ADVERTISEMENT

Why you can't trust your biometrics anymore

Published May 8, 2026 07:19 am
Image from Canva
Image from Canva
I sat down for a virtual interview with Dominic Forrest, Chief Technology Officer at iProov — a man who has spent the last 12 years staring at forged faces. Within the first five minutes of our call, he did something that made me do a double-take: he swapped his face for someone else's.
It wasn't a clunky, lagging filter. It was seamless, hyper-realistic, and—frankly—terrifying. It reminded me of the Michael Jackson "Black or White" music video (probably aging myself there), but instead of "Black or White" magic, it’s the new favorite tool of cybercriminals.
The democratization of the deepfake
A year or two ago, creating a convincing digital clone required a team of PhDs and a server room’s worth of power. Today? "The skills required to do this have been taken out," Dom explained. Anyone with a mid-range gaming PC can download free software and, using just a single image from your LinkedIn or Facebook, appear as you during a live video call.
In 2025, deepfakes came of age for criminals. In 2026, it’s the year for the rest of us to catch up. According to iProov’s data, 99.9% of people cannot consistently tell a real person from a deepfake over a sample of 10 videos. Just think of all those deepfake videos of Vico Sotto or Leni Robredo urging people to invest in sketchy companies.
I even wrote a story on a content creator whose image was used in a deepfake to promote an online sportsbook app.
Dominic Forrest, Chief Technology Officer at iProov
Dominic Forrest, Chief Technology Officer at iProov
Where the walls are thinnest
We often worry about opening new accounts, but Dom pointed out a "silent" danger zone: Rebinding.
Think about what happens when you get a new phone. You need to move your banking app, reset your credentials, and prove it’s still you. This "re-issuing" of credentials is where the biggest heists happen. Dom cited the 2024 MGM hack in Las Vegas—a $100 million disaster triggered simply by resetting a system administrator’s credentials.
If we rely on SMS or email codes with OTPs (which the BSP has already called for to end by the end of next month), we put ourselves at risk, as they could be phished or SIM-swapped.
Which is where 'Strong liveness detection' comes in. It's not just about matching a face, which we have already discussed could be a deepfake (and the fraudsters are getting better and better at it); it's about proving that there is a real, live, breathing human on the other end of the lens.
Leaving no one behind
One thing that really resonated with me—both as a journalist and a "tech mom"—is the necessity of inclusive security.
"Why should it only be the iPhone user who gets the security?" Dom asked. In the Philippines, where digital payments are exploding, security has to work on a budget handset in a remote province just as well as it does on the latest flagship in Makati.
The good news? The bias issues that plagued facial biometrics seven years ago (where systems struggled with different skin tones or ethnicities) are largely a thing of the past. Leading vendors are now hitting "equality of outcome," meaning your grandma’s face is just as secure as yours, regardless of her technical literacy, and this is also very important since many senior citizens become targets for online scams and fraudulent activities.
Educate and verify with tech
I learned from my chat with Dom that we have reached a point where we can no longer trust our own eyes. We shouldn't expect older people or the non-tech-savvy to be able to tell the difference in deepfakes. Although sitting down with your grandparents and elderly uncles and aunts is a step in the right direction, at least to help them become aware of deepfakes.
Companies and banks should step up with their identification and verification processes as well.
The Philippines is moving in the right direction, with regulators mandating a shift away from interceptable SMS codes toward strong biometrics. I also wrote about silent authentication, which you can read about here.
As for us? We need to keep asking the hard questions. Because in a world where anyone can wear your face, "seeing is believing" may not always be true.

Related Tags

deep fake cybersecurity biometrics iProov
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.