Skip to content

Amazon Echo device Alexa used to ‘eavesdrop’

The Telegraph is reporting that eavesdroppers are able to listen to entire conversations happening around the device even if the owner hasn’t said “Alexa”.

Pentesting UK originally posted about the threat to our homes from such devices in early June 17 ‘electronic assistants pose security risk‘.  Now one of the greatest fears about the Amazon Echo has been confirmed.

Eavesdroppers are able to listen to entire conversations happening around the device even if the owner hasn’t said “Alexa”.

Researchers have discovered a way to turn the Echo speaker into a “wiretap” that sends all recordings to a hacker’s computer…

…The vulnerability could let cyber criminals listen to microphone recordings, see an owner’s Amazon credentials, steal sensitive information, and takeover the device.

“Someone could use [the hack] to install malicious software on the device and turn it into a wiretap without the person who owns the Echo knowing.” said Mark Barnes, one of the MWR security consultants who discovered the problem…

…”On the base of the Amazon Echo there are 18 pads you can easily access used for debugging the device.” said Barnes. “If you attach an SD card to certain parts you’re able to reboot the system without it showing you, which gives you access to the device and let’s you basically do anything you want.”…

Amazon said: “To help ensure the latest safeguards are in place, as a general rule, we recommend customers purchase Amazon devices from Amazon or a trusted retailer and that they keep their software up-to-date.”

Read more at:  ‘Amazon Echo can be used to eavesdrop

PENETRATION TESTING SERVICES BASED IN EXETER, DEVON

Pentesting UK is based in Exeter, Devon helps organisations identify their vulnerabilities, through penetration testing,  ASV scanning, application testing and vulnerability scanning for businesses and organisations across the UK and beyond. Contact us for more info…