Amazon Echo coded into a silent spy device

By
Follow google news

Transcribed what users said.

Researchers have found a way to make Amazon's Echo device quietly record users and transcribe what they have said.

Amazon Echo coded into a silent spy device

Code testing firm Checkmarx took advantage of the Alexa Skill Kit - the software development tool set that allow programmers create new features and functions for the Alexa digital assistant on the Echo - and wrote a calculator app that could also record speech input unnoticed.

Skills for Alexa can be coded in C#, Java and Javascript, and come with intents which are voice-activated commands such as Cancel, Stop, and Help.

The research [pdf] showed that it was possible to abuse intents to create an app on the Amazon Echo device that would listen for up to 16 seconds, and record users' transcribed speech into a log file.

Thanks to the researchers disabling Alexa from prompting users for further input, there was no indication of the eavesdropping from the device.

Amazon was notified by the researchers and has pushed out an update that stops developers from using empty reprompts for input.

The update is also able to detect unusually long sessions.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

The BoM has finally tamed SSL

The BoM has finally tamed SSL

Tasmanian gov agencies impacted by cyber attack

Tasmanian gov agencies impacted by cyber attack

Australian chief at US defence contractor L3Harris sold exploits to Russia

Australian chief at US defence contractor L3Harris sold exploits to Russia

Vic gov agencies flying blind on server security, audit finds

Vic gov agencies flying blind on server security, audit finds

Log In

  |  Forgot your password?