Attackers can force Amazon Echos to hack themselves with self-issued commands

Popular “smart” device follows commands issued by its own speaker. What could go wrong?

A group of Amazon Echo smart speakers, including Echo Studio, Echo, and Echo Dot models. (Photo by Neil Godwin/Future Publishing via Getty Images)

Enlarge / A group of Amazon Echo smart speakers, including Echo Studio, Echo, and Echo Dot models. (Photo by Neil Godwin/Future Publishing via Getty Images) (credit: T3 Magazine/Getty Images)

Academic researchers have devised a new working exploit that commandeers Amazon Echo smart speakers and forces them to unlock doors, make phone calls and unauthorized purchases, and control furnaces, microwave ovens, and other smart appliances.

The attack works by using the device’s speaker to issue voice commands. As long as the speech contains the device wake word (usually “Alexa” or “Echo”) followed by a permissible command, the Echo will carry it out, researchers from Royal Holloway University in London and Italy’s University of Catania found. Even when devices require verbal confirmation before executing sensitive commands, it’s trivial to bypass the measure by adding the word “yes” about six seconds after issuing the command. Attackers can also exploit what the researchers call the "FVV," or full voice vulnerability, which allows Echos to make self-issued commands without temporarily reducing the device volume.

Alexa, go hack yourself

Because the hack uses Alexa functionality to force devices to make self-issued commands, the researchers have dubbed it "AvA," short for Alexa vs. Alexa. It requires only a few seconds of proximity to a vulnerable device while it’s turned on so an attacker can utter a voice command instructing it to pair with an attacker’s Bluetooth-enabled device. As long as the device remains within radio range of the Echo, the attacker will be able to issue commands.

Read 12 remaining paragraphs | Comments

Ursprung des Corona-Virus: Politik mit unsicherem Wissen

Verschwörungsmythen viel Schaden anrichten, etablierte Medien vertiefen ihn durch fehlenden Recherchewillen. Fallanalyse eines Medienversagens (Teil 2 und Schluss)

Verschwörungsmythen viel Schaden anrichten, etablierte Medien vertiefen ihn durch fehlenden Recherchewillen. Fallanalyse eines Medienversagens (Teil 2 und Schluss)

The war in Ukraine is keeping Chinese social media censors busy

Posts that glorify war and those that criticize Russia are getting quietly deleted.

A sign outside Canada's embassy in Beijing supporting Ukraine. It was later defaced, and posts about the incident were scrubbed from Chinese social media.

Enlarge / A sign outside Canada's embassy in Beijing supporting Ukraine. It was later defaced, and posts about the incident were scrubbed from Chinese social media. (credit: Kevin Strayer | Getty Images)

“Artillery fire lights up the sky and breaks my heart. I hope my compatriots in Ukraine are taking care of themselves and their families,” said a user on Weibo, often called China’s Twitter, on February 27. The message was quickly blocked, according to Free Weibo, a service of Great Fire, which tracks Chinese censorship online.

Two days later, a very different message appeared on Weibo: “I support fighting! America and Taiwan have gone too far.” That, too, was blocked, according to Free Weibo.

Read 15 remaining paragraphs | Comments

"Russland auf Sanktionen vorbereitet"

Der Wirtschaftswissenschaftler Hansjörg Herr über den europäischen Finanzmarkt, die EZB und die Folgen des Einmarsches der russischen Armee in die Ukraine

Der Wirtschaftswissenschaftler Hansjörg Herr über den europäischen Finanzmarkt, die EZB und die Folgen des Einmarsches der russischen Armee in die Ukraine

MidCat-Pipeline zur Befreiung von der russischen Gas-Abhängigkeit?

2019 wurde das einst von der EU als “prioritär” bezeichnete Projekt gestoppt, über das Gas aus Algerien und Flüssiggas von der Iberischen Halbinsel nach Zentraleuropa gepumpt werden könnte

2019 wurde das einst von der EU als "prioritär" bezeichnete Projekt gestoppt, über das Gas aus Algerien und Flüssiggas von der Iberischen Halbinsel nach Zentraleuropa gepumpt werden könnte

Ukraine-Schock-Strategie: 100 Milliarden mehr fürs deutsche Militär

Koalitionäre und Unionsparteien haben sich geeinigt. Dem 100-Milliarden-Rüstungspaket inklusive Grundgesetzänderung steht nichts mehr im Weg. Die Aufrüstung schafft aber keinen Schutz, sondern birgt Gefahren.

Koalitionäre und Unionsparteien haben sich geeinigt. Dem 100-Milliarden-Rüstungspaket inklusive Grundgesetzänderung steht nichts mehr im Weg. Die Aufrüstung schafft aber keinen Schutz, sondern birgt Gefahren.