Are You Being Catfished by Your Customers?

Exploring your options for online identity verification.
If you’ve seen Catfish: The TV Show, you know that people are not always whom they claim to be.
Catfishing refers to a scam where someone, the ‘catfish,’ creates a fictitious online identity often using someone else’s pictures and false biographical information to pretend to be someone other than themselves. Online dating websites and cell phone dating apps are fertile hunting grounds for catfish.
Catfishing involves significant deception – it’s not just someone fudging his or her height and weight in a Match.com profile and using a three-year-old photo. A catfish will be far more deceptive. Often, he or she will use someone else’s photos; grab personal details such as work, educational history, and personal histories off of the Internet; and invent an entirely fictitious life for his or her fictitious identity.
Catfishing comes as no surprise to companies that do business online as most have had to contend with some flavor of online fraud, credit card fraud, and phishing/imposter scams. So, how do modern enterprises actually verify that the people creating online accounts are who they say they are — short of sending people to their home to verify their legitimate identities?
There’s a variety of methods in practice, each with their pros and cons, that can help identity proof your customers. To better understand the pros and cons of each type of identity verification, we put together a handy table. Check it out here.
Digital Trust Throughout the Customer Journey
How to Leverage the Jumio KYX Platform from Onboarding to Ongoing Monitoring
Knowledge-Based Authentication (KBA)
KBA verifies customers by asking them to answer specific security questions in order to provide accurate authorization for online or digital activities. We’re all familiar with these questions and often have to struggle to remember the right answers. The bad news is that it might be easier for the fraudsters to get a hold of those supposedly secret questions. Thanks to global data breaches, a lot of the data that you thought was private is now common knowledge and available for pennies on the dark web. And in some cases, it’s even easier than that. Unfortunately, many KBA questions are based on information that criminals can easily find on social media sites or through other sources of publicly available information that they can then use to pass these security tests and access consumers’ accounts.
Two-Factor Authentication
Two-factor authentication is an extra layer of security that requires not only a password and username, but also something that that the user has on them (i.e. a piece of information only they should know or have immediately on hand, such as a physical token or a numeric code delivered via text message). Nearly all major web services now provide some form of two-factor authentication, but they vary greatly in how well they protect accounts.
Unfortunately, dedicated hackers have little problem bypassing the weaker implementations, either by intercepting codes or exploiting account-recovery systems. Criminals targeting Bitcoin services were finding ways around the extra security, either by intercepting software tokens or more elaborate account-recovery schemes. In some cases, attackers went after phone carrier accounts directly, setting up last-minute call-forwarding arrangements to intercept codes in transit. Drawn by the possibility of thousand-dollar payouts, criminals were willing to go further than the average hacker.
Credit Bureau-Based Solutions
Many online identity verification systems call out to one of the big three credit bureaus, Experian, Equifax, and TransUnion, who then search for an identity match within their vast repositories of consumer credit data.
The good news is that these sources are often authoritative databases that provide a wealth of information based on first and last name, address, and social security number. But, the biggest downfall with credit-bureau based solutions is that they do not actually verify that the person providing the information is the actual person behind the transaction. Plus, people with thin credit files, usually young people, recent immigrants, or people who for some reason have very rarely used mainstream financial services, often cannot be matched.
Database Solutions
These solutions leverage online, social media, and offline data (and sometimes behavioral patterns) to detect if an online ID is authentic, a fraudster or a bot. Unfortunately, these solutions can be spoofed because of the ease of creating fake online identities (e.g., synthetic identity fraud) and bogus social profiles. And like credit bureau-based solutions, their biggest weakness is not being able to definitively verify that the person providing the information is the actual person behind the transaction
Online Identity Verification
New online identity verification solutions often leverage a mix of artificial intelligence, computer vision, biometrics and verification experts to determine if a government-issued ID is authentic and belongs to the user. Some solutions, like Jumio’s Trusted Identity as a Service, also require the user to take a selfie to ensure that the person holding the ID the same person shown in the ID photo. These solutions have proved more reliable in ensuring that the person behind an online transaction is the same person behind the driver’s license (or passport) and the selfie.
In fact, banks have reported that when such biometric authentication is used, customers are much more inclined to go through with their purchase. The abandonment rates can drop by up to 70% compared to other methods like two factor authentication which reflects the much improved user experience.
Clearly, you need to maintain a healthy level of skepticism about the identities of your customers. But, at the same time, you need to make sure that your legit customers can still sail through the onboarding or account set-up process with ease and as little friction as possible.
Increasingly, today’s enterprises are turning to online identity verification to better detect bad actors and increase conversion rates by leveraging smart technology and better processes that lead to much higher levels of assurance.
To learn more about the characteristics of an enterprise-class identity verification solution, I encourage you to check out our Buyer’s Guide for Online Identity Verification.
Новая форма верификации Jumio
Зарегистрируйте новую учётную запись в нашем сообществе. Это очень просто!
Войти
Уже есть аккаунт? Войти в систему.
Форум Cam-Modeling – популярная, живая площадка, объединяющая тысячи людей, связанных с Вебкам индустрией.
Интересуетесь работой в WebCam? Здесь вы получите ответы на любые вопросы, советы и консультации от опытных моделей, помощь в обучении, выборе оборудования, настройке технической базы, оформлении рабочего пространства для максимально продуктивной работы и стабильно-высокого заработка уже на старте карьеры.
Вас ждёт адекватное общение без грязи и негатива, дружелюбная администрация и уютная, домашняя атмосфера. Присоединяйтесь. Регистрация бесплатна и займёт не более 1-й минуты. Вам откроются скрытые разделы форума с действительно ценной информацией, возможность трудоустройства от ведущих студий. Вы сможете бесплатно получать реальную помощь от профессионалов бизнеса и полноценно пользоваться уникальными сервисами компании WCB Media Group.
Copyright © 2021 Cam-modeling. All right reserved! Powered by Invision Community
Jumio верификация как пройти
This is the default behavior for a variant of the ID verification ( Passfort collects documents) check with Jumio Netverify as the data provider.
You upload the individual’s document to Passfort . Passfort submits the document to Jumio Netverify who checks for signs of forgery and extracts the customer’s name, date of birth, document number and, where possible, nationality from the document.
You can upload these documents for the Verify identity task:
You can select Unknown if the document type is not known, Jumio Netverify will perform a check to determine the type of documentation provided.
The document must be no larger than 15 MB and in either JPG or PNG file types.
Jumio Netverify performs image quality checks and the following security checks on documents:
Passfort cross-references the details recorded in the individual’s profile (name, date of birth, and, if available, nationality) with the extracted data provided by Jumio Netverify .
An image of the document is displayed in the check results.
The check passes when all three criteria are met:
The document details obtained from Jumio Netverify match the details in the profile.
Jumio Netverify confirms the document is authentic by confirming the status of the check is Clear .
Jumio Netverify confirms that any additional checks have passed.
If the individual’s details do not match Jumio Netverify ‘s data, the check fails.
Because cross-referencing the individual’s details is an action performed in Passfort and not in Jumio Netverify , it’s possible for the check to pass in Jumio Netverify but fail in Passfort .
If the individual’s profile doesn’t have data for the required fields, an error is displayed.
This check variant is supported for all countries. To get step-by-step instructions for running this check, see Verify a document.
Configuration options
The following configuration option is available:
API region : Choose the API region you want to use. Contact Jumio Netverify about setting up a direct agreement.
What we’ll need
Let us know that you’d like to add a variant of the ID verification ( Passfort collects documents) and your Jumio Netverify API credentials. We’ll set it up for you.
Testing your configuration
Once the check variant is configured, follow these steps in your demo environment to test whether it’s working as expected.
To get a PASSED result, check that the ID is authentic and the document details in the demo environment match profile details.
Create an individual profile with these details:
First name: Alex
Date of birth: 01 January 2000
Expected result: DOCUMENT_ALL_PASS
To get a FAILED result, use the example where the DOB entered is different from the details in the demo environment.
Create an individual profile with these details:
First name: Ashley
Date of birth: 30 June 1980
Expected result: DOCUMENT_DOB_FIELD_DIFFERENT
Profile fields
These are the profile details matched with the document details extracted by Jumio Netverify :
Name
Description
The individual’s first and, if applicable, middle names.
The individual’s last name.
The individual’s date of birth.
The expiry date of the documentation.
The country that issued the documentation.
The documentation’s unique number, i.e. a passport number.
ID verification (service collects documents)
How it works
This is the default behavior for a variant of the ID verification (service collects documents) check with Jumio Netverify as the data provider.
The individual submits their documents to Jumio Netverify who checks for signs of forgery and extracts the individual’s name, date of birth, and, where possible, address history from the documents.
Passfort cross-references the extracted data provided by Jumio Netverify with the details recorded in the individual’s profile, such as name and, where possible, date of birth and gender. If the check was run with PROOF_OF_ADDRESS as the document category, the address is also cross-referenced.
Passfort displays an image of the documents in the check results.
The check passes when all three criteria are met:
The document details obtained from Jumio Netverify match the details in the profile.
Passfort performs MRZ validation as part of the check. On the identity page of your passport, the MRZ is the machine readable zone that cameras and software can quickly read. It contains two rows of 44 characters each. The characters used are A-Z and 0-9, demarcated with < separators. We extract the following fields from the MRZ:
When the MRZ has names with single separators only, the name components on the MRZ will be compared to the full name, given names and surname combined, on the Passfort profile.
Additionally, we mark the MRZ itself as invalid if any of the checksums fail or none of the fields listed here are found. This validation is enabled by default for the specific providers that return the MRZ details.
Jumio Netverify confirms the documents are authentic.
Jumio Netverify confirms that any additional checks have passed, for example, police checks or selfie checks.
If the individual’s details do not match the data in Jumio Netverify ’s sources, the check fails.
Because cross-referencing the individual’s details is an action performed in Passfort and not in Jumio Netverify , it’s possible for the check to pass in Jumio Netverify but fail in Passfort .
If the individual’s profile doesn’t have data for the required fields, an error is displayed.
This check variant is supported for all countries.
For more information about how Jumio Netverify handles this check, see Jumio Netverify ’s documentation.
Configuration options
You can choose from the following configuration options:
Check the individual’s nationality against the one extracted from the document : When this option is selected, Passfort always cross-references the country of nationality recorded in the individual’s profile against the country of nationality that Jumio Netverify extracted from the document. If the country of nationality does not match, the check fails. If the profile does not have a country of nationality, an error is displayed.
Require full date of birth (year, month and day) to run the check : When this option is selected, the full date of birth must be provided in the profile to run the check. When deselected, a partial date of birth, that is year and month or just year, can be used.
What we’ll need
Let us know that you’d like to add a variant of the ID verification (service collects documents) check with Jumio Netverify and which configuration options you’d like to use. We’ll set it up for you.
We’ll also need to know:
Your Jumio Netverify API token and secret: For more information about getting your API token and secret from the Customer Portal, see Jumio Netverify ‘s Implementation Guide.
Your user agent: This is a way to identify that Passfort is making the request. We suggest using » Passfort » as your user agent, but it can be anything you want.
Your data center location: Whether your Jumio Netverify data center is inside or outside the European Union.
Testing your configuration
Once the check variant is configured, follow these steps in your demo environment to test whether it’s working as expected.
Does the check pass when the ID is authentic and the extracted document details obtained from Jumio Netverify match the details in the profile?
To run this test, first create an individual profile with an address.
You also can create a profile via the portal. To get the profile ID, used to run the check in the next step, view the profile in the portal and copy the string of letters and numbers displayed after /onboarding/ in the URL.
Next, run the check variant by making the following request to the following endpoint.
Request endpoint:
Request body:
Replace the ID in task IDs with the actual task ID for your profile.
Response:
The check is working as expected if:
The preceding response is returned.
The check has passed. In the portal, the check is marked Passed .
This image is displayed in the portal as the image of the ID in the check results:

Does the check fail when the ID is not authentic?
You can create a profile via the portal. To get the profile ID, used to run the check in the next step, view the profile in the portal and copy the string of letters and numbers displayed after /onboarding/ in the URL.
Next, run the check by making a request to the following endpoint.
Request endpoint:
Request body:
Response:
The check is working as expected if:
This preceding response is returned.
The check has failed (when you view the check in the portal, the check is marked Failed and the error message is, «Your check provider failed this document check.»
This Sample Filing image is displayed in the portal as the image of the ID in the check results:

Profile fields
These are the profile details matched with the document details extracted by Jumio Netverify :
Name
Description
The individual’s first and, if applicable, middle names.
The individual’s last name.
The individual’s date of birth.
Required when the check was run with PROOF_OF_ADDRESS as the document category; not used when the check was run with PROOF_OF_IDENTITY as the document category
The individual’s address history.
If you’re running the check via the API, the ID verification check also uses the following keys:
Key name
Value
Description
The provider that the results are retrieved from. In this case, the provider is Jumio.
Sample value: 6bba3592-d9de-1ee5-8e97-ba8d8d13c558
The reference ID the data provider is using for the document. In this case it’s the scanReference provided by Jumio.
To learn how to run this check via the API, see Run a Document fetch check (API).
Jumio launches “selfie” ID verification technology
Jumio Authentication works by capturing hundreds of images of people when they take a selfie video to verify themselves during sensitive online transactions or when unlocking accounts and doors, as it creates a 3D identity map that ensures identities cannot be spoofed.
What does Jumio expect to achieve?
The technology will offer a new dimension to existing biometric authentication, by recognising a person’s detailed and unique human traits such as their face and voice. In that way, it enables more secure verification.
The company hopes it will eventually replace less secure verification processes such as passwords and two-step authentication for its clients, which, as well as Airbnb, include the airline easyJet and challenger bank Monzo.
Jumio president Robert Prigge told Compelo: “Selfies are now our passports and increasingly over the next few years, biometrics will be the future. In the past, companies have checked who we are by asking questions about our background or two-factor authentication.
“All those systems are so easy to spoof that I’m convinced it’s really all about biometrics – our faces and voice will be how we unlock things in the future. With technology like ours, you’re just going to need to take a video selfie to unlock a rental car, get into your hotel room if you’ve lost the key, open a new bank account and make a big transaction,” he added.
What is the purpose of the Jumio ID verification technology?
Jumio claims to be the world’s largest AI-powered provider of identity service technology, with more than 2,000 staff and offices worldwide.
Since its inception, Jumio has enabled both identities and documents to be verified instantly using its AI technology over 150 million times.
Mr Prigge said that offers more enhanced security than previous methods, such as knowledge-based or personal questions, as these can still be picked up by online fraudsters, credential phishing scams and large-scale data breaches among others.
Jumio realised fraudsters were quickly spotting loopholes to bypass online identify verification software by tricking it with so-called “spoofing attacks”. It can be done by simply using a photograph, video or mask of the authorised person’s face.
According to Javelin Strategy, identity theft is on the rise, with 16.7 million victims recorded in the US in 2017, costing nearly $17bn in data losses. Meanwhile, UK fraud prevention service Cifas said cases in Britain rose by 125 per cent in ten years to 175,000 in 2017.
Prigge said: “Identity fraud is absolutely rampant and increasing as a problem. As companies move online, there’s been almost no way of dealing with it remotely so they’re reacting to it now and adapting to new ways of verifying identities.”
How does Jumio Authentication work?
Jumio Authentication is integrated with anti-spoofing technology made by FaceTec, which begins during the enrolment process when a user takes a photograph of their government-issued ID, such as a driver’s licence, passport or ID card.
They are then asked to take a video selfie, which is instantly analysed using AI to determine they are who they claim to be and not a fraud.
Later, when the user wants to log into their account or whenever a sensitive transaction occurs, the facial recognition technology enables the user to take another video selfie, where a new 3D face map is established. That is then compared to the original face map, and this verifies the user and unlocks the account in a matter of seconds.
Entitled “ZoOm 3D Face Login with TrueLiveness Detection”, it claims to be the only software of its kind recognised with level one and two security certificates issued by software testing company iBeta and the US’ National Institute of Standards and Technology (NIST).
Mr Prigge said: “We’re tying your biometrics to your identity so we know who you are. When you’re taking a selfie, instead of one image, it’s taking hundreds if not thousands of them.
“This creates a 3D map and shows whether it’s a mask or if you’re pretending to be someone else. The real power of it is that, because we can map the video selfie, if you lose your phone, all you need to do is take another video selfie and the technology will identify it as you again, rather than someone who might have stolen your phone.
“Trust is the killer problem that companies need to solve when they go online and we think this is the only way,” he added.
What does the future hold for Jumio and biometrics?
According to research group Gartner, over half of the world’s large companies will replace their existing authentication platforms with biometrics by 2023, and there will be over 2.6 billion biometric payment users in banks by the same year.
In June last year, consultancy company McKinsey predicted the identity verification-as-a-service market would grow from $10bn (£7.8m) to almost $20bn (£15.6m) by 2022.
Jumio CEO Stephen Stuut added: “As more of our important interactions move online, establishing trust digitally has become critical. Jumio is pioneering selfie-based authentication to allow businesses to leverage biometric user data captured during enrolment and re-verify that data in the future.
“With our new selfie-based authentication, users are not required to repeat the identity proofing process again. They just take a quick selfie and as the digital chain of trust grows, so does the security level,” he added.