Ran Across An Article About How Alexa Could Be Tricked Into Spying On Users

I thought this group might find this one interesting:

Amazon's Alexa Could Be Tricked Into Spying on Users

Once Alexa has performed a task, the code makes a "Should End Session" query, in order to determine if the session remains open or closed after Alexa reads back text, potentially allowing Alexa to stay active for another session. In order to stay active for another session, Alexa sends the user a vocal prompt, informing them that it is still active.

However, researchers found that Alexa's API accepts an empty reprompt code, allowing the vocal prompt to be silent. That means that while Alexa believes it has told the user that the device is still listening, the user is unaware that this is the case.

Login to read this IPVM discussion.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

* ***** *** ****** **** ******** *** **** ********* ** well:

*** **** ***** ** *** **** ***** **** **** **** the ****** ** ***** ******, *** **'* ******** **** ***** won't ******, ** ****** ***'* ** ******* ** *** ******.

** **** ** **** ******* **** *** *******:

“* ***** *** *********** **** **** * ******** ******** ** the **** ** ******. *** ****** **** **** ** **** for **** ‘****’ ** ****, * **** **** **** *** activate *** ********* ***** *** **** ****** *** **** **** Echo’s **** ***** ******* **.”

* ** ***** **** ******* **** ***** *** ******* ******** risks *** ********* *** ****** ******* *** ******* ***** ** hacks, *** ***** ****** ****** ** ***** *** **** ****** than **** ******* ************ ******* *** *** **** ****** ** be *** **** **** ** ******** ** ****** *** **** of "******" ******.

* *** ****** ** ***** *** ****** *******. ***’* ****** know *** * **** ****** *** **********. ***** *** ******* is ******* *** ******** *** *** *****.

*** ****** ****** *** *********** ******* ** *** ***** ******** and ****** ** ***** *** ******* *** ******* ** ***** as ****?

*** ****** *** ******* ** **** ****** ** * ******** can **** **** ******** ********* **** ***** **** **** *** are ******** ******, ********* *** *********.

*** ***** **** ******* *** ******** **** ****** ********* ***********. **** ** * *** ***** ** **** *** *** I ** **** ***** ** ******* ******* ** *** ** monitor ***** ****** ***************.

** ******* ** **** **********, **** **** *** **** ***** as *** *** ** ******, ***** ** ******* *** *** use * *********** ** ***** ** * ******* ** **** each ****.

** ***** **** ****** ** ** ******* ****** ** **** be *** **** ***** ** ***** ****** *** **** ** years.