Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

TheBlackAdder

(28,209 posts)
Mon Apr 30, 2018, 04:25 PM Apr 2018

Amazon Echo Flaw Allowed For Silent Eavesdropping Of Users' Conversations

.

From the, "Gee, I didn't see this coming" files:

Alexa Is Always Listening

Normally, the Echo has an “always-on” listening capability, which in theory is supposed to only be fully activated when it hears the word “Alexa.” Once a user says Alexa, the device will start recording what the user says and analyze that audio information. After it provides the information the user requested, then its listening capabilities should go back to stand-by and it should stop recording users’ voices.

However, a flaw uncovered by Checkmarx researchers can allow a malicious party to record everything indefinitely after the user has activated a malicious app (or “skill”). Exploiting this bug still required the researchers to ensure the Alexa recording session would stay alive after the user received a silent response from the device. They also had to ensure that the transcribing of the recorded voice was accurate, in order for the data to be useful to a malicious party.

Mitigations

The Checkmarx researchers disclosed the flaw to Amazon and said that they worked closely with the company’s team to implement some solutions against this type of attack. For starters, Amazon will review apps under a stricter criteria, to find the "eavesdropping" skills. The company will also change Echo's code to take appropriate actions when certain skills send empty-reprompts or when the sessions take longer than usual.

As more people buy devices such as the Echo, Google Home, or other similar always-listening devices, they’ll likely be at an increased risk of eavesdropping, as similar flaws are more sought-out by malicious parties. We also know that the FBI has started becoming quite interested in using Amazon’s Echo to surveil suspects, and this interest will likely only grow in the future.


https://www.tomshardware.com/news/amazon-echo-silent-eavesdropping-users,36959.html


Kind of makes you wonder if these "flaws" aren't just undocumented value-added features, until exposed.

.
10 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Amazon Echo Flaw Allowed For Silent Eavesdropping Of Users' Conversations (Original Post) TheBlackAdder Apr 2018 OP
A flaw. That's it. That's the ticket. Sneederbunk Apr 2018 #1
"flaw" dawg Apr 2018 #2
yep, like onethatcares Apr 2018 #5
My son won't talk in the room where Alexa is. JenniferJuniper Apr 2018 #3
He's smart, like my eldest daughter. The other three kids post stuff online all of the time. TheBlackAdder Apr 2018 #4
So true, employers JenniferJuniper Apr 2018 #6
Many just outsource that to a third-party firm that has already mined the information. TheBlackAdder May 2018 #9
Here is a simple rule Lee-Lee Apr 2018 #7
And that is why I will never get one MiniMe Apr 2018 #8
Download crap apps, get bad shit with it Blue_Adept May 2018 #10

onethatcares

(16,173 posts)
5. yep, like
Mon Apr 30, 2018, 05:40 PM
Apr 2018

"whoops, we left a microphone on and it accidentally sent everything it could pick up to the "cloud"".

Panatir (?) just loves that shit.

There's also two dolls out their that record conversations with kids, feminine and masculine.What they hear goes to the cloud.

Imagine what kids say to their playtoys. It's fucking scary and there is not a thing we can do about it. Companies that enable this stuff laugh at resistance.

TheBlackAdder

(28,209 posts)
4. He's smart, like my eldest daughter. The other three kids post stuff online all of the time.
Mon Apr 30, 2018, 05:38 PM
Apr 2018

.

No matter how much I warn them, it's Snapchat, Instagram, Twitter, Facebook, etc.

Most of it is stupid stuff, but a lot has identifiable information in i, or stuff that might bite them in the ass.


I tell them, if you apply for a job, and don't get any offers, it's probably because of your web content.

JenniferJuniper

(4,512 posts)
6. So true, employers
Mon Apr 30, 2018, 05:54 PM
Apr 2018

scour the web for that stuff. The last thing you want is to not get your dream job at 22 because of some nonsense you posted five or six years ago. I know in kids years that's a long time, but it's nothing in adult years.

TheBlackAdder

(28,209 posts)
9. Many just outsource that to a third-party firm that has already mined the information.
Tue May 1, 2018, 02:45 PM
May 2018

Even the deleted stuff is stored.

 

Lee-Lee

(6,324 posts)
7. Here is a simple rule
Mon Apr 30, 2018, 06:05 PM
Apr 2018

If it has a microphone and can connect to the internet then it can be used to spy on you.

You smart phone, your laptop, your smart speaker, your gaming console, your smart TV, your fancy video doorbell. Your thermostat you can talk to.

If it has a microphone and connects to the net, it has everything needed to be a bug and just needs someone to turn it on.

Blue_Adept

(6,399 posts)
10. Download crap apps, get bad shit with it
Tue May 1, 2018, 02:47 PM
May 2018

It's a problem with any open market store like they have for these things.

Latest Discussions»General Discussion»Amazon Echo Flaw Allowed ...