dolphinattack
Could hackers trick voice assistants into committing fraud? Researchers say yes.
Voice assistant technology is supposed to make our lives easier, but security experts say it comes with some uniquely invasive risks. Since the beginning of the year, multiple Nest security camera users have reported instances of strangers hacking into and issuing voice commands to Alexa, falsely announcing a North Korean missile attack, and targeting one family by speaking directly to their child, turning up their home thermostat to 90 degrees, and shouting insults. These incidents are alarming, but the potential for silent compromises of voice assistants could be even more damaging. Nest owner Google -- which recently integrated Google Assistant support into Nest control hubs -- has blamed weak user passwords and a lack of two-factor authentication for the attacks. But even voice assistants with strong security may be vulnerable to stealthier forms of hacking.
Amazon 'human error' let Alexa user to eavesdrop on 1,700 private audio files from another person
Researchers at China's Zhejiang University published a study last year that showed many of the most popular smart speakers and smartphones, equipped with digital assistants, could be easily tricked into being controlled by hackers. They used a technique called DolphinAttack, which translates voice commands into ultrasonic frequencies that are too high for the human ear to recognize. While the commands may go unheard by humans, the low-frequency audio commands can be picked up, recovered and then interpreted by speech recognition systems. The team were able to launch attacks, which are higher than 20kHz, by using less than ยฃ2.20 ($3) of equipment which was attached to a Galaxy S6 Edge. They used an external battery, an amplifier, and an ultrasonic transducer.
Security flaw in Amazon Echo devices could let hackers spy on you
A group of security researchers have exposed a flaw in the Amazon Echo that allows hackers to secretly listen to unsuspecting users' conversations - but only if they're savvy enough to be able to carry out the attack. In a presentation dubbed'Breaking Smart Speakers: We are Listening to You,' researchers from Chinese tech giant Tencent explained how they were able to build a doctored Echo speaker and use that to gain access to other Echo devices. The researchers have since notified Amazon of the vulnerability, and the company issued a patch in July. Hackers from Tencent's Blade security research team exposed a flaw in Amazon's Echo smart speaker that would allow someone to secretly spy on others and play random sounds'After several months of research, we successfully break the Amazon Echo by using multiple vulnerabilities in the Amazon Echo system, and [achieve] remote eavesdropping,' the researchers said in the presentation, which was given at the DEF CON security conference, according to Wired. 'When the attack [succeeds], we can control Amazon Echo for eavesdropping and send the voice data through network to the attacker.'
Woman says her Echo device recorded and sent a private conversation
Be careful of what you say around your Echo devices. A Portland woman was shocked to discover that Echo recorded and sent audio of a private conversation to one of their contacts without their knowledge, according to KIRO 7. The woman, who is only identified as Danielle, said her family had installed the popular voice-activated speakers throughout their home. It wasn't until a random contact called to let them know that he'd received a call from Alexa that they realized their device had mistakenly transmitted a private conversation. The contact, who was one of her husband's work employees, told the woman to'unplug your Alexa devices right now. 'We unplugged all of them and he proceeded to tell us that he had received audio files of recordings from inside our house,' the woman said.
Ultrasonic Attacks Can Trigger Alexa & Siri With Hidden Commands, Raise Serious Security Risks
Over the last two years, academic researchers have identified various methods that they can transmit hidden commands that are undetectable by the human ear to Apple's Siri, Amazon's Alexa, and Google's Assistant. According to a new report from The New York Times, scientific researchers have been able "to secretly activate the artificial intelligence systems on smartphones and smart speakers, making them dial phone numbers or open websites." This could, perhaps, allow cybercriminals to unlock smart-home doors, control a Tesla car via the App, access users' online bank accounts, load malicious browser-based cryptocurrency mining websites, and or access all sort of personal information. In 2017, Statista projected around 223 million people in the U.S. would be using a smartphone device, which accounts for roughly 84 percent of all mobile users. Of these 223 million smartphones users, around 108 million Americans are using the Android Operating System, and some 90 million are using Apple's iOS (operating system).
Voice assistants vulnerable to silent voice control attack
Voice assistants, including Apple's Siri and Amazon's Alexa, can be controlled by hackers using inaudible voice commands, researchers at Zhejiang University in China have found. This can be done using a technique that translates voice commands into ultrasonic frequencies that are too high for the human ear to recognise. The technique, named DolphinAttack, could be used to download a virus, send fake messages and even add fake events to a calendar. It could also give hackers access to outgoing video or phone calls, allowing them to spy on their victims. The fault is due to vulnerabilities in the software and hardware of speech recognition systems.
DolphinAttack: Researchers Send Undetectable Commands To Hijack Alexa, Siri
Hackers could use inaudible, undetectable commands transmitted via ultrasound in order to compromise speech recognition systems and popular voice assistants, security researchers in China discovered. The technique, dubbed "DolphinAttack" by researchers from China's Zhejiang University, could be carried out by an attacker to hijack voice-controlled assistants like Apple's Siri, Amazon's Alexa or Google's Assistant. DolphinAttack could be carried out by using ultrasonic frequencies that reach pitches above 20,000hz--well beyond the range humans can hear, but still audible to the microphone in a smart device like the Google Home or Amazon Echo and Dot. Newsweek is hosting a Structure Security Event in San Francisco, Sept. 26-27. By transmitting commands at those undetectable frequencies, the researchers were able to direct a number of devices with built-in microphones and speech recognition to carry out actions with potentially harmful results.