/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

How activists and fraudsters are evading facial recognition, including by using face masks and paint and combining multiple faces to form a new identity

Wall Street Journal Parmy Olson

Context & Ripple Effects

Facial recognition spoofing has been graduating from lab stunts to real-world tradecraft for years: researchers fooled systems with printed paper eyeglass frames back in 2016, then claimed in late 2019 that 3D masks and photos could deceive Alipay, WeChat Pay and Schiphol Airport. What the WSJ documents now is that both sides of the surveillance fight have adopted the playbook.

Activists who built tools to identify police officers with off-the-shelf software — covered here earlier — are masking themselves against state systems, while fraudsters industrialize the same techniques. The endpoint visible in the coverage is synthesis: computer-generated "master key" faces that impersonate nearly half of the faces in three top systems, and identity verifier Socure reporting bad actors using social media selfies and generative AI to forge more realistic fake IDs.

First-order effects

  • Operators whose deployments were already shown vulnerable — Alipay, WeChat Pay, Schiphol Airport and China's train stations — now face adversaries actively exploiting those gaps rather than merely demonstrating them, forcing re-examination of face-as-password checkouts and border gates.
  • Identity verification vendors like Socure confront a rising volume of synthetic IDs built from scraped selfies and generative AI, raising false-negative risk for every customer onboarded on a face match alone.

Second-order effects

  • Verification providers will be pushed toward layered checks — liveness detection, device signals, document forensics — because each published bypass devalues single-biometric authentication and shifts procurement toward vendors who can show adversarial testing results.
  • The same arms race cuts both ways for law enforcement and activists alike: as masks and paint defeat state cameras, the activist-built tools identifying police rely on unmasked officers, making anonymity itself the contested resource.

Third-order effects

  • If blended and generated faces keep passing commercial systems, the industry's structural answer is to stop treating the face as a sole credential — folding biometrics into multi-factor stacks where a spoofed face unlocks nothing by itself.
  • Persistent spoofing success also strengthens the regulatory case for limiting mandatory biometric identification, since the coverage shows even well-funded deployments cannot guarantee the person behind the mask matches the enrolled identity.

The trend: Biometric identity is moving from a single face-match gate toward adversarially hardened, multi-signal verification, with each published spoof accelerating the shift for payments, travel and policing alike.

Discussion

  • @evanselinger Evan Selinger on x
    In today's episode of how current is your cyber jargon, we've got “synthetic identity fraud” perpetrated via folks using AI generated “Frankenstein faces.” cc: @hartzog & @FoxCahn. https://www.google.com/...
  • @martijnrasser Martijn Rasser on x
    Facial-recognition systems, long touted as a quick and dependable way to identify everyone from employees to hotel guests, are in the crosshairs of fraudsters https://www.wsj.com/... via @WSJ