CaraComp
CARACOMP DAILY · EP.81

Identity Verification On A Mobile: SIM Swap Failures Expose the Real Identity Verification Gap · Video Briefing

July 23, 20263:22Watch on YouTube →
Identity Verification On A Mobile: SIM Swap Failures Expose the Real Identity Verification Gap · Video Briefing
Chapter 1 of 3 · MOST TRUSTED, LEAST TRUSTED
0:00 / 3:22

Full Transcript

You've unlocked your phone with your face a thousand times. You trust it. Now ask yourself a harder question. Do you trust the company holding that scan afterward? Most people don't. They believe the technology works. They just don't believe anyone will keep the data safe. For you, that's the whole ballgame. A stolen password can be changed. A stolen face cannot.

MOST TRUSTED, LEAST TRUSTED ▶ 0:22

According to a global study published on Globe Newswire by Regula, biometrics is the most trusted way to prove who you are, yet fewer than half of people would actually choose it. And separate tracking shows trust in companies to protect that data cratered in two years, from about one in four people down to one in twenty.

The technology isn't the problem. The people holding your face are. Companies have been collecting it on borrowed trust for years. That's a bet that eventually gets called.

When the people building these systems fail you, the promise on the label starts to crack. Watch what happened in Europe.

A security researcher named Paul Moore looked at Europe's official age-verification app. In under two minutes, he walked right through it. If you're a parent who exhales when you see 'age verified,' this is a cold splash of water. That app was meant to keep kids out and let adults in. Instead, it was beaten with a simple browser add-on, built with A.I. help. Then, three months and thousands of fixes later, beaten again. Same trick.


THE GATE THAT FELL OFF ▶ 1:11

According to Cybernews, the European Commission spent two million euros on that app, part of a digital identity system meant to reach four hundred fifty million people. Experts say the flaw can't be patched. The design has to be rebuilt from scratch.

Kids learn workarounds faster than governments can fix them. An 'age verified' label tells you a check ran. It doesn't tell you it worked.

Both stories are about the same crack. Companies measure your face and hope you won't ask what happens next. One court just asked for them.

You click 'try on' at an eyewear site. Ten seconds later, glasses appear on your face. Feels like a fun filter. But in those seconds, software may have mapped your face to hundreds of exact reference points. The distance between your eyes. The width of your cheekbones. That's not a photo. That's a blueprint. And a blueprint of your body has legal protections a snapshot doesn't.


IT'S A MEASUREMENT, NOT A FILTER ▶ 2:04

According to Law.com, a federal appeals court just revived a class action against an eyewear company that tried to dodge Illinois biometric law by calling its glasses a health product. The judge's response? Better-appearing glasses are not medical treatment.

The law doesn't care what you started with. It cares what you extracted. Measure a face from a photo, and you've created protected data. Now you know to ask.

Three stories, one thread. Your face is being collected everywhere. By banks, by governments, by shopping sites. And each one asks you to trust that they'll handle it right. The scanning is easy. Earning that trust is the part everyone keeps skipping.

Links to every story and today's podcast deep-dives are in the description. See you next time.

Sources

Stories in This Episode