Do you trust the selfie?

Issue 2/3 2023 Financial (Industry), Access Control & Identity Management, Security Services & Risk Management

The COVID pandemic saw virtual identity checks become the norm. However, not all identity-proofing methods are created equal; some of the mainstream options fall far short of best practice guidelines. By choosing the right methodology and technology, CIOs and security and risk leaders can build an authentication solution that maximises security and provides a frictionless customer experience.

In a world where data breaches occur every other day, there are thousands of terabytes of personal information in the hands of the wrong people, making identity spoofing one of the biggest security challenges today.

When it comes to on-boarding customers signing up for new bank accounts, loan finance applications, or insurance policies, having secure ways of verifying applicants’ identities is critical. The old ways of conducting identity checks, which rely on the usual name, address, and ID number, can no longer be viewed as adequate, given the amount of new account fraud that occurs via identity spoofing.

Leveraging stronger solutions that layer of risk and trust signals, such as device ID, behavioural analytics, and location signals, security can be bolstered. However, even these methods do not always offer a sufficiently robust security response.

“Solutions that rely on multiple data points like ID number, name, as well as behavioural data are more secure than solutions that only rely on a name, address and ID number, but they are still not sufficient. Creating a synthetic ID is so easy nowadays that anyone can learn how to do it online. The most secure approach to identity proofing relies on comparing a presented ID document against a government database. In cases and countries where such databases do not exist, the next best option would be what experts refer to as ‘document-centric identity proofing’, or the ID+selfie process. In this case, a picture of a photo ID document is compared with a selfie using liveness detection,” says Gerhard Oosthuizen, Chief Technology Officer at Entersekt.

Proof of life is not as hard as it once was

Oosthuizen explains that the reason why document-centric identity proofing is working so well is that it can rely on sophisticated technology to assist with the verification process and help protect against ID spoofing.

“We already have the iBeta ISO 30107-3 standard, which prescribes the recommended methods to test biometric authentication and measure the effectiveness of liveness detection. This can be achieved in various ways, such as bouncing different coloured lights onto the person when taking the photo. Based on the feedback, the software can detect if the photo is of a living person. And, while some vendors will rely on AI to run the checks, many still have call centres where checks can be escalated to human assessors, adding an additional layer of verification,” he explains.

Interest is growing fast and it’s not surprising

The identity verification market is expected to grow from $8 billion in 2021 to reach $17.7 billion in 2026, with a compound annual growth rate (CAGR) of 17.1%, and identity proofing in particular, is gaining popularity.

Oosthuizen explains that this technology is also of particular relevance to organisations that do not have access to central identity databases.

“Using a selfie with an ID document is a self-contained system. By lifting the picture in the ID document and comparing it to the live picture of the selfie, relying on a central governmental database is not required. Since many countries do not have such databases in place, it is not surprising that this technology is getting real traction from many banks that are using the capability as part of their on-boarding and recovery processes,” he says.

Oosthuizen says companies can use identity proofing as a way to take their first real step towards a passwordless future, especially if it is part of an integrated authentication solution.

“Using ID + selfie identity for ID proofing is a great fallback authentication method and an initial establishment of truth, but we understand that companies do not want to rely on this as their default authentication method, nor should they. For lower risk transactions and processes, we should be aiming towards a frictionless environment where advanced security happens in the background. Fortunately, with this built into Entersekt’s standard offering, companies can customise their risk settings as they need,” he says.

Oosthuizen is not complacent about how fast nefarious groups can adapt to new technologies. “It has become urgent for companies to employ a diverse range of risk and trust signals for functions like on-boarding, credential recovery and adding new recipients. It is a sad reality that bad actors are exceptionally good at adopting new technologies to separate us from our identities and funds, but for now, it remains difficult to socially engineer away my face,” he says.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Making a mesh for security
Information Security Security Services & Risk Management
Credential-based attacks have reached epidemic levels. For African CISOs in particular, the message is clear: identity is now the perimeter, and defences must reflect that reality with coherence and context.

Read more...
From friction to trust
Information Security Security Services & Risk Management Financial (Industry)
Historically, fraud prevention has been viewed as a trade-off between robust security and a seamless customer journey, with security often prevailing. However, this can impair business functionality or complicate the customer journey with multiple logins and authentication steps.

Read more...
Security ready to move out of the basement
AI & Data Analytics Security Services & Risk Management
Panaseer believes that in 2026, a board member at a major corporation will lose their job amid rising breaches and legal scrutiny, as organisations recognise that cyber risk is a business risk that CISOs cannot shoulder alone.

Read more...
Cyber remains top business risk, but AI fastest riser at #2
News & Events Security Services & Risk Management
The Allianz Risk Barometer 2026 ranks cybersecurity, especially ransomware attacks, as the #1 risk, while AI is the biggest riser and jumps from #10 to #2, highlighting the emerging risks for companies in almost all industry sectors.

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...
Access data for business efficiency
Continuum Identity Editor's Choice Access Control & Identity Management AI & Data Analytics Facilities & Building Management
In all organisations, access systems are paramount to securing people, data, places, goods, and resources. Today, hybrid systems deliver significant added value to users at a much lower cost.

Read more...
Beyond the fence
Technews Publishing Fang Fences & Guards SMART Security Solutions Perimeter Security, Alarms & Intruder Detection Access Control & Identity Management
In a threat landscape characterised by sophisticated syndicates, harsh environmental conditions, and unstable power grids, a static barrier is no longer a defence; it is merely a brief delay.

Read more...
Zero Trust access control
Technews Publishing SMART Security Solutions CASA Software NEC XON Editor's Choice Access Control & Identity Management Information Security
Zero Trust Architecture enforces the rule of ‘never trust, always verify’. It changes an organisation’s security posture by assuming that threats exist both inside and outside the perimeter, and it applies to information and physical security.

Read more...
OT calculator to align cyber investments with business goals
Industrial (Industry) Information Security Security Services & Risk Management
The OT Calculator has been developed specifically for industrial organisations to assess the potential costs of insufficient operational technology (OT) security. By offering detailed financial forecasts, the calculator empowers senior management to make well-informed decisions.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.