Subscriber Discussion

Ran Across An Article About How Alexa Could Be Tricked Into Spying On Users

Avatar
Jon Jones
Apr 30, 2018

I thought this group might find this one interesting:

Amazon's Alexa Could Be Tricked Into Spying on Users

Once Alexa has performed a task, the code makes a "Should End Session" query, in order to determine if the session remains open or closed after Alexa reads back text, potentially allowing Alexa to stay active for another session. In order to stay active for another session, Alexa sends the user a vocal prompt, informing them that it is still active.

However, researchers found that Alexa's API accepts an empty reprompt code, allowing the vocal prompt to be silent. That means that while Alexa believes it has told the user that the device is still listening, the user is unaware that this is the case.

U
Undisclosed #1
Apr 30, 2018

I think you should have included the next paragraph as well:

The blue light on the Echo could give away that the device is still active, but it's possible that users won't notice, or simply won't be looking at the device.

as well as this comment from the article:

“I would not necessarily call this a security loophole on the part of Amazon. The bottom line here is that for this ‘hack’ to work, a user must load and activate the malicious skill and then ignore the fact that Echo’s blue light remains on.”

I do agree that devices like Alexa can present security risks and implement new attack vectors for various kinds of hacks, the Alexa device itself is still far more secure than many Chinese surveillance cameras and far less likely to be the item that is breached to create any kind of "spying" device.

 

Avatar
Jon Jones
May 01, 2018

I was trying to share the entire article.  Don’t really know how I only shared two paragraphs.  Guess the problem is between the keyboard and the chair.

(1)
U
Undisclosed #2
Apr 30, 2018

Has anyone tested any frequencies outside of the human spectrum and verify if Alexa can monitor and respond to those as well?

The rhythm and cadence of your typing on a keyboard can give your personal signature away along with what you are actually typing, character for character.

One sight that records and monitors your typing signature is typeracer. This is a fun place to hang out but I am sure there is metrics running on how to monitor human output characteristics.

In regards to your smartphone, know that you must smile as you are on camera, audio is enabled and you use a fingerprint to click on a website or send each text.

If Alexa gets hacked by an outside source it will be the holy grail of hacks within the last 20 years.

New discussion

Ask questions and get answers to your physical security questions from IPVM team members and fellow subscribers.

Newest discussions