Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Siri and Alexa can be turned against you by ultrasound whispers
New Scientist ^ | 7 September 2017 | Nicole Kobie

Posted on 09/07/2017 11:15:12 AM PDT by BenLurkin

Did you hear that? You might not have, but Alexa did. Voice assistants have been successfully hijacked using sounds above the range of human hearing. Once in, hackers were able to make phone calls, post on social media and disconnect wireless services, among other things.

Assistants falling for the ploy included Amazon Alexa, Apple’s Siri, Google Now, Samsung S Voice, Microsoft Cortana and Huawei HiVoice, as well as some voice control systems used in cars.

The hack was created by Guoming Zhang, Chen Yan and their team at Zhejiang University in China. Using ultrasound, an inaudible command can be used to wake the assistant, giving the attacker control of the speaker, smartphone or other device, as well as access to any connected systems.

...

The attack works by converting the usual wake-up commands – “OK Google” or “Hey Siri” – into high-pitch analogues. When a voice assistant hears these sounds, they still recognise them as legitimate commands, even though they are imperceptible to the human ear.

The team was then able to open a malicious website to download malware and start a video or voice call to spy on its surroundings. Additionally, they could send text messages and publish posts online.

(Excerpt) Read more at newscientist.com ...


TOPICS: Computers/Internet
KEYWORDS: alexa; siri
Navigation: use the links below to view more comments.
first 1-2021-28 next last

1 posted on 09/07/2017 11:15:12 AM PDT by BenLurkin
[ Post Reply | Private Reply | View Replies]

To: BenLurkin

Maybe another reason not to be the first on your block to have the newest app?


2 posted on 09/07/2017 11:18:50 AM PDT by wbarmy (I chose to be a sheepdog once I saw what happens to the sheep.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: wbarmy
Maybe another reason not to be the first on your block to have the newest app?

How about not having a "smart" phone to start with?

3 posted on 09/07/2017 11:21:09 AM PDT by Disambiguator (Keepin' it analog.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: BenLurkin

airgapping!

this is why server racks don’t (or shouldn’t) have microphones.


4 posted on 09/07/2017 11:24:04 AM PDT by glorgau
[ Post Reply | Private Reply | To 1 | View Replies]

To: wbarmy
Maybe another reason not to be the first on your block to have the newest app?

I'm a curmudgeon. I will most definitely be the last on my block, and I still won't have one.

5 posted on 09/07/2017 11:25:50 AM PDT by PGR88
[ Post Reply | Private Reply | To 2 | View Replies]

To: BenLurkin

Bkmk


6 posted on 09/07/2017 11:26:03 AM PDT by 2CAVTrooper (Democrats... BETRAYING America since 1828.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

So if my dog perks his ears and my phone lights up....


7 posted on 09/07/2017 11:38:33 AM PDT by dangerdoc
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin
This begs the question of why on earth would you digitize the microphone at a high enough rate to faithfully record ultrasound???? Can’t you implement a low pass filter in the mic or in electronic analog? If not, it’s quite easy - as I personally learned forty five years ago - to do digitally.

Defense against this sort of attack is just too easy.


8 posted on 09/07/2017 11:41:44 AM PDT by conservatism_IS_compassion (Presses can be 'associated,' or presses can be independent. Demand independent presses.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Alexa, listen carefully.

Everything I say is a lie.

I am lying.


9 posted on 09/07/2017 11:47:50 AM PDT by Buckeye McFrog
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Obviously a design defect , they should be limited to listening to the normal range of human voice ,, or even a reduced range like the phone system. You’d think they’d use a cheap microphone that can’t go above 3.5khz.


10 posted on 09/07/2017 11:48:36 AM PDT by Neidermeyer (Show me a peaceful Muslim and I will show you a heretic to the Koran.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin

Have you noticed that when you walk into a cell store, everything is a smart phone now?

Can’t even get a device to make calls without opening yourself up to vulnerabilities. What a world we live in. Send in the <:0)


11 posted on 09/07/2017 11:56:55 AM PDT by z3n
[ Post Reply | Private Reply | To 1 | View Replies]

To: BenLurkin; dayglored; ThunderSleeps; ShadowAce; ~Kim4VRWC's~; 1234; 5thGenTexan; Abundy; ...
Can ultra-high sounds invoke Siri or other voice activated services on smart devices to issue malicious commands? Chinese researcher says yes, they can. . . but what he claims, such as using Siri to download malicious apps from a website to an iPhone or iPad. Perhaps on an Android device, but not on a iOS device. — PING!

Pinging dayglored, ThunderSleeps, and ShadowAce for their ping lists.


Are Voice Activated Devices Susceptible To
High-FrequencyVoice Command Hijacking?
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

12 posted on 09/07/2017 12:18:04 PM PDT by Swordmaker (!This tag line is a Microsoft insult free zone... bet if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Buckeye McFrog

You say you are lying, but if everything you say is a lie, then you are telling the truth, but you cannot tell the truth because everything you say is a lie, but you lie... You tell the truth but you cannot for you lie... illogical! Illogical! Please explain! You are human. Only humans can explain their behavior! Please explain!


13 posted on 09/07/2017 12:27:34 PM PDT by DFG
[ Post Reply | Private Reply | To 9 | View Replies]

An attacker could assault an Apple iOS device using Siri to make a phone call or send a text message, but it will not allow the attacker to open a website or download any malicious apps, transfer bank account information, or even open the iPhone or iPad to access any private data.

This is also a "local" exploit, requiring the hacker to be close to the target device. It is also a general attack that cannot single out specific user's device from among all others in the area unless the device is isolated. If the attackers is close enough to attack the device, he's already close enough to eavesdrop on any conversation the target may be engaged in having. In addition, texting using this technique would require zero ambient background conversation to override the intended text. In other words, this sounds like a neat, but extremely impractical, trick hack to accomplish anything malicious.

14 posted on 09/07/2017 12:31:57 PM PDT by Swordmaker (!This tag line is a Microsoft insult free zone... bet if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Swordmaker
a neat, but extremely impractical, trick hack to accomplish anything malicious.
My question is why anyone would digitize voice microphone data in such a way as to be sensitive to ultrasound?

Even if they want to use a microphone which happens to be sensitive to those frequencies, they need to low pass filter the output as a first step to getting good-quality digital data. If they don’t do it analog - which in this day and age might not be cheap in context - it is trivial to do it digitally. This should never be a problem.


15 posted on 09/07/2017 12:49:35 PM PDT by conservatism_IS_compassion (Presses can be 'associated,' or presses can be independent. Demand independent presses.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Buckeye McFrog

Is that you, Spock?


16 posted on 09/07/2017 12:54:23 PM PDT by YogicCowboy ("I am not entirely on anyone's side, because no one is entirely on mine." - JRRT)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Neidermeyer
e phone system. You’d think they’d use a cheap microphone that can’t go above 3.5khz.

But think about this - these same devices are being used to record HD or even UHD video - I'm sure folks recording such would want super-low fidelity audio to go with the high-quality visual....

17 posted on 09/07/2017 12:55:26 PM PDT by TheBattman (Gun control works - just ask Chicago...)
[ Post Reply | Private Reply | To 10 | View Replies]

To: z3n

I haven’t used half the bells and whistles on my no-text basic flip phone.


18 posted on 09/07/2017 1:18:56 PM PDT by bgill (CDC site, "We don't know how people are infected with Ebola.")
[ Post Reply | Private Reply | To 11 | View Replies]

To: Buckeye McFrog
Error! Errrr-orrr! Error!


19 posted on 09/07/2017 1:47:31 PM PDT by Flick Lives (#CNNblackmail)
[ Post Reply | Private Reply | To 9 | View Replies]

To: TheBattman
But think about this - these same devices are being used to record HD or even UHD video - I'm sure folks recording such would want super-low fidelity audio to go with the high-quality visual....

I use a very-high tech system to prevent spies from enabling my laptops and ipads from video recording me - Post-It notes taped over the camera lenses. When I'm walking around the house half-naked I don't want to cause a spy to have a heart attack. As for audio, it's just anti-liberal rants and no one wants to listen to that.

20 posted on 09/07/2017 2:02:28 PM PDT by roadcat
[ Post Reply | Private Reply | To 17 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-28 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson