Amazon Echo and Google Home owners spied on by apps

Amazon Echo

Amazon Echo and Google Home speakers have been compromised by apps modified to spy on users after being approved by the technology companies.

Berlin-based Security Research Labs (SRL) built the eight “smart spies”, which were promoted as a way to deliver horoscopes and generate random numbers.

Once approved, the researchers updated the Echo Skills and Home Actions to eavesdrop and steal passwords.

They then alerted the US companies, which blocked the software.

“Smart spies undermine the assumption that voice apps are only active as long as they are in dialogue with the user,” Karsten Nohl, SRL’s chief scientist, told BBC News.

Warning: Third party content may contain adverts Report

End of Youtube post by SRLabs

Creating them had been a fairly easy process that required relatively little programming experience, he said.

They were activated when a user said something like: “Alexa, turn on my horoscopes,” or: “OK Google, ask My Lucky Horoscope to give me the horoscope for Taurus.”

When the user tried to turn off the app, they heard a “Goodbye” message but the software carried on running for several more seconds rather than deactivating immediately.

If, in that time, the person said a phrase including the word “I” or other chosen terms, their speech was transcribed and sent back to SRL.

One giveaway something was not right was the smart-speaker light remained turned on, indicating it was still listening, according to Mr Nohl.

And, he suggested, this should be something smart-speaker owners kept an eye on.

A variation of the attack involved the app saying: “An important security update is available for your device. Please say, ‘Start update,’ followed by your password.”

Anything the user said after the word “Start” was then sent back to the developer.

“Users should be very suspicious when any smart speaker asks for a password, which no regular app is supposed to do,” Mr Nohl added.

David Emm, a security analyst at Kaspersky Lab, said people needed to remember some of the apps offered for Amazon Echo and Google Home devices were made by third parties.

“We all need to aware of the capabilities of these devices,” he said.

“They’re ‘smart listeners’, not just smart speakers. Their capabilities extend to apps that we use with them.”

Google said it had removed SRL’s Actions.

“We are putting additional mechanisms in place to prevent these issues from occurring in the future,” the company added.

Amazon said: “Customer trust is important to us and we conduct security reviews as part of the skill certification process.

“We quickly blocked the Skill in question and put mitigations in place to prevent and detect this type of Skill behaviour and reject or take them down when identified.”

source: https://www.bbc.com

Also read: Top 8 Amazon Echo Tricks That You Probably Didn’t Know About

Paraphrase tool
Technology

Paraphrasetool.ai: an In-Depth Analysis of Its Features & Benefits

Writers are always looking for top-of-the-line tools that can help them boost creativity and work efficiency. Paraphrasetool.ai is one such tool that has gained immense popularity these days. Powered by artificial intelligence, this online paraphrase tool paraphrases content efficiently. Is it worth the hype? In today’s comprehensive review article, we will explore its key features […]

Read More
Using AI as online chatting assistants when dating:
Computer Home Software Technology

Using AI as online chatting assistants when dating: thingsto know

Singles have been using dating sites for some time, with upwards of one in three of today’s successful relationships being initiated after digital contact. Signing up to a website or app to flirt and hook up with prospective partners is now so popular, that this activity will eventually surpass the offline version. Digital matchmaking is […]

Read More
chat GPT photo
Technology

Why ChatGPT Matters: Advantages and Honours of AI Chatbots?

ChatGPT appears to be another chatbot, but that’s not the case. While other Chatbots fail to respond to you when asked questions in a contextual manner, ChatGPT can surprise you. This machine learning system based on AI can easily converse with human beings with a certain ease.  In this article, we will try to tell […]

Read More