Skip to content
Security & Trust

Synacktiv used AI video to beat a website's AWS Rekognition age check

Face checks must prove where the video came from, not only that the face looks alive

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Synacktiv used AI video to beat a website's AWS Rekognition age check

AI-generated image for WebPulse. About our images

In brief
  • Synacktiv says it used generative video to bypass the age check of one website that relies on AWS Rekognition.
  • The attack needs two parts: convincing AI video, and a way to feed it in place of a real camera.
  • Leaders should ask vendors whether they verify the video's origin, and whether desktop browsers are allowed.

A camera feed is just another input

Identity checks assume one thing. The video shows a live person in front of a lens. Security firm Synacktiv has published research that tests this assumption.

The lesson here is simple. A camera feed is an input, like any other. Inputs can be replaced.

Synacktiv says it used AI to bypass the age check of one website. That site relies on AWS Rekognition. This is one site, tested by one team. It is not a finding about every provider, or about Rekognition itself.

The full write-up also compares two ways to make fake video. One uses local AI models on low-cost hardware. The other is a cloud deepfake-as-a-service.

Two problems, and AI solves only one

Synacktiv splits the attack into two parts. First, the attacker needs images that can pass liveness analysis. That is the test that a real person is present.

Second, the attacker needs a way to hand those images to the system. The researchers call this step injection.

Generative video helps with the first part. The second part is older plumbing. That matters because it shows where a defender can still act.

How the injection works

On a computer, a virtual camera is a software driver that pretends to be a webcam. Synacktiv names the OBS virtual camera and the Linux module v4l2loopback. A browser then treats the injected stream as a normal camera.

On a phone, the researchers describe a tool called Frida. It intercepts calls to the camera. The app then reads an MP4 file instead of the real sensor. Mobile emulators can also be set up with virtual cameras.

The browser has its own weak point. A script can hook getUserMedia, the function that asks for camera access. Suppose a site demands strict video quality. The hook can lower that demand so any video is accepted.

Quality can also be adjusted. Low-resolution video is quicker to generate. It also holds less detail for detectors to analyse.

Synacktiv says two FFmpeg tools gave a good balance of results and run time. They are the Lanczos method for resolution and motion interpolation for frame rate. Together they lift a 480p, 25 fps clip to 720p, 30 fps.

What defenders can do

The defences Synacktiv lists all aim to verify where a video came from. On phones, an app can ask the device's secure hardware to sign the camera data, on devices that have a secure element. A Frida or virtual-camera feed would then carry a missing or invalid signature.

Google's Play Integrity API and Apple's App Attest add another check. They help show whether the app is running on a genuine phone, not inside a virtual machine or on a rooted device. There is a trade-off. Requiring them rules out alternative mobile operating systems that lack them.

Motion data is a third check. A hand-held phone trembles slightly. If the accelerometer reports a frozen reading or a repeating pattern, that suggests injected video. Readings that do not match the footage are also a signal.

Desktops have some options too. Scripts can compare the CPU cores a browser claims with measured performance. They can also test whether camera functions still point to native code.

These checks sit inside a standard. France's ANSSI runs the PVID framework for remote identity verification providers. It requires proof-of-life tests, and it is built to meet at least the EU's eIDAS rules. eIDAS defines a "substantial" level, for cases like opening a bank account, and a "high" level, for sensitive acts like qualified signatures.

4 / 0
Operators certified at France's "substantial" level / at the "high" level
Source: Synacktiv, citing ANSSI's PVID framework (October 5, 2026)

The split matters here. Providers are certified in France at the lower level, but none at the higher one. A certificate does not tell a buyer how well a given vendor handles injected video.

The desktop gap

Synacktiv draws a clear conclusion about workflow design. Suppose a KYC process does not require a native mobile app. Then webcam checks in a browser become the "path of least resistance" for an attacker.

On desktops, virtual cameras look like ordinary devices. The web capture APIs do not yet have chain-of-trust tools as mature as those on phones. If the workflow lets users switch to a computer, the researchers expect attackers to favour it.

The researchers also make a plain assumption. Determined attackers will get past anti-injection measures. That is why liveness testing still matters. Synacktiv names three categories: passive detection, active detection and human verification. It says combining all three greatly improves a solution's effectiveness.

About €10,000
Cost of a made-to-measure latex mask for a physical attack
Source: Synacktiv (October 5, 2026)

That figure frames the shift. A physical attack needs significant resources. Injection moves the attack into software.

Why age checks are spreading

France's law of 21 May 2024 tasks the regulator ARCOM with setting age-verification rules. ARCOM can order platforms to be blocked or delisted.

Synacktiv reports a traffic drop of around 28% for Pornhub in France in the second half of 2025. The researchers tie it to delisting.

~28%
Reported drop in Pornhub traffic in France, H2 2025
Source: Synacktiv (October 5, 2026)

The drop was not total. The law targets access from French IP addresses. A VPN still lets minors in. The legal duty is clear, but the technical assurance behind it is uneven.

Questions for your team

Ask your identity vendor whether it verifies the origin of the video, not only the face in it. Ask whether desktop browser capture is allowed. If so, ask what extra checks apply there.

Ask whether phone checks use device attestation and motion data. Ask what happens to users whose devices fail attestation. Synacktiv's point about alternative operating systems shows the cost of that choice.

Finally, ask whether anyone has tested your own flow with injected video.

A liveness check can show that a face looks alive. It does not show that the camera was real. Defenders need to prove both.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Synacktiv.

Share this insight