Alexa, swap out this code that Amazon approved for malware... Installed Skills can double-cross their users
- Reference: 1614236646
- News link: https://www.theregister.co.uk/2021/02/25/alexa_amazon_skills/
- Source link:
In [1]research presented on Wednesday at the Network and Distributed System Security Symposium (NDSS) conference, researchers describe flaws in the process Amazon uses to review third-party Alexa applications known as Skills.
[2]
The boffins – Christopher Lentzsch and Martin Degeling, from Horst Görtz Institute for IT Security at Ruhr-Universität Bochum, and Sheel Jayesh Shah, Benjamin Andow (now at Google), Anupam Das, and William Enck, from North Carolina State University – analyzed 90,194 Skills available in seven countries and found safety gaps that allow for malicious actions, abuse, and inadequate data usage disclosure.
The researchers, for example, were able to publish Skills using the names of well-known companies, which makes trust-based attacks like phishing easier. And they were also able to revise code after it had been reviewed without further scrutiny.
[3]
We show that not only can a malicious user publish a Skill under any arbitrary developer/company name, but she can also make backend code changes after approval
"We show that not only can a malicious user publish a Skill under any arbitrary developer/company name, but she can also make backend code changes after approval to coax users into revealing unwanted information," the academics explain in their paper, titled "Hey Alexa, is this Skill Safe?: Taking a Closer Look at the Alexa Skill Ecosystem."
[4]PDF
By failing to check for changes in Skill server logic, Amazon makes it possible for a malicious developer to alter the response to an existing trigger phrase or to activate a previously approved dormant trigger phase. A Skill manipulated in this way could, for example, start asking for a credit card after passing Amazon's initial review.
The researchers also found that the permission system Amazon uses to protect sensitive Alexa data can be bypassed. The problem is that just because a developer doesn't declare the intent to use an API for a sensitive data type like a credit card number, that doesn't preclude a developer's Skill from asking for or collecting that information.
"We tested this by building a skill that asks users for their phone numbers (one of the permission-protected data types) without invoking the customer phone number permission API," the paper explains. "Even though we used the built-in data type of Amazon.Phone for the intent, the skill was not flagged for requesting any sensitive attribute."
You know that silly fear about Alexa recording everything and leaking it online? It just happened [5]READ MORE
The boffins identified 358 Skills capable of requesting information that should be protected by a permission API.
They also found that Skill squatting – e.g. Skills that try to get people to invoke them inadvertently by implementing invocation and intent names that sound similar to the invocation and intent names of legitimate Skills – is common.
At the same time, they observe that this isn't being done maliciously, to their knowledge. Rather, it appears mainly to be a way for developers to piggyback on the popularity of their own existing Skills – having two Skills activated by nearly identical phrases increase the likelihood some of their software will run.
Finally, the researchers found that almost a quarter (24.2 per cent) of Alexa Skills don't fully disclose the data they collect. They contend this is particularly problematic for Skills in the "kids" and "health and fitness" categories due to the higher privacy standards expected by regulators. Along similar lines, they say about 23.3 per cent of Alexa Skill privacy policies don't adequately explain the data types associated with the permissions being requested.
Problems add up
These findings coincide with the arrival of another paper exploring Alexa security, from computer scientists Yanyan Li, Sara Kim, Eric Sy at California State University, San Marcos. Their work, titled, " [6]A Survey on Amazon Alexa Attack Surfaces ," looks at Alexa more broadly.
It doesn't unearth previously unknown vulnerabilities. Rather it provides an overview of various attack vectors related to voice capturing, voice traffic transmission, Alexa voice recognition, Alexa skill invocation, Lambda functions and Amazon S3 buckets. It also proposes a variety of potential mitigations, all of which would require Amazon to invest additional time and resources to lock its ecosystem down.
The researchers from Germany and the US say Amazon has confirmed some of its findings and is working on countermeasures.
Amazon couldn't quite bring itself to acknowledge that when asked to comment, admitting only that it's always working on security. A company spokesperson said the company was aware of the work by Lentzsch and colleagues and is still reviewing the second paper.
"The security of our devices and services is a top priority," Amazon's spokesperson said in an email to The Register . "We conduct security reviews as part of skill certification and have systems in place to continually monitor live skills for potentially malicious behavior."
[7]
"Any offending skills we identify are blocked during certification or quickly deactivated. We are constantly improving these mechanisms to further protect our customers. We appreciate the work of independent researchers who help bring potential issues to our attention." ®
Get our [8]Tech Resources
[1] https://www.alexa-skill-analysis.org/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YDeDS9xB3GwEmE9OeTB6lgAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YDeDS9xB3GwEmE9OeTB6lgAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://anupamdas.org/paper/NDSS2021.pdf
[5] https://www.theregister.com/2018/05/24/alexa_recording_couple/
[6] https://arxiv.org/abs/2102.11442
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YDeDS9xB3GwEmE9OeTB6lgAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://whitepapers.theregister.com/
Re: I don't want your help
I have Google Assistant snd the mic disabled on my phone, the icon for the mic however, is always functional and placed where it can be inadvertently touched so I constantly have a pop up asking to allow or deny the mic for Google.
I have found that shouting at the phone doesn't help at all but it hasn't stopped me.
There are so many reasons I won't let one of these in my house.
( [1]Obligatory ).
[1] https://xkcd.com/1807/
No such thing
... analyzed the security measures protecting Amazon's Alexa voice assistant ecosystem and found them wanting.
Security measures?
Protecting?
Amazon's Alexa?
It's been quite obvious from the very first time this crap came out on the market:
There - is - no - such - thing.
If you are stupid enough to buy one, you deserve what you get.
O.
I don't want your help
Don't know if this is important, but my new Android mobile phone has this button on the side that brings up a "How can I help" assistant. The button is perfectly placed so that it unwittingly gets pressed every time one handles the phone. One day, in a rage, I managed to switch on a blighter that was reading the news while some female robot voice wanted to know how it could help me. Not being used to UI's that have been thoroughly millnialized, I could not figure out how to exit the news. Then this robot starts asking me "How can I help?", to which I requested the Google go away. But I may have been using some words and a tone of voice that would clearly indicate that I did not wish to be helped by Google's robot (i.e. F-OFF GOOGLE!!!!!). My rage doubled when this thing actually said: "I'm sorry if I upset you".