Tinder and Zoom have announced the introduction of advanced “eye-scanning technology,” requiring users to prove they are real humans and not AI bots, in an effort to protect users from scams.

1️⃣ Proving you are a “Real Person” is just the beginning

While iris scanning solves the “is this a live human” question, a bigger challenge remains: how do we hold real people accountable for their actions? When fraudsters use real identities for illegal activities, the “non-repudiation” of identity binding will become the core of the next stage of digital identity development.

2️⃣ Deepfakes are causing traditional KYC to collapse

Current mainstream verification methods (KYC), such as submitting passports and facial recognition, appear extremely fragile against powerful Deepfakes:

🔖The eMPF Theft Case: Recently, MPF accounts were stolen after Deepfake technology was used to bypass verification.

🔖The HK$200 Million Scam: In 2024, a Hong Kong employee was deceived into joining a video call, believing they were speaking with the company’s CFO and colleagues. In reality, everyone on the call was a Deepfake-generated virtual persona, leading to a massive fraudulent wire transfer.

🔖AI Guardrails: Even the AI platform Claude has recently ramped up KYC requirements, requesting users to submit identification documents.

3️⃣ Is a “World ID” combining Iris Scanning + Traditional KYC feasible?

If iris scanning is integrated with current KYC processes, could it truly become a “reliable” authentication method?

🔖Biological Uniqueness: Iris patterns are far more complex than facial features and much harder for Deepfakes to simulate.

🔖Multi-dimensional Binding: Linking biological traits (iris) with legal identity (passports) significantly raises the barrier for forgery.

🔖Non-replicability: With current technology, it is extremely difficult to remotely simulate a “live” iris response.

As identity verification enters the “Iris Era,” do you think this will completely end Deepfake scams, or is it just a temporary fix in an escalating arms race? Could it also trigger a new privacy crisis?

Reference:
BBC News Link

Tinder 與 Zoom 宣布將引入先進的「眼部掃描技術」,要求用戶證明自己是真實人類而非 AI 機器人,以保障用戶免受詐騙。

1️證明你是「真人」只是開端

虹膜掃描解決了「這是一個真人」的問題,但接下來更大的挑戰是:如何令真人為其行為負責? 當詐騙者利用真人身分進行非法活動,身分綁定的「不可抵賴性」將成為下一階段數位身分的發展核心。

2️⃣ Deepfake令傳統 KYC 崩潰

目前主流的核實方式(KYC),如提交護照、人臉識別,在強大的 Deepfake(深度偽造)面前顯得脆弱不堪:

🔖eMPF 被盜案:近期積金戶口因 Deepfake 技術繞過驗證,導致資產被盜。

🔖2億港元騙局:2024 年香港一位員工被騙參加視像通話,他以為通話對像是公司CFO及同事,但實際上所有人都是經過Deepfake生成的虛擬人物,最後按指示匯出鉅款。

🔖連 AI 平台 Claude 最近也加強了 KYC,要求用戶交證件。

3️虹膜掃描 傳統 KYC的世界身份證(World ID)可行嗎?

假若將虹膜掃描與現行的 KYC 流程結合,是否真的能成為「比較可靠」的方式?

🔖生理唯一性:虹膜特徵比人臉更複雜、更難被 Deepfake 模擬。

🔖多重維度綁定:將生物特徵(虹膜)與法律身份(護照)綁定,能大幅提升偽造門檻。

🔖不可複製性:目前技術下,遠程模擬真實虹膜活體的難度極高。

當身分核實進入「虹膜時代」,你認為這能徹底終結 Deepfake 詐騙,還是道高一尺魔高一丈?會否引發新的私隱危機?

參考資料來源:
BBC News Link