{"id":271739,"date":"2018-08-13T10:46:20","date_gmt":"2018-08-13T08:46:20","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=271739"},"modified":"2018-08-13T10:47:44","modified_gmt":"2018-08-13T08:47:44","slug":"amazon-echo-turned-into-listening-bug-through-complex-hack","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/271739-amazon-echo-turned-into-listening-bug-through-complex-hack.html","title":{"rendered":"Amazon Echo turned into listening bug through complex hack"},"content":{"rendered":"<p>Security researchers from China will present their hack of the Amazon Echo, which turns it into a spying device, at the\u00a0<strong><a href=\"https:\/\/www.defcon.org\/html\/defcon-26\/dc-26-speakers.html#HuiYu\" target=\"_blank\" rel=\"noopener\">DEFCON<\/a><\/strong> event in Las Vegas.<\/p>\n<p>Wu Huiyu and Qian Wenxiang, who work at Tencent, disclosed their discovery to Amazon which issued a patch, <strong><a href=\"https:\/\/www.wired.com\/story\/hackers-turn-amazon-echo-into-spy-bug\/\">Wired reported<\/a><\/strong>.<\/p>\n<p>According to the report, the researchers had to exploit several bugs for the attack to work. Their technique also requires that they have access to the same Wi-Fi network as the Amazon Echo.<\/p>\n<p>To take over an Echo, the researchers disassembled it and wrote custom firmware to the device&#8217;s flash chip &#8211; which they had to remove and re-solder to the Echo&#8217;s motherboard.<\/p>\n<p>They then used a chain of vulnerabilities in the Alexa web interface, all of which Amazon has subsequently patched:\u00a0cross-site scripting, URL redirection, and HTTPS downgrade attacks.\u00a0This allowed them to link the hacked Echo with their target&#8217;s Amazon account.<\/p>\n<p>Once on the same network as their target device, the attackers exploited the Whole Home Audio Daemon, a software component in the Echo which lets devices communicate with one another.<\/p>\n<p>The\u00a0daemon contained a vulnerability which allowed them to take over the target speaker with their hacked Echo.<\/p>\n<p>While their attack is limited, the report stated it demonstrates an issue with smart speakers that security researchers have warned about.<\/p>\n<h3 class=\"my-4\">Now read:\u00a0<a href=\"https:\/\/mybroadband.co.za\/news\/gadgets\/204702-i-built-a-voice-controlled-amazon-echo-using-a-raspberry-pi.html\">I built a voice-controlled Amazon Echo using a Raspberry Pi<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Security researchers from China will present their hack of the Amazon Echo at DEFCON.<\/p>\n","protected":false},"author":23,"featured_media":257055,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[27491,45102,53049],"class_list":["post-271739","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-amazon-echo","tag-def-con","tag-def-con-2018"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/271739"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=271739"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/271739\/revisions"}],"predecessor-version":[{"id":271753,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/271739\/revisions\/271753"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/257055"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=271739"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=271739"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=271739"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}