Amazon Alexa flaw that could expose personal information and speech histories found
#1
Information 
Quote:Security researchers have identified an exploit in Amazon’s Alexa voice platform. When exploited, Check Point Research says that the flaw could have given attackers access to users’ personal information. These include users’ Amazon account details as well as speech histories.
 
The researchers identified the vulnerability while conducting tests with the Alexa smartphone app. They used a script to bypass the mechanism implemented for protecting the app's traffic, which allowed them to view it in clear text. They found that several requests made by the app had a misconfigured policy, which could be potentially bypassed to send requests from a domain controlled by a malicious party.
 
In the real world, a bad actor would have been able to convince an unsuspecting user to click on a malicious link to Amazon that actually holds code-injection capabilities. Once clicked, the attacker would be able to get hold of the users’ list of apps and skills installed on Alexa. They would also be able to remotely install and enable new skills for the victim. More serious attackers could also get hold of users’ speech histories as well as personal information from their Alexa account.
 
Oded Vanunu, Head of Products Vulnerabilities Research at Check Point is quoted as saying in a press release:
Quote:Smart speakers and virtual assistants are so commonplace that it’s easy to overlook just how much personal data they hold, and their role in controlling other smart devices in our homes. But hackers see them as entry points into peoples’ lives, giving them the opportunity to access data, eavesdrop on conversations or conduct other malicious actions without the owner being aware.
Vanunu adds that the research firm highlighted the flaw to Amazon back in June, and it responded by fixing it. “We conducted this research to highlight how securing these devices is critical to maintaining users’ privacy. Thankfully, Amazon responded quickly to our disclosure to close off these vulnerabilities on certain Amazon/Alexa subdomains,” he said.

Source: https://www.neowin.net/news/amazon-alexa...ries-found
[-] The following 2 users say Thank You to silversurfer for this post:
  • dhruv2193, harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Microsoft Defender Antivirus security in...
Stable channel upd...harlan4096 — 07:25
Google Chrome 146.0.7680.177/178
Google Chrome 146....harlan4096 — 07:22
F-Secure v26.3
Hello, as per the ...harlan4096 — 07:21

[-]
Birthdays
Today's Birthdays
avatar (44)lamSouse
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (41)alapesihy
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>