Face recognition black production: a set of one hundred yuan for real-person authentication video

Contains ID card photos and videos of nodding, shaking and opening mouth. Most transactions are hidden on social platforms. Sellers claim that they can be verified by multiple APP platforms

  A black-produced vendor sold real-life facial recognition videos, asking for a set of 150 yuan.

  "A set of 100 yuan, including the front and back photos of the ID card, the photos of holding the ID card, and the video of nodding and shaking your head and mouth." On some social platforms and websites, many sellers clearly marked the price of the face recognition video, and also packaged a ticket to say that it was sold. The verification video can pass the verification process of most APP platforms.

  From March 30th to April 5th, a reporter from the Beijing News found that most of this kind of underground illegal property transactions were hidden in QQ groups and overseas websites. The names of QQ groups contained key points such as "face-to-face" and "recognition technology". Words, so as to facilitate buyers to retrieve relevant information.

  Among the black products for face verification on the APP platform, a set of 100 yuan verification video is a "high price and high quality" product, because the dynamic verification video recorded by a real person is used, the verification pass rate is high, and there is a low-cost face verification. The method is to use dynamic software to make face photos into "dynamic video", and verify with the "plug-in" software.

  "The cheap set only costs a few yuan, and if the demand is large, it can even be as low as 0.5 yuan a set." A seller said that the success rate of dynamic facial verification mainly depends on the degree of detail in the dynamic processing of photos, but real people The recorded video will definitely pass 100%.

  Regarding the purchase and sale of facial recognition information, Beijing Yunjia Law Firm lawyer Zhao Zhanzhu said that according to the Civil Code, citizens have civil rights to personal information, and illegal collection and sale of other people's information without their consent would constitute a civil tort.

The facial feature information of a person is information that can directly identify the true identity of a specific natural person. It belongs to the category of personal information. If you buy or sell personal information without the user's consent, it is suspected of illegal crimes.

  "Advancing with the Times" Black Property Trading

  When Ms. Zhang registered on Weibo for face verification, she was prompted that her ID information had been registered, but she had not downloaded and used Weibo before.

  Ms. Zhang consulted the microblog service and learned that if the ID card has been bound to another account or the number of times the ID card has been used exceeds the limit, it is because the ID card has been bound to another account.

At present, one ID number can be bound to two Weibo accounts. When the number of accounts bound to the ID number reaches the upper limit, the current ID number can no longer be used for verification.

  "My information must have been leaked." Ms. Zhang said that she usually pays more attention to the protection of personal information. In addition to going to school, applying for a bank card, applying for a phone card, staying in a hotel, and buying a bus ticket, she has used her ID card in other places. Haven't used it.

  Ms. Zhang’s experience is not unique. Many netizens have posted that they were registering on Weibo, QQ, official accounts, etc., and found that their personal identity information was stolen.

  With the increase in the number of fraudulent use of personal information, network-related feedback and complaints have also increased, followed by the upgrade of security verification of major APP platforms, using dynamic face recognition as a security verification method.

In the upgrade iteration of APP platform security verification, practitioners of this black industry chain are also taking advantage of the loopholes to "specialize" how to crack this "dilemma".

This chain of black property interests that has emerged with the development of the Internet real-name system has also been upgraded from the initial collection and sale of names and ID numbers to the collection and sale of hand-held ID card photos, facial videos and photo dynamic processing software.

  According to a black product seller who sells personal information on the dark web, the front and back photos of the ID card, the photo of the ID card and the video of nodding and shaking the head of the face, a set of 100 yuan, can be discounted for large quantities, if you buy 100 sets at a time , The price can be reduced to 10 yuan a set, "If the quantity is small, it is really not cheap, and the cost of collecting this information is also high."

  Then, the other party sent two videos of mouth opening, blinking, nodding and shaking head recorded by others, saying, "These are videos recorded by real people. It is verified that most APPs are okay, and the pass rate is higher than that of dynamic videos for photo processing."

  Most of the live verification videos come from "online part-time jobs"

  A number of black-produced sellers said that they developed apps such as borrowing and walking to make money. The information they sell comes from the information collected when users download and register these apps. “Most of these people are factory workers and some online part-timers. "

  However, these part-time online account holders do not know that they will leak their privacy when doing some APP-certified orders.

  Ms. Bai from Shanxi told the Beijing News that she started doing some online part-time jobs such as swiping orders half a year ago. Sometimes the amount of swiping orders is limited, so she will make some APP-certified orders.

  Ms. Bai said that these orders need to scan the QR code provided by the other party to download the APP and then perform real-name authentication. Most of the real-name authentication process involves uploading photos of the front and back of the ID card and performing face recognition before the registration is considered successful.

A list is about 5 yuan -15 yuan, some certification requirements are complicated and the price will be higher.

  In the part-time job order, some only need to upload the name and ID number. This is 3 yuan per order, and the price for face recognition may reach more than ten dollars.

Ms. Bai said that when some apps are performing face authentication, it is easier to pass by blinking and shaking your head a little bit, or if the face is closer.

  "I never thought that someone would collect personal information in this way, and I have never heard that someone would collect dynamic videos for facial recognition." Ms. Bai said that when she first started receiving this kind of APP registration form, she encountered an identity. I hesitated when verifying the facial information, but then I felt that everyone in the group was taking orders, and I didn't hear anyone say that there was any problem, so I started to do so.

  Data leakage caused by part-time credit card authentication should be considered as a minority.

There have been media reports that 80% of personal information data leaks were caused by internal employees.

  Many black producers also agree with this statement.

Some vendors revealed that most of the hand-held ID photos on the market today were leaked during the brutal development of microfinance platforms and companies, and some were collected from various industries. The general situation of this information transaction and use The download will not be discovered, "At that time, many people borrowed money and didn't pay it back. The platform used this information to sell it. It was expensive at first, but now it’s cheaper to resell it."

  In addition, facial information recognition and collection are now required for daily use of APP, entering and exiting stores, and there are also people who carry out information collection in the name of face recognition technology development and system testing.

  On the Internet, a reporter from the Beijing News noticed that someone posted information on recruiting information collectors. The job content was to collect ID cards and facial information in the villages, and they could give edible oil, pots and other commodities as gifts.

  The "four-piece suit" of the black production circle

  Compared with real-life video recording, the face in the photo is dynamically processed by software to form a verification video, and the cost is lower.

  On March 31, reporters from the Beijing News searched through QQ groups according to conditions, and entered keywords such as "cross face" and "recognition technology" in the search box, and many related QQ groups appeared.

Reporters randomly joined 6 QQ groups and found that the members of these groups range from more than 100 to more than 1,700, and new members join from time to time.

  In the QQ group, from time to time, some people publish information about selling WeChat accounts and selling face-changing software. At the same time, some people are consulting on how to dynamically process the characters in the photos and pass the facial recognition verification.

  In addition, after reporters from the Beijing News joined the group as they needed to purchase facial authentication technology and software, within 3 hours, a number of illegal information sellers added reporter friends to understand their needs.

  These black-produced sellers said that they sell software such as photo cutouts, dynamic processing, etc., so that the characters in the photos open their mouths, blink, shake their heads left and right, and nod up and down.

After that, use a specific mobile phone to open a "plug-in" for face recognition, "We generally use it to verify WeChat, QQ, and Momo, and other software can also verify face."

  On March 31, a merchant engaged in the trading of black goods released a message on its QQ zone that due to the upgrade of WeChat security verification, it was temporarily unable to pass the facial recognition verification, and he was studying a method.

On April 3, the merchant stated that it had overcome the new security verification and could take orders.

  In addition, these merchants also sell front and back photos of ID cards, photos of hand-held ID cards, and photos with faces. These are commonly called "four-piece suits" in the black industry circle, and the price of each set ranges from 0.5 yuan to 3 yuan.

  When asked about the source of these ID photos, merchants began to be cautious during the chat.

In the end, a reporter from the Beijing News stated that when there was a large demand for the four-piece information, a seller said that someone was responsible for collecting it and he bought it from others before selling it.

  Open "plug-in" software for face recognition

  Whether it is recording a video of a real person or dynamic processing of photos, the important tools for completing APP facial dynamic verification are mobile phones and plug-in software.

  A reporter from the Beijing News asked a black product seller and learned that a certain brand of second-hand R9 mobile phone can be purchased from a second-hand trading platform for more than 200 yuan, and then the flashing package can be implanted into the mobile phone.

  During the face recognition verification process of some APP platforms, the screen will change to three colors of red, yellow, and blue to verify the brightness of the face, but the verification can also be completed by using the relevant plug-in software.

  "The purpose of flashing a mobile phone is to obtain more permissions to operate the mobile phone." Regarding the principle of facial recognition verification after the photo is dynamically processed, two black sellers said that when the APP needs to verify the face through the camera, use your hands If the camera is blocked, the "plug-in" of the mobile phone will be activated. By modifying the relevant data and settings, the dynamic face video prepared in advance is imported into the APP to complete the authentication.

  "The pass rate of videos recorded by real people is definitely high. The photo processing depends on your talent. There is no guarantee that you will pass every verification. It depends on whether the facial dynamic video you make is meticulous. If the first verification fails, verify a few more times. Second, it may pass later.” A black product seller said that embezzling other people's information for APP account registration and verification is illegal, and the country has cracked down on it, so he only sells software and teaching, and does not directly operate it.

  According to the tips of the black product seller, the Beijing News reporter spent more than 500 yuan to buy an Android phone and a set of dynamic processing software and teaching. The black product seller included 30 sets of front and back photos of the ID card and photos of the hand-held ID card.

  In the actual experience process, according to the black product seller, using a certain brand of R9 mobile phone that has been swiped, save the processed facial dynamic video on this mobile phone, and open the APP to cover the camera with objects to make the camera in a black screen Status, you can successfully pass the security verification.

  Beijing News reporters used this method to pass face recognition on platforms such as Tantan and Zhaolian Recruitment.

  Tantan customer service staff told the Beijing News reporter that if personal identity information is found to have been stolen and authenticated, the user can only report it to the platform after discovering it. After that, the user needs to provide his identity information to the platform for review. After the review is passed, the platform will The verified account is blocked.

For Tantan platform's face recognition authentication vulnerabilities, they will report the situation upwards.

  The customer service personnel of platforms such as Zhaolian Recruitment and Momo have stated that there is currently no good response to false face recognition, and will respond to the situation later.

  Lawyer: Privately selling facial information is illegal

  There are not many cases of illegal use of personal information after being sold.

  On the Chinese Judgment Documents website, a criminal verdict on facial recognition verification showed that, starting from July 2018, the defendants Zhang, Yu and others used the personal identity information of the citizens they purchased to register for Alipay accounts for profit. And use software to make the citizen's avatar photo into a citizen's 3D avatar, so as to pass Alipay's face recognition authentication.

  In this way, the corresponding red envelope rewards provided by Alipay for inviting new Alipay users to register (including red envelopes for newcomers, red envelopes for general consumption, red envelopes for Huabei, etc.) are obtained, and each newly registered Alipay can get at least 28 yuan in income.

As of the incident, the gang has illegally collected nearly 20 million pieces of citizenship information, and successfully registered at least 547 real-name Alipay accounts that have passed facial recognition authentication using the personal identity information of other people's citizens, making a profit of 40,000 yuan.

  Zhao Zhanzhu, a lawyer at Beijing Yunjia Law Firm, said that facial feature information is information that can directly identify the true identity of a specific natural person. It belongs to the category of personal information. It is illegal or even criminal to buy or sell personal information without the user's consent.

  According to the Civil Code, citizens have civil rights to personal information, and illegal collection and sale of information from others without their consent constitutes a civil tort.

In addition, the "Criminal Law Amendment (9)" provides for the crime of infringing on citizens' personal information.

The transaction of highly sensitive personal information reaches a certain amount, and the conduct that meets the criteria for filing a case stipulated in the judicial interpretations of the judicial two highs is suspected of criminal offense.

In this process, both the buyer and the seller are suspected of violating citizens’ personal information.

  After the personal information of a natural person is illegally bought and sold by others and used for some illegal or even criminal acts, he shall not bear legal responsibility for this.

However, evidence is needed to prove that personal information was illegally obtained and misappropriated by others.

There are many criminal cases regarding personal information, and public security organs capture a large number of criminal suspects who violate citizens' personal information every year.

  Beijing News reporter Liu Mingyang