Researchers abuse Alexa and Google Home to eavesdrop and phish passwords

Peter Reutemann <[email protected]> Mon, 21 Oct 2019 12:19:57 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+RPbFeXgj9ZCbzwy2DhDFGRDRdEEsGLzt2OJ2gJv3mJg@mail.gmail.com>
'By now, the privacy threats posed by Amazon Alexa and Google Home are
common knowledge. Workers for both companies routinely listen to audio
of users—recordings of which can be kept forever—and the sounds the
devices capture can be used in criminal trials.

Now, there's a new concern: malicious apps developed by third parties
and hosted by Amazon or Google. The threat isn't just theoretical.
Whitehat hackers at Germany's Security Research Labs developed eight
apps—four Alexa "skills" and four Google Home "actions"—that all
passed Amazon or Google security-vetting processes. The skills or
actions posed as simple apps for checking horoscopes, with the
exception of one, which masqueraded as a random-number generator.
Behind the scenes, these "smart spies," as the researchers call them,
surreptitiously eavesdropped on users and phished for their
passwords.'

-- source: https://arstechnica.com/information-technology/2019/10/alexa-and-google-home-abused-to-eavesdrop-and-phish-passwords/

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz