Amazon Alexa security bug could have let hackers listen in to your chats amazon echo


Owners of Amazon Echo devices have been warned that their systems may have been compromised due to a security flaw in the Alexa voice recognition service.
Researchers from security firm Check Point found vulnerabilities in certain Amazon and Alexa subdomains that could have allowed outsider access to a user’s voice history.
This includes all voice searches and conversation history made by a user, and could mean that personal data would be accessed and potentially stolen.
Alexa security flaw
Alexa users could have been easily tricked into falling for the vulnerability, which reportedly only needed a single click on a malicious link crafted and sent by the hacker.
Check Point says the attack could also have allowed hackers to remove or install apps (known as skills) on the victim’s Alexa account, meaning malicious programs could have been inserted to steal more personal information.
As well as clicking on the malicious link, some form of voice interaction would also have been needed. The researchers noted that hackers could get around this by creating a separate Alexa skill that required the same activation phrase as a legitimate service, so that when the user uttered the “invocation phrase” needed, it unwittingly activated the malicious skill.
“Smart speakers and virtual assistants are so commonplace that it’s easy to overlook just how much personal data they hold, and their role in controlling other smart devices in our homes. But hackers see them as entry points into peoples’ lives, giving them the opportunity to access data, eavesdrop on conversations or conduct other malicious actions without the owner being aware,” said Oded Vanunu, Head of Products Vulnerabilities Research at Check Point.
“We conducted this research to highlight how securing these devices is critical to maintaining users’ privacy. We hope manufacturers of similar devices will follow Amazon’s example and check their products for vulnerabilities that could compromise users’ privacy. Alexa has concerned us for a while now, given its ubiquity and connection to IoT devices. It’s these mega-digital platforms that present the biggest security risk and can hurt us the most. Therefore, their security levels are of crucial importance.”
Check Point says it reported the issue to Amazon in June 2020, with the company fixing the flaw soon after.
“The security of our devices is a top priority, and we appreciate the work of independent researchers like Check Point who bring potential issues to us,” Amazon said in a statement to the BBC.
Owners of Amazon Echo devices have been warned that their systems may have been compromised due to a security flaw in the Alexa voice recognition service. Researchers from security firm Check Point found vulnerabilities in certain Amazon and Alexa subdomains that could have allowed outsider access to a user’s voice…
Recent Posts
- Victrola’s cheapest Sonos-compatible turntable is over half off today
- Amazon’s AI-heavy Alexa+ will be accessible on the web
- Live updates from Amazon’s 2025 AI Alexa event
- Lucid’s CEO steps down, as EV maker aims to double production
- iPhones are replacing ‘Trump’ with ‘racist’ during dictation – but Apple is fixing the problem
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010