Budapest Post

Cum Deo pro Patria et Libertate
Budapest, Europe and world news

Amazon Alexa security bug allowed access to voice history

Amazon Alexa security bug allowed access to voice history

A flaw in Amazon's Alexa smart home devices could have allowed hackers access personal information and conversation history, cyber-security researchers say.

Attackers could install or remove apps on a device without the owner knowing, Check Point Research reports.

The hack "required just one click on an Amazon link" purposely crafted by the attacker, it says.

The firm told Amazon about the flaw, which has now been fixed.

Amazon said: "The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us."

It said it did not know of any case where a bad actor had used the vulnerability to target its customers.

In January, Amazon said there were "hundreds of millions" of Alexa devices in the world.

Malicious skills


Check Point said the hack required the creation of a malicious Amazon link, which would be sent to an unsuspecting user.

Once they clicked the link, the attacker could get a list of all installed Alexa "skills" - or apps - and steal a token allowing them add or remove skills.

One way to use the flaw would be to remove a skill and then install a malicious one that uses the same "invocation phrase" - the series of spoken words used to trigger it. This could have been done without the user knowing.

The next time the user tried to activate that skill, it would have run the attacker's app instead.

The attackers would have been able to see Alexa's voice history - a record of conversations between the user and device.

Check Point said this could create major problems, pointing to banking skills that let the user check their account balance.

"This could lead to exposure of personal information, such as banking data history," they argued - even though it does not save banking login details.

Amazon objected to this suggestion, however, saying that banking information - like balances - was redacted in the record of Alexa's responses, so it could not have been accessed.

The attack would also allow access to personal information in the Amazon profile, such as a home address, Check Point said.

Amazon also said it believed the use of a secret malicious skill was less likely than Check Point's researchers implied.



Amazon’s head of Alexa Dave Limp on privacy concerns



It said there were systems in place to prevent malicious skills from ever hitting the Alexa Skills Store - and that security reviews were part of their process.

Badly behaving apps were also routinely deactivated, it said.

"Their screening process probably would have caught most bad actors - they are quite good at that and know their reputation is at stake," said University of Surrey cyber-security expert Prof Alan Woodward.

"The thing about this hack was that it was due to a vulnerability that is well-known… so it's surprising to see it in Amazon's estate."

He said the access to voice records was a big concern, but was unsure if other hackers could have known about the vulnerabilities in specific subdomains used to launch the attack.

"Although if the security researchers found it, I'm sure less scrupulous people could have done the same."

AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
French Police Probe Suspected Weather-Data Tampering After Unusual Polymarket Bets on Paris Temperatures
CATL Unveils Revolutionary EV Battery Tech: 1000 km Range and 7-Minute Charging Ahead of Beijing Auto Show
Changi Airport: How Singapore Engineered the World’s Most Efficient Travel Experience
Power Dynamics: Apple’s Leadership Shakeup, Geopolitical Risks in the Strait of Hormuz, and Europe's Energy Strategy Amidst Global Challenges
Apple's Leadership Transition: Can New CEO John Ternus Navigate AI Challenges and Geopolitical Pressures?
Italy’s €100K Tax Gambit: Europe’s Soft Power Tax Haven
Budapest latest News Roundup
Travel on all public transport in the Australian state of Victoria will be free in May and then half price for the remainder of this year as the government ramps up help for consumers battling high fuel costs
News Roundup
Microsoft lost 2.5 millions users (French government) to Linux
Privacy Problems in Microsoft Windows OS
News roundup
Hungary's elections
Péter András Magyar and the Strategic Reset of Hungary
Hungary After the Landslide — A Strategic Reset in Europe
The CIA’s Secret Technology That Can Find You by Your Heartbeat Successfully Locates Downed Airman
Operation Europe: Trump Deploys Vance to Hungary to Save the EU
Asian Energy Security Tested as Strait of Hormuz Disruption Threatens Oil Supplies
Iran Sets Three Conditions for Ending Regional War as Diplomatic Efforts Intensify
Iran warns of $200 oil as forces target merchant ships in Gulf
Japan to Release 45 Days of Oil Reserves Amid Iran Conflict
Global Energy Agency Announces Record Release of 400 Million Barrels to Stabilize Oil Markets Amid Hormuz Disruption
U.S. and Israel Intensify Strikes on Iran as Conflict Expands to Lebanon and Gulf States
When the State Replaces the Parent: How Gender Policy Is Redefining Custody and Coercion
Larry Summers, the former U.S. Treasury Secretary, is resigning from Harvard University as fallout continues over his ties to Jeffrey Epstein.
U.S. stocks ended higher on Wednesday, with the Dow gaining about six-tenths of a percent, the S&P 500 adding eight-tenths of a percent, and the tech-heavy Nasdaq climbing roughly one-and-a-quarter percent.
Nvidia posted better than expected results for the January quarter on Wednesday and forecast current quarter revenue above market estimates.
Ukrainian government intensifies pressure on Hungary and Slovakia with oil blockade
Britain’s Channel Crisis: Paying Billions While the Boats Keep Coming
Woman Receives Gift Card for Christmas – Discovers It Is ‘Worth’ 63,000,000,000,000,000 Pounds
United Nations Calls for Global Action Against Disinformation and Hate Speech Online
Tucker Carlson warns of an inevitable clash in Western societies over mass migration
OpenAI CEO Sam Altman praises the rapid progress of Chinese tech companies.
Poland's President Karol Nawrocki ENDS support for Ukrainian citizens:
Italy's PM Giorgia Meloni highlights record employment and economic growth
Chancellor Friedrich Merz Re-elected as CDU Leader, Opposes AfD Influence
Trump Directs Government to Release UFO and Alien Information
Trump Signs Global 10% Tariffs on Imports
UK Government Considers Law to Remove Prince Andrew from Royal Line of Succession
Two teens arrested in France for alleged terror plot.
US Supreme Court Voids Trump’s Emergency Tariff Plan, Reshaping Trade Power and Fiscal Risk
Greek Prime Minister Kyriakos Mitsotakis advocates for a ban on minors using social media.
Meanwhile in Time Square, NYC One of the most famous landmarks
Jensen Huang just told the story of how Elon Musk became NVIDIA’s very first customer for their powerful AI supercomputer
Former British Prince Andrew Arrested on Suspicion of Misconduct in Public Office
Former President Yoon Suk Yeol Sentenced to Life in Prison for Abuse of Authority
Unitree Robotics founder Wang Xingxing showcases future robot deployment during Spring Festival Gala.
German Chancellor Friedrich Merz calls for real name use on social media.
Italian Police Arrest Man After Alleged Attempt to Abduct Toddler at Bergamo Supermarket, Child Hospitalised With Fractured Femur
British Tourist Arrested at Hong Kong Airport After Meltdown and Vandalism
×