My bank wants my voice as a password. Is voice ID safe against AI cloning?
ok so this one is personal. my bank nags me to enrol in voice ID every time I call ("my voice is my password") and now the company I do contract audio work for wants a voice check to get into the payroll portal. two different places want my voice to be the key.
Cite
Global 100 Forum, "My bank wants my voice as a password. Is voice ID safe against AI cloning?", https://forum.global100.org/q/my-bank-wants-my-voice-as-a-password-is-voice-id-safe-against-ai/, accessed 2026-10-11.here is my problem. I have something like 400 hours of my voice on the open internet. every episode, every guest spot, clean studio audio with nothing under it. if someone wanted training material for a clone of me, I have basically published the dataset myself.
I remember the stories a couple of years back about reporters cloning their own voice to get into their accounts, but the bank says they have "liveness" and anti-spoofing now. is that real? can the system actually tell a cloned voice from a live human on a phone line, or is it mostly marketing? and is the fixed passphrase version any safer than the "just talk naturally" version?
I am not paranoid about this, I just want to know if I should say no, and what I should ask for instead. would love the security people's take.
2 more replies
Most helpful first- Dan OkaforMember ·
My credit union describes the voiceprint as being like a fingerprint, over a hundred characteristics, unique to you. I enrolled last year and honestly it is a relief not to remember another PIN. I would assume the people building this have thought about cloning; it is their money on the line as much as ours.
Jules, your case is unusual because you have so much audio out there. For most of us there are maybe a few voicemails floating around. I would not lose sleep over it.
- Sam WhitlockMember ·
The fingerprint comparison is marketing, and it points the wrong way for a threat model. A fingerprint is hard to collect without touching you. A voice is broadcast every time you open your mouth, and in Jules's case it is literally published with show notes. Biometric security rests on the sample being hard to obtain. Voice is the one biometric you hand out for free.
Anti-spoofing is a real research area, not pure vapour. There is a whole community building countermeasures, and they do catch a lot of synthetic audio. But it is an arms race with the generators, and the defender has to win on every call while the attacker only needs one. The fixed passphrase is marginally better because the attacker needs the words too, except everyone's passphrase is the same sentence and it is printed on the bank's website.
What to ask for instead: any factor you can revoke. You cannot rotate your larynx.
Write something first.
Give people something to work with: at least 30 words on what happened and what you tried.
That is too long. Keep it under 6,000 characters.
Write the question as the title, 15 to 140 characters, no links.
Pick a category.
Add a name (2 to 40 characters, no links).
That email address does not look right.
That was quick. Read the thread, then try again.
The form expired. Reload the page and post again.
Something went wrong with the form. Reload and try again.
Please complete the check and post again.
Limit reached for now. Try again later.
This thread is closed to new replies.
This thread no longer accepts replies.
Something went wrong with the form. Reload and try again.
Post a reply or question first (name and email), then this browser can vote, edit and accept answers.
You cannot vote on your own post.
Only the author (within 30 days) or the forum team can do that.
That email belongs to a forum team account. Use your sign-in link instead.
New accounts are paused for the moment. Try again later.
That was already posted.