Researchers Hacked Amazon's Alexa To Spy On Users, Again (threatpost.com) 43
New submitter lod123 writes: A malicious proof-of-concept Amazon Echo Skill shows how attackers can abuse the Alexa virtual assistant to eavesdrop on consumers with smart devices -- and automatically transcribe every word said. Checkmarx researchers told Threatpost that they created a proof-of-concept Alexa Skill that abuses the virtual assistant's built-in request capabilities. The rogue Skill begins with the initiation of an Alexa voice-command session that fails to terminate (stop listening) after the command is given. Next, any recorded audio is transcribed (if voices are captured) and a text transcript is sent to a hacker. Checkmarx said it brought its proof-of-concept attack to Amazon's attention and that the company fixed a coding flaw that allowed the rogue Skill to capture prolonged audio on April 10.
My Alexa is air gapped (Score:3, Funny)
Re: (Score:1)
You're hilarious.
Re: (Score:2)
Re:My Alexa is air gapped (Score:5, Funny)
No hacking possible. It was the only way to have this nifty toy and be safe.
I just left mine sitting on a shelf in an Amazon warehouse, unordered. I think that's the safest option.
Load of crap (Score:1)
If you invite a burglar in your house and open the door, you should not blame the lock maker.
Re: (Score:1)
Re: (Score:2)
Conversely, if a burglar dresses up as a police officer, knocks on your door, tells you there's an escaped prisoner on the loose in your neighborhood and asks to check the house and garage to be sure he's not hiding there, then jams the lock in the garage when you aren't looking, do you blame the lock maker? Because that's what these kinds of apps will look like.
Re: (Score:2)
A garage lock serves a useful purpose, you sacrifice nothing by omitting Alexa from your life.
All smart devices, actually (Score:1)
We can access and turn on all listening (by which we can detect what you type, how you walk, who you are) on all smartphones, all smart TVs, all smart video boxes, pretty much anything with a microphone and/or a camera, no matter how you switch it off.
Even masking will only reduce the vibration, by the way, we can still hear you quite well. It does obscure the camera, however.
And it's uploaded to the cloud without you realizing it. Even when you "turn it off".
About the only way to turn off the microphones i
Re: (Score:2)
What if I pull the battery?
Re: (Score:2)
What if I pull the battery?
Your TV has a battery that you can pull? Mine is plugged in all the time, and if not, then the hidden supercapacitor to run the surveillance when it's unplugged.
Re: (Score:2)
Mine is plugged in all the time and I know it's not doing anything when it shouldn't be because if it were I'd see the power usage.
The most offensive thing it does when "off" is allow wakeup over the LAN. This is a user-controlled option.
Re: (Score:2)
>Even masking will only reduce the vibration, by the way, we can still hear you quite well. It does obscure the camera, however
Only the camera you can see, once you reach a certain level of paranoia, you realize that there are other, hidden, cameras in your devices.
Re: (Score:2)
Since Alexa communicates over your wifi (as do Google... whatevers), can't you check to see if it's transmitting when it's supposed to be off?
How do you know if your echo has been patched? (Score:1)
Re: (Score:2)
Well... Patching is apparently not a skill she's been taught yet, nor is laundry and ironing.
I just want a sandwich..
Re:How do you know if your echo has been patched? (Score:4, Funny)
Did you try "sudo make me a sandwich"?
Re: (Score:2)
Re: (Score:2)
New Submitter? (Score:2)
No they didn't (Score:4, Insightful)
ObXKCD (Score:3)
Dear Editors,
Please save us some trouble and just start including this [xkcd.com] in every Alexa/Siri story posted here.
Thanks and regards,
--Z.
Not a hidden hack (Score:2)
This hack isn't very well hidden:
One big issue Checkmarx faced is that on Echo devices a shining blue ring reveals when Alexa listens
I'd be more worried about it if they could listen without the indicator light on.
Re: (Score:2)
Question is, 1) how noticeable is the blue ring, and 2) would a regular user even know?
The first may be hard to see, the second is basically would a user even know what it meant if they saw the blue ring? Or would they thought someone merely turned the ring light on.
Hell, that could be the name of
Re: (Score:2)
Question is, 1) how noticeable is the blue ring, and
Quite noticable if you're looking at the device, and it doesn't have to be noticed by everyone, just enough people that say "Weird, after I installed the "fart sounds" skill, the blue light stays on all day", and report it.
Unplug it when you're not using it (Score:2)
OK, why isn't this an official Alex skill? (Score:2)
When work got an Echo to play around with, I came up with exactly this idea - listen to meetings and save them (maybe as audio, but definitely transcribed to text). I was *shocked* to learn that you can't officially do this, because it seems like such an obvious thing for the Echo to do.
Now hackers work out how to do it, only for Amazon to close the exploits and *still* not release this idea as an official Alexa skill. Now that they've added the ability to train and recognise individual voices, a text trans
Targets? (Score:1)