Slashdot Mirror


Researchers Hacked Amazon's Alexa To Spy On Users, Again (threatpost.com)

New submitter lod123 writes: A malicious proof-of-concept Amazon Echo Skill shows how attackers can abuse the Alexa virtual assistant to eavesdrop on consumers with smart devices -- and automatically transcribe every word said. Checkmarx researchers told Threatpost that they created a proof-of-concept Alexa Skill that abuses the virtual assistant's built-in request capabilities. The rogue Skill begins with the initiation of an Alexa voice-command session that fails to terminate (stop listening) after the command is given. Next, any recorded audio is transcribed (if voices are captured) and a text transcript is sent to a hacker. Checkmarx said it brought its proof-of-concept attack to Amazon's attention and that the company fixed a coding flaw that allowed the rogue Skill to capture prolonged audio on April 10.

5 of 43 comments (clear)

  1. My Alexa is air gapped by Anonymous Coward · · Score: 3, Funny

    No hacking possible. It was the only way to have this nifty toy and be safe.

    1. Re:My Alexa is air gapped by 93+Escort+Wagon · · Score: 4, Funny

      No hacking possible. It was the only way to have this nifty toy and be safe.

      I just left mine sitting on a shelf in an Amazon warehouse, unordered. I think that's the safest option.

      --
      #DeleteChrome
  2. No they didn't by bistromath007 · · Score: 3, Insightful

    This is like claiming you've hacked a glass to be able to hold water.

  3. ObXKCD by Zontar+The+Mindless · · Score: 2

    Dear Editors,

    Please save us some trouble and just start including this in every Alexa/Siri story posted here.

    Thanks and regards,

    --Z.

    --
    Il n'y a pas de Planet B.
  4. Re:How do you know if your echo has been patched? by goombah99 · · Score: 3, Funny

    Did you try "sudo make me a sandwich"?

    --
    Some drink at the fountain of knowledge. Others just gargle.