惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

美团技术团队
N
Netflix TechBlog - Medium
WordPress大学
WordPress大学
云风的 BLOG
云风的 BLOG
J
Java Code Geeks
V
Visual Studio Blog
H
Help Net Security
Engineering at Meta
Engineering at Meta
Hugging Face - Blog
Hugging Face - Blog
Microsoft Security Blog
Microsoft Security Blog
腾讯CDC
博客园 - 【当耐特】
B
Blog
Stack Overflow Blog
Stack Overflow Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
大猫的无限游戏
大猫的无限游戏
GbyAI
GbyAI
博客园 - 司徒正美
博客园 - 叶小钗
Y
Y Combinator Blog
MyScale Blog
MyScale Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why
Face value: What it takes to fool facial recognition
Tomáš Foltýn · 2026-03-13 · via WeLiveSecurity

Privacy

ESET’s Jake Moore used smart glasses, deepfakes and face swaps to ‘hack’ widely-used facial recognition systems – and he'll demo it all at RSAC 2026

13 Mar 2026  •  , 2 min. read

Face value: What it takes to fool facial recognition

Facial recognition is increasingly embedded in everything from airport boarding gates to bank onboarding flows. The widely-held assumption is that a face is hard to fake and that matching a live face to a trusted source is a reliable identity signal.

Jake Moore, ESET Global Cybersecurity Advisor, recently put this assumption through several practical stress tests. His experiments showed that the powerful technology can actually be both misused and defeated.

In one test, Jake used a pair of modified off-the-shelf smart glasses that can identify people in real time. He walked through a public space, captured people’s faces and compared them against publicly available online data sources, with identity matches returned within seconds. The names and social media profiles were pulled from nothing more than people’s glances.

This ability might come in handy if, say, a conference attendee struggles to remember people's names, but it’s far less palatable when you consider what someone with ill intentions could do with that information.

The second demo had a different spin. It went after financial services, turning a fraud prevention system against itself. Using AI-generated images and freely available software, Jake created a fictitious face to open an actual bank account. The bank's facial recognition and eKYC (know your customer) platform accepted it as a genuine person.

After proving the point, Jake closed the account and shared all information with the bank, which has since shut down that specific method of identity abuse. But one broader question remains: how many financial institutions may still be susceptible to this kind of attack?

jake-facial-recognition-tom-cruise

Lastly, Jake added himself to a facial recognition watchlist at a busy train station in London. He then walked through the monitored area while running real-time face swap software that overlaid Tom Cruise’s likeness onto Jake’s own in the camera feed. The system, which is also used by the UK police, never recognized or flagged him. It was as if he simply wasn't there and anyone actively searching for him on CCTV would have seen the actor instead.

There's a lot more to these experiments than we can cover here – they’re all part of Jake’s talk at RSAC 2026, which is due in San Francisco from March 23rd-26th, 2026. If you're at the conference, consider attending the talk – after all, seeing this all work against an in-production system in a live environment is different from ‘just’ reading about it. To learn more, including about other ESET talks at the conference, visit this website.

The big picture

Facial recognition systems are being deployed with implicit trust that doesn't match their actual resilience when someone tries to break them – even where they only use off-the-shelf consumer hardware and easily available software, just like Jake did. Identity verification that is solely dependent on a face match clearly carries more risk than most people and organizations realize.

The experiments also send a message to vendors of facial recognition systems and anyone responsible for identity verification systems. Among other things, the systems should be tested in attack simulation settings and under other adversarial conditions. The technology behind facial recognition is fragile in ways that matter when someone attempts to subvert it.

rsac26-banner


Let us keep you
up to date

Sign up for our newsletters