That "Instant" ID Check Can Be Fooled by Words You Can't See
That "Instant" ID Check Can Be Fooled by Words You Can't See
This episode is based on our article:
Read the full article →That "Instant" ID Check Can Be Fooled by Words You Can't See
Full Episode Transcript
A document can carry a secret message that no human eye will ever see. Not a watermark. Not fine print. Words written in white text on a white background, or hidden characters that take up no space at all. And when a computer reads that document to check who you are — it might follow those hidden words like an order.
If you've ever uploaded a photo of your license to
If you've ever uploaded a photo of your license to open a bank account, this story is about you. More and more, the thing on the other end isn't a person. It's an artificial intelligence system that scans your document, pulls out the text, and decides if you're really you. Security researcher Pasquale Pillitteri points to a real court case in Connecticut where this trick already showed up in a filing — invisible white text buried inside a document. The danger isn't a fake ID card. It's that the machine reading your real one can be tricked by text you'll never notice. So how does a document you can't see anything wrong with turn into a weapon?
Let's start with what these hidden messages actually look like. The concealment tricks range from white letters on a white page — to what are called zero-width characters, invisible symbols that take up literally no space. Some attackers even hide instructions in the file's metadata, the behind-the-scenes notes attached to a document. Stare at the page all day and you'll see nothing. But the machine reads every character. Up next: Your Moms Voice On The Phone Isnt Proof Anymore Heres The 10.
Here's why that matters. Many of these systems use something called O-C-R — software that turns a picture of text into readable text. The problem isn't that the O-C-R gets it wrong. The problem is it gets it right — and then hands everything it found straight to the A-I as if it were a command. Researchers call this indirect prompt injection. That's a mouthful, so picture it this way: the system can't tell the difference between what a document *shows* and what hidden words in it secretly *say*.
This is spreading fast
And this is spreading fast. According to industry figures compiled by S-Q Magazine, hidden instructions tucked inside images or documents now make up nearly one in ten experimental attacks this year. The same research found that in roughly a third of the A-I systems tested, attackers pulled out secret internal instructions the system was never supposed to reveal. A third. That's not a rare glitch.
Google saw it too. Between late last year and early this year, Google measured about a third more malicious activity across the public web. The people behind these attacks aren't experimenting anymore. They're using it.
Now the part that should sit with you. Your own documents could carry these invisible words by accident. Copy and paste from a template, and leftover hidden text can ride along without you knowing. That means a perfectly honest file — one you sent in good faith — could still trigger something on the other end you never intended.
The Bottom Line
The industry says it's fighting back, layering in checks for deepfakes and tampered documents. But those defenses look for a fake — a forged photo, a bad format, a doctored seal.
Here's the twist that reframes the whole thing. A flawless, genuine-looking document can still be the attack. The fraud checks pass, no tampering trips an alarm — because the danger isn't a broken document. It's a perfect one whispering an order the machine chooses to obey.
So here's the whole thing in plain terms. Some A-I systems that verify your identity read every word in a document — even words hidden from human eyes. Attackers slip in invisible instructions, and the machine can follow them like commands. The fix isn't better scanning — it's teaching the system that a document is evidence to examine, not a voice to obey. Whether you're building these systems or just uploading your license to sign up for something, the takeaway is the same. What a machine reads isn't always what you can see. The full story's in the description if you want the deep dive.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Episodes
A 99.7% Accurate Face Search Can Still Finger 3,000 Innocent People — Including You
A face search system can be ninety-nine point seven percent accurate and still point at three thousand innocent people. Not because it's broken. Because that's exactly what the math does when you search a database of a mi
PodcastGoogle Will Now Erase Your Leaked ID From Search. Your Face Is Already Gone.
A convincing scam video doesn't work because the fake is good. It works because the name is real. The photo is real. Sometimes the home address is real too. This week, Google rolled out a bigger version of its tool called
PodcastPlayStation Now Wants Your Kid's Face Before It Sells Them a Game
In Australia, before your teenager can buy a mature-rated video game, PlayStation now wants to scan their face. Not their name. Not a password. Their actual face. Or a photo of a government ID — driver's license, passport, take your pick. <br
