Skip to content
Utah Community Learning

AI voice cloning and the newer tricks I'm still learning

About 18 minutes

AI voice cloning and the newer tricks I'm still learning

The previous session examined romance scams and how slowly that con unfolds. This lesson is adjacent but distinct. It concerns your voice, or your grandchild's voice, or your bishop's voice, being reproduced accurately enough to deceive you over the phone.

I will be direct at the outset. This is the section of the course where I am not the authority in the room. I keep the categories stable from year to year, but the tools these operators use change every few months, and some of what I am presenting today I learned only a couple of weeks ago. I will flag the points where I am uncertain.

The mechanism

Software now exists, and is easy to locate, that takes a short clip of a person's voice, perhaps from a posted video, a voicemail greeting, or a TikTok, and generates new sentences in that same voice. Not a synthetic robotic voice. Their voice, producing whatever text the operator supplies.

So the call that once involved a stranger reading a poor script while pretending to be your grandson is now, in some cases, a voice that genuinely sounds like your grandson, stating that he is in trouble and needs money sent right now, and not to tell his parents.

That is the entire mechanism: urgency combined with a familiar voice. It is precisely the combination that suppresses the part of the brain that would otherwise slow down and verify.

The widow in our ward

I have told you before that romance scams are not amusing, and I want to make a similar point here, in a quieter register than my usual class delivery.

A few years ago a widow in our ward was courted by an account claiming interest in her, patiently and warmly, for about a month before her family recognized what was happening. No one in that family is careless. No one is foolish. She was lonely on an ordinary Tuesday, and the person on the other end of the screen was very good at the job.

I raise it here because voice cloning operates on the identical hinge. It is not fundamentally a technical problem. It is an emotional one in a technical costume: someone who loves you, or sounds like someone who loves you, requesting help. That is the whole con. The AI component only improves the disguise.

Countermeasures

You cannot out-engineer this one. No application prevents a cloned-voice call from reaching you. So we return to habits, as always.

Establish a family password. Select a word, something specific and arbitrary, not "password" or your dog's name. If anyone in the family calls requesting money or asking you to bail someone out of trouble, they state the word. No word, you hang up and call them back on their actual number. Do this today, at dinner, while everyone is together.

Hang up and call back, every time. If you receive a call that sounds like your child or grandchild in trouble, hang up. Call their number directly, the one already stored in your phone, not a number they gave you during the call. This single habit defeats nearly every version of this scam, cloned voice or otherwise.

Slow down deliberately. I have stated this in every class and will continue to, because it remains the entire game. Scams require you to move quickly. If a call causes your stomach to drop and your hand to reach for your wallet within the same thirty seconds, that reaction is the indicator, not the content of what was said.

Limit the voice and video you publish. I am not advising anyone to abandon social media. But the more clean audio of your voice that exists publicly, the easier you are to clone. If your account is public and does not need to be, restrict it. Kylie asked me about this after her Microsoft call scare, and I gave her the same answer I am giving you: it is a small setting, it takes five minutes, and it makes you a marginally harder target. That is all any of this is. A marginally harder target.

Verify through the ordinary channel when uncertain. Text the person. Ask a question only they could answer, something not available on the internet. A cloned voice can produce anything the operator types, but it cannot know your family's answer.

What I don't know yet

I do not know how to identify a cloned voice by ear reliably, and I do not expect that you will either. The good ones are good. I have heard demonstrations that deceived me. So I am not going to stand here and tell you to "listen for the flat spots" or similar, because that advice is already going out of date. What does not go out of date is the callback rule: hang up, call the real number, ask the arbitrary password question. That part holds regardless of how convincing the fake becomes.

In fairness, this is the one topic where you may encounter a new development in the news before I do. If you see a new variant of this trick, forward it to me. That is genuinely how I keep the notebook current.

Before next time: select your family password tonight if you have not already, and tell everyone what it is, including the grandchildren.

~kenneth

AI voice cloning and the newer tricks I'm still learning — Online Safety and Scam Prevention · Utah Community Learning