News: 1646332268

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Amazon Alexa can be hijacked via commands from own speaker

(2022/03/03)


Without a critical update, Amazon Alexa devices could wake themselves up and start executing audio commands issued by a remote attacker, according to infosec researchers at Royal Holloway, University of London.

By exploiting a now-patched vulnerability, a malicious person with some access to a smart speaker could broadcast commands to itself or to other smart speakers nearby, allowing said miscreant to start "smart appliances within the household, buy unwanted items, tamper [with] linked calendars and eavesdrop on the [legitimate] user."

These were the findings of RHUL researchers Sergio Esposito and Daniele Sgandurra, working with Giampaolo Bella of Italy's Catania University. They discovered the flaw, nicknamed Alexa versus Alexa (AvA), describing it as "a command self-issue vulnerability."

[1]

"Self-activation of the Echo device happens when an audio file reproduced by the device itself contains a voice command," the researchers said.

[2]

[3]

The pair said they'd confirmed AvA affected both third- and fourth- generation ( [4]the latest release, first shipped in September 2020 ) Echo Dot devices.

Triggering the attack is as simple as using an Alexa-enabled device to start playing crafted audio files to itself, which the researchers suggested [5]in their paper could be hosted on an internet radio station tunable by an Amazon Echo. In this scenario, a malicious person would simply need to tune the internet radio station (essentially a command-and-control server, in infosec argot) to achieve control over the device.

[6]

Executing the attack requires exploitation of Amazon Alexa Skills. These, as Amazon explains, "are like apps that help you do more with Alexa. You can use them to play games, listen to podcasts, relax, meditate, order food, and more."

Here's a flowchart from the paper on how to pull off the AvA technique:

[7]

How to pull off an Alexa versus Alexa attack using a malicious radio station and skill ... Click to enlarge

As you can see, it's a neat way to get around some of the security of the device, depending on the situation. It's a novel method for taking control of a person's Alexa box if you, for instance, trick your victim into running a skill that plays a malicious internet radio station.

Sergio Esposito, one of the research team, told The Register that Speech Synthesis Markup Language (SSML) gave them another route for exploitation with skills, separate from the radio streaming approach. He explained: "It is a language that allows developers to program how Alexa will talk in certain situations, for example. An SSML tag could say that Alexa would whisper or maybe speak with a happy mood."

An SSML break tag, he told us, allowed natural-sounding pauses in scripts read out by Alexa to be extended to an hour long, meaning Alexa was no longer listening to the user's inputs: "So, an attacker could use this listening feature to set up a social engineering scenario in which the skill pretends to be Alexa and replies to the user's utterances as if it was Alexa."

[8]

Anyone can create a new Alexa Skill and publish it on the Alexa Skill store; as an example, while briefly reviewing Amazon UK's Skill store, The Register [9]found a Skill on the first page which reads out the lunch menu at a high school in northern India. Skills don't need any special privileges to run on an Alexa-enabled device, though Amazon says it vets them before letting them go live.

[10]Alexa, swap out this code that Amazon approved for malware... Installed Skills can double-cross their users

[11]Hackers manage – just – to turn Amazon Echoes into snooping devices

[12]Shine on: Boffins bedazzle Alexa and her voice-controlled assistant kin with silent laser-injected commands

[13]Amazon, Google inject Bluetooth vuln vaccines into Echo, Home AI pals

Amazon patched most of the vulns except for one where a Bluetooth-paired device could play crafted audio files over a vulnerable Amazon Echo speaker, Esposito told us. The threat model there involves a malicious person being close enough to connect to the speaker (Bluetooth range is about 10m); in that case you may have bigger problems than someone being able to remotely turn your dishwasher on.

One vuln in particular, tracked as [14]CVE-2022-25809 , was assigned a medium severity according to the researchers. A US National Vulnerability Database entry described it as "improper neutralization of audio output" and said it affected "3rd and 4th Generation Amazon Echo Dot devices," allowing "arbitrary voice command execution on these devices via a malicious 'Skill' (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an 'Alexa versus Alexa (AvA)' attack."

Alexa-enabled devices receive software updates automatically when connected to the internet. You can also use Alexa itself to update to the latest software version for an Echo device, according to Amazon.

"Say, 'Check for software updates' to install software on your Echo device," the vendor [15]suggests .

The researchers are due to present their findings in May at the AsiaCCS conference but curious readers can read all about it on their [16]website .

We have asked Amazon for comment and will update this article if it responds. ®

Get our [17]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YiFInDjmeRoCanWS6CPbfwAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiFInDjmeRoCanWS6CPbfwAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiFInDjmeRoCanWS6CPbfwAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://press.aboutamazon.com/news-releases/news-release-details/introducing-all-new-echo-family-reimagined-inside-and-out

[5] https://arxiv.org/abs/2202.08619

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YiFInDjmeRoCanWS6CPbfwAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://regmedia.co.uk/2022/03/03/handout_ava_flowchart.png

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YiFInDjmeRoCanWS6CPbfwAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.amazon.co.uk/Shiv-Nadar-School-Faridabad-Food/dp/B09Q2Z1CBW/ref=sr_1_4?brr=1&qid=1646317762&rd=1&s=digital-skills&sr=1-4

[10] https://www.theregister.com/2021/02/25/alexa_amazon_skills/

[11] https://www.theregister.com/2018/08/14/amazon_echo_hacking/

[12] https://www.theregister.com/2020/08/14/shine_on_boffins_bedazzle_alexa/

[13] https://www.theregister.com/2017/11/15/amazon_echo_blueborne/

[14] https://nvd.nist.gov/vuln/detail/CVE-2022-25809

[15] https://www.amazon.com/gp/help/customer/display.html?nodeId=GEYUPNHC9AYVL4Q3

[16] https://www.ava-attack.org/

[17] https://whitepapers.theregister.com/



Why give it house room?

Uncle Slacky

Unless I was elderly/disabled, I can't see any reason for keeping a listening device in my house. I'm obliged to have a smartphone, but I run an audio jammer (PilferShush) on it at all times.

Only one valid command

b0llchit

Alexa, please destroy yourself by all means possible.

With any luck, only dumb (smart) speakers are affected. However, some significant collateral damage is acceptable if it involves these listening devices (and their owners).

Re: Only one valid command

FuzzyTheBear

A handy hammer could accelerate the process considerably ..

Re: Only one valid command

jake

12 gauge.

PULL!

They are "mostly harmless", honest

martinusher

I've been living with these things since they came out and they're like any other piece of technology, they can be turned off if necessary. In addition to the 'mute' button there's the option of pulling the plug.

Amazon is aware of the possibility that the units could be hacked so should you use the unit for ordering stuff -- something that has to be first enabled in the application -- then you'll have ample opportunities to confirm and cancel the order. Its true that applications could be started but you'd be a complete idiot to connect anything to an interface like this that's potentially hazardous. These devices can record audio, but then anything with a microphone can.

Compared to a lot of Smart Home type toys that you can buy these units are both unobtrusive and seamless. I'm amazed at just how bad most units are -- they require intrusive signups for onine accounts you neither want nor need, they update their software so frequently that you're lucky if the 'app' works from one month to the next and when the provider goes belly up you end up with a paperweight. Bad software is the norm these days, hastily written in a desperate attempt to monetize the unmonetizable. Echo units at least work, they're unobtrusive and they're as useful as they need them to be. They're an object lesson in good product design.

Re: They are "mostly harmless", honest

Anonymous Coward

With these things it's not only what they are - but what they're capable of.

First off, do these things process the audio on the device itself? I don't think so.

Can the end user audit every bit of data going out of the thing, choose what goes out, or at least choose what Amazon can and can't do with the data? Fat chance.

Amazon has been caught red-handed overreaching with their IoT crap before.

[1]NYT, on Ring's security incidents

[2]The Guardian, on Ring being used for mass surveillance

Second, technology is (and should be) off until you need it. Smartphones don't abide by that rule - but with a limited battery life, there's only so much that they can do in terms of snooping. Smart speakers and "voice assistants" on the other hand are on by default until muted (at least the mute switch on the Echo speakers is a real switch and not software-controlled) - and with an infinite power supply, there is quite the potential for becoming a "bug".

Third, doesn't muting an Echo defeat its very purpose (at least as advertised) of being the future voice assistant that can be called anytime and anywhere in the house? Therefore what most people will do is that they'll leave the damn thing on because they're too lazy to unmute every time they need Alexa to turn on a light or whatever people use it for.

Alexa *does* need an Amazon account though.

Yeah they are intuitive and easy-to-use and all, but that doesn't justify paying out of pocket just to be a data point in some algorithm that wants to sell me crap.

Crap software is the result of attempts by the underdogs to beat Amazon at their game - which they can't, because Amazon has the sheer size needed to actually effectively do the data mining game.

[1] https://www.nytimes.com/2020/02/19/technology/personaltech/ring-doorbell-camera-spying.html

[2] https://www.theguardian.com/commentisfree/2021/may/18/amazon-ring-largest-civilian-surveillance-network-us

Re: They are "mostly harmless", honest

b0llchit

Well, if "mostly harmless" is the standard here, then I will await the Vogon construction fleet to fix the local space for that planned highway. This has, after all, the advantage of converting "mostly harmless" to "definitely no problem anymore".

Alternatively, we can limit ourselves to invite some Vogon poetry to be read to Alexa. It would probably sterilize the backing computers of all ability to record and reply. At least all Alexa enabled device owners will spontaneously kill themselves upon exposure to the exquisite Vogon verbal expressionism.

Re: They are "mostly harmless", honest

jake

"they can be turned off if necessary."

So you have to get up and flip a switch to tell it to turn on the lights (radio ...) and then flip the switch back off again? As apposed to getting up to turn on the lights (radio ...)?

Useful, that.

Anonymous Coward

> The threat model there involves a malicious person being close enough to connect to the speaker (Bluetooth range is about 10m); in that case you've got bigger problems than someone being able to remotely turn your dishwasher on.

Not necessarily. How about a burglar outside the house, bluetoothing in to get alexa to open the front door?

druck

Or if another Bluetooth device within 10m has been hacked, and can be commanded to pair with Alexa.

Anonymous Coward

Or if a Bluetooth device *20* metres away had been hacked and is used to compromise a Bluetooth device 10 m away which can be commanded to pair with the Amazon thing.

Anonymous Coward

That's on top of smart locks themselves having some pretty huge security issues.

jake

That's because smart lock designers are not actually lock designers. And from what I've seen, they aren't smart designers, either.

b0llchit

Assigning the label "smart" to these devices or these people is very problematic.

Next you know they are using blockchains to lock/unlock. Can't wait for the NFT enabled lock in my door.

Anonymous Coward

You say it in jest - but to me, it's as good as done.

"A smart lock that allows me to unlock my door simply with a transaction on the blockchain! Ain't that nice!"

- some poor mark, probably.

b0llchit

Poor only until the lock successfully mines your beloved digital tokens.

How is that for a design? A lock that pays its own bills! And it seconds as a (door)warmer.

Self pwning mode

Anonymous Coward

That's very handy.

If you have one

chivo243

For the safety of others, put the crap back in the box it came in, and send it back. Even if you mention my name(which isn't uncommon) I don't want to be fingered!! If, however, you know what you are dong, put the fucker in the hopper! And stop thinking you can stop alexa and friends munching your data, my best effort is to limit it! You must be delusional... sorry dude, but reality sux!

..and it's programmable...as well!! Whoopee!!

Anonymous Coward

https://betterprogramming.pub/how-to-play-youtube-audio-from-your-alexa-e2d4fb8b5ce9

"You know why there are so few sophisticated computer terrorists in the United
States? Because your hackers have so much mobility into the establishment.
Here, there is no such mobility. If you have the slightest bit of intellectual
integrity you cannot support the government.... That's why the best computer
minds belong to the opposition."
-- an anonymous member of the outlawed Polish trade union, Solidarity