Tag Archive for: Speaker

Hey Alexa Go Hack Yourself: Researchers Detail Wild Self-Issued Smart Speaker Hijacks


dot table

Did you ever get an Amazon delivery and not remember placing an order for the item? There are plenty of stories of this all over the internet, and sometimes those boil down to one too many cocktails in your attitude adjustment hour. What if we told you that maybe one of those times it wasn’t related to brain fog or blackouts, but some random person decided to order something for you through your own Amazon Echo device?

That’s what researchers from the University of London’s Royal Holloway, and Catania University in Italy discovered is entirely possible. Through a few different methods of either social engineering or just being nearby an Echo device, Alex can be activated and used fairly easily. Tested on the third generation of the Echo Dot, though believed to be exploitable via fourth gen devices as well, the researchers found that playing audio files with the right wake words will activate the Alexa Voice-enabled device it is playing from. Dubbed “Alexa Versus Alexa” by the researchers, the exploit can be used to order products, make modifications to settings, install skills, and a whole host of other functionality that the Echo device product line allows Amazon Echo Dot owners to take advantage of.

fixed social radio
Diagram Of Alexa Vs Alexa Exploit

An social engineering exploit example would be having someone activate an internet radio station that intentionally utilizes common activation terms. So pre-existing skills, like Echo’s Music and Radio skill, may play one of these stations that then let that device activate itself. Part of the reason this can be a really big problem is that Amazon’s Echo devices typically only validate account activity and actions during the initial setup of the device. Skill installation is a big deal for this because these are small apps that run directly on the device, and with the right malicious code they can potentially be a security threat. That creates a situation where once the vulnerability is activated, the attacker can issue any command that is at the disposal of the Echo device.

Amazon has issued a patch (check your software version here), which you can force by asking the device to ‘check for updates’. However, the issue remains if the attacker is in…

Source…

Amazon Big Screen Smart Speaker | Mobile Robot


The Show 15 can also function as a 1080p TV for the kitchen with support for Hulu, Netflix, Prime Video, and later this year, Sling TV. And when it’s not in use, the laptop-sized screen can blend into the background as a smart picture frame, displaying family photos or other pre-selected art. The device will be available later this fall, the company says.

Alexa, the company’s voice-controlled digital assistant, is getting a variety of new skills that seem designed to dovetail with the Show 15.

For example, the digital assistant can now use a smart speaker’s camera to identify members of a household and allow them to see their individual calendars, messages, or even recently played music.

And, you can now set up alerts linked to sounds in your home; for example, a notification that lets you know the smart speaker has heard the beep your fridge makes when it’s left open.

The company also announced a potentially important privacy change for its higher-end devices.

Instead of sending all voice recordings to Amazon’s cloud servers for processing, the company’s more expensive smart speaker models will process some verbal commands—such as “turn on the lights”—locally on the device.

The option will be available on the Echo Show 10, Echo Show 15, and the fourth generation Echo, but not on less expensive devices, like the entry-level Echo Dot, which have more limited processing capabilities.

Source…

John McAfee to be Keynote Speaker at the China Internet Security … – PR Newswire (press release)

John McAfee to be Keynote Speaker at the China Internet Security …
PR Newswire (press release)
HARRISON, N.Y., Aug. 12, 2016 /PRNewswire/ — MGT Capital Investments, Inc. (NYSE MKT: MGT) has announced that John McAfee, the Company's proposed …

and more »

“internet security” – read more