Skip to content
Global 100 Forum

My bank wants my voice as a password. Is voice ID safe against AI cloning?

Asked by Jules · 2 replies · updated

Short answer

ok so this one is personal. my bank nags me to enrol in voice ID every time I call ("my voice is my password") and now the company I do contract audio work for wants a voice check to get into the payroll portal. two different places want my voice to be the key.

CiteGlobal 100 Forum, "My bank wants my voice as a password. Is voice ID safe against AI cloning?", https://forum.global100.org/q/my-bank-wants-my-voice-as-a-password-is-voice-id-safe-against-ai/, accessed 2026-10-11.
Written by Jules ·
  1. Member ·

    here is my problem. I have something like 400 hours of my voice on the open internet. every episode, every guest spot, clean studio audio with nothing under it. if someone wanted training material for a clone of me, I have basically published the dataset myself.

    I remember the stories a couple of years back about reporters cloning their own voice to get into their accounts, but the bank says they have "liveness" and anti-spoofing now. is that real? can the system actually tell a cloned voice from a live human on a phone line, or is it mostly marketing? and is the fixed passphrase version any safer than the "just talk naturally" version?

    I am not paranoid about this, I just want to know if I should say no, and what I should ask for instead. would love the security people's take.

    0
    ReplyLink

2 more replies

Most helpful first
  1. Dan OkaforMember ·

    My credit union describes the voiceprint as being like a fingerprint, over a hundred characteristics, unique to you. I enrolled last year and honestly it is a relief not to remember another PIN. I would assume the people building this have thought about cloning; it is their money on the line as much as ours.

    Jules, your case is unusual because you have so much audio out there. For most of us there are maybe a few voicemails floating around. I would not lose sleep over it.

  2. Sam WhitlockMember ·

    The fingerprint comparison is marketing, and it points the wrong way for a threat model. A fingerprint is hard to collect without touching you. A voice is broadcast every time you open your mouth, and in Jules's case it is literally published with show notes. Biometric security rests on the sample being hard to obtain. Voice is the one biometric you hand out for free.

    Anti-spoofing is a real research area, not pure vapour. There is a whole community building countermeasures, and they do catch a lot of synthetic audio. But it is an arms race with the generators, and the defender has to win on every call while the attacker only needs one. The fixed passphrase is marginally better because the attacker needs the words too, except everyone's passphrase is the same sentence and it is printed on the bank's website.

    What to ask for instead: any factor you can revoke. You cannot rotate your larynx.

Write a reply

Plain text or simple Markdown. Links are nofollow. Your email is never shown.