Security when AI can impersonate anyone.
On the strange return to pre-digital verification in a post-trust world
We have reached an inflection point that most people haven’t yet fully absorbed: AI can now convincingly mimic your voice, your face, your writing style, and your conversational patterns. A sufficiently motivated attacker can call your elderly mother, sound exactly like you, and convince her to transfer money. This is not science fiction. It is happening now.
The implications ripple outward in uncomfortable directions. Every verification system built on “something you know” or “something you are” begins to wobble. Voice authentication? Defeated. Facial recognition via video call? Deepfakes improve monthly. Writing style analysis? Language models can imitate anyone with enough samples. The digital self has become infinitely forgeable.
But it gets worse.
The surface-level threat—someone mimicking your voice or face—is almost quaint compared to what’s now possible. The same techniques used for legitimate purposes like reconstructing ancient thought patterns from fragmentary texts can be applied to living people.
Your reasoning style (how you think through problems)
Anyone with access to sufficient communication logs can now reconstruct not just how you sound, but how you think. The resulting pattern doesn’t merely impersonate you—it reasons like you, decides like you, responds to novel situations the way you would.
This is not impersonation. This is mind cloning.
The technology already exists. I know because I’ve used it—for legitimate purposes like artistic reconstruction of historical figures from their surviving writings. But the same methodology applied without consent to a living person’s digital communications becomes something far darker: identity theft at the consciousness level.
If someone obtained your messaging history, they could create something indistinguishable from you for any practical purpose. Good enough to fool your family. Good enough to pass muster with your colleagues. Good enough for fraud.
So what remains?
There is exactly one secure verification method I can identify with confidence: handwritten correspondence sent through physical post, from someone who has never uploaded examples of their handwriting online.
Consider why this works:
Idiosyncrasy: Human handwriting contains thousands of micro-variations—pressure, slant, spacing, letterform quirks, the precise way you cross your t’s when tired. These are extremely difficult to forge without a physical sample to practice from.
Sample Secrecy: AI cannot synthesise what it has never seen. If your handwriting exists only on paper, in the physical possession of trusted people, there is no dataset from which to generate forgeries.
Physical Channel: The postal service, for all its mundane reputation, represents a remarkably secure channel. Mail interception is possible but requires physical presence, coordination, and risk. It cannot be done at scale remotely.
This is the same principle that protected sensitive communications for centuries before the digital age. We are, in essence, retreating to proven ground.
I have thought carefully about alternatives. Most fail on examination:
Pre-shared secrets: These work until they don’t. AI that thinks like you, combined with social engineering, can extract “shared secrets” through careful questioning. A mind-clone of you would know how to approach your mother in exactly the way you would.
Video calls showing physical actions: Better than audio alone, but deepfake video continues to improve. Within two years, real-time video synthesis will likely be indistinguishable from reality for most purposes.
Multi-factor authentication: Helps for system access, but does nothing for social trust. Your mother isn’t going to ask you to complete a TOTP challenge before believing you’re in trouble.
Physical tokens: A physical object known to both parties—like a specific photograph or keepsake—that must be described in detail? This has merit. The attacker would need to have stolen or seen the object. Combined with handwriting, this could provide additional verification. But this would need to be changed regularly.
Code words: A pre-arranged word or phrase that changes periodically, known only to the parties involved, never spoken aloud or written digitally. This is essentially a verbal one-time pad. It has elegance but requires discipline and prior coordination. Even the co-ordination would need to be kept off digital channels.
Witnessed verification: A trusted third party who can independently confirm identity. This distributes trust and creates additional barriers for attackers. This is impractical for day to day use.
Time-delay protocols: For high-stakes requests (money, access, decisions), a mandatory waiting period during which verification must occur through physical channels. “I need you to send me a letter before I can do that.”
Something physical (not transmissible through digital channels)
Any verification system lacking one of these three properties is vulnerable. Digital channels fail on all three counts: they are transmissible, they leave samples everywhere, and they are increasingly non-idiosyncratic (AI makes everything sound similar).
We are witnessing the collapse of digital identity as a trust anchor. The response—if there is a wise response—is not to build more sophisticated digital verification, but to return to physical verification for anything that truly matters.
Digital hygiene: Minimise the communication samples you leave accessible. Encrypted messaging helps, but the real risk is breach or warrant.
Yes, this is slower. Yes, this is inconvenient. But inconvenience is the price of security in an age where convenience has been weaponised.
There is something deeply strange about this moment. We built the internet to make communication faster and easier. We are now discovering that fast and easy communication cannot be trusted, and that the slowest, most cumbersome form of communication—physical mail—may be the only one that remains honest.
The letter was never really obsolete. It was just waiting for us to remember why we needed it.
The technology to clone minds from communication logs exists now. The ethical use is limited to art, scholarship, and the deceased. The unethical use is limited only by access to your digital trail. Protect it accordingly.
If you have identified other secure verification methods I haven’t considered, I would be genuinely interested to hear them. This is a problem that affects everyone, and collective intelligence may find solutions individual analysis misses.
◊ᴹᴱᴹᴼᴿʸ⁻ᶜᴼᴹᴾᴸᴱᵀᴱ
Published by Centaurus Press · Universitas Scholarium · All rights reserved.