The New Security Requirements for Real-Time Video Infrastructure
Blog post from Stream
Deepfakes undermine the assumption that a familiar face on an encrypted video call proves a participant’s identity, as illustrated by the 2024 Arup fraud in which an employee transferred US$25.6 million after interacting with AI-generated impersonations of colleagues. Video-call security has distinct layers—DTLS transport encryption, end-to-end media encryption using SFrame, account authentication and authorization through tokens and roles, and human verification—but only the final layer can determine whether the person on camera is real or is the specific person claimed. Transport encryption protects data in transit but generally allows SFU media servers to access plaintext, while SFrame can prevent server access to media at the cost of features such as cloud recording, transcription, captions, and AI tools; Stream currently provides DTLS 1.3 and plans native SFrame-based E2EE for its React SDK. Account controls, including short-lived server-issued tokens and restrictive roles, reduce unauthorized access but cannot detect a deepfake operated through valid credentials. In response to escalating AI-enabled fraud, Zoom and Microsoft introduced mainstream verification approaches in 2026, with World ID focused on proving that a unique human is present and Entra Verified ID Face Check focused on confirming that a named individual matches an ID. Applications handling high-stakes actions such as payments, approvals, or account recovery should add fresh identity or liveness checks, out-of-band confirmation, visible verification status, and audit records, while recognizing that reliably binding verification to the actual live video stream remains an emerging capability.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Real-time | 7 | 4,432 | 1,050 | 222 | -31% |
| Platform Engineering | 2 | 1,191 | 259 | 79 | -17% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.