who they claim to be, authorization decides what that person is allowed to do inside the account or system. A login that authenticates correctly but hands out too much authorization, access to funds, settings, or data beyond what that user needs, creates risk even when the identity verification and authentication steps both worked exactly as designed.
Identity proofing is the term many compliance teams use for the initial step of establishing that a real, unique person exists behind an application, before any ongoing authentication ever happens. It typically combines document verification, a selfie or other biometric check, and identity data verification against outside records, all aimed at confirming a genuine identity rather than a synthetic or stolen one. Solutions that skip a thorough identity proofing step at the start put every later authentication and login attempt on a shaky foundation, since there's no way to fix a weak initial check after the fact.
Iris scanning is one of the less common biometric options compared to face or fingerprint checks, but it shows up in higher-security settings where the cost of a false match is severe. Like other biometric methods, iris scanning depends on the underlying matching software being tested against current spoofing techniques, not just the physical hardware working correctly. A business considering iris scanning should ask the same question that applies to every other method here: when was this specific check last tested against attacks that exist today, not attacks from when it was first deployed.
There is a wide variety of secure identity verification methods available to businesses today, and no single one covers every risk on its own. Document checks catch fake or altered IDs, selfie and iris scanning catch cases where someone tries to use somebody else's identity, and identity data verification catches mismatches that a photo alone would never reveal. Choosing among that variety isn't about finding the one perfect method; it's about combining enough of them, and retesting all of them often enough, that a gap in one is caught by another.
Trust in any of these systems has to be earned continuously, not granted once and assumed to last. A business builds trust with regulators, partners, and customers by showing its verification, authentication, and authorization steps are retested on a schedule, not by pointing to a badge earned years ago. Customers extend trust to a service the moment they hand over a document or a selfie, and that trust is broken the instant a preventable fraud slips through a check that hadn't been updated.
Compliance requirements increasingly reflect this shift, pushing businesses toward documented, ongoing testing rather than a one-time certification filed away and forgotten. Regulators in many industries now expect evidence that verification and authentication systems are reviewed on a regular cycle, with records showing what fraud methods were tested and when. Meeting compliance on paper is not the same as reducing actual risk, which is exactly why the retesting question matters more than whichever badge a vendor puts on its homepage.
Risk, in this context, isn't a single number a business can calculate once and file away; it shifts every time fraud tactics shift. A login protected by strong authentication today can become a weak point next month if attackers find a new way to defeat it, which is why ongoing monitoring matters as much as the initial setup. Businesses that treat risk as a moving target, and that build authorization and authentication solutions around that assumption, end up far better protected than those that treat any single certification as the finish line.
Real-Time Synthetic Identity Fraud Detection: Catching the Problem Before Money Moves
Real-time synthetic identity fraud detection means a system flags a suspicious application the moment it comes in, not weeks later when a lender reviews
Frequently asked questions
What is real-time synthetic identity fraud prevention?
Real-time synthetic identity fraud prevention means checking whether the face or identity on a screen is genuine at the moment it appears, rather than relying on a system certified against fraud methods that may already be outdated. Because fraud evolves fast, prevention only works if verification reflects current threats, not January's test results applied in a later month.
Why do 99% accuracy claims mislead in identity verification?
A 99% accuracy badge only reflects performance against the fraud techniques known at the time of testing. If a system was certified in January and fraudsters moved to six new techniques by March, that same badge stays displayed even though it no longer represents current protection, making the number misleading without a testing date attached.
Why does synthetic identity fraud move faster than verification systems can adapt?
Identity fraud now evolves faster than the tests built to catch it, so a system tested and certified against known methods can become obsolete within months without ever being broken or hacked. It simply keeps facing new techniques it was never checked against, which is why accuracy claims alone say little about actual protection.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Biometrics: 5 Sleep Numbers Map a Woman's Cycle Daily
Stanford researchers used five simple biometric measurements to map the menstrual cycle day by day. Here's what that means for anyone wearing a smartwatch or fitness tracker.
privacyBiometric consent: Japan shields kids under 16 by law
You can agree to a face scan and still get burned. Japan's new privacy rules show that biometric consent is only step one, not the whole safety net, especially for kids.
biometricsBiometric Payment: The Fingerprint Never Leaves the Phone
Your fingerprint doesn't travel to the store when you tap to pay. Here's what actually gets sent, why it's safer than a password text, and how to spot the difference next time an app asks for your face.
