Amazon Echo and Google Home ‘Smart Spies’
Berlin-based Security Research Labs (SRL) discovered possible hacking flaws in Amazon Echo (Alexa) and Google Home speakers and installed their own voice applications to demonstrate hacks on both device platforms that turned the assistants into ‘Smart Spies’.
What Happened?
Research by SRL led to the discovery of two possible hacking scenarios that apply to both Amazon Alexa and Google Home which can enable a hacker to phish for sensitive information in voice content (vishing) and eavesdrop on users.
Knowing that some of the apps offered for use with Amazon Echo and Google Home devices are made by third parties with the intention of extending the capability of the speakers, SRL was then able create its voice apps designed to demonstrate both hacks on both device platforms. Once approved by both device platforms, the apps were shown to successfully compromise the data privacy of users by using certain ‘Skills and actions’ to both request and collect personal data including user passwords by eavesdropping on users after they believed the smart speaker has stopped listening.
Amazon and Google Told
SRL’s results and the details of the vulnerabilities were then shared with Amazon and Google through a responsible disclosure process. Google has since announced that it has removed SRL’s actions and is putting in place mechanisms to stop something similar happening in future. Amazon has also said that it has blocked the Skill inserted by SRL and has also put in preventative mechanisms of the future.
What Did SRL’s Apps Do?
The apps that enabled the ‘Smart Spy’ hacks took advantage of the “fallback intent”, in a voice app (the bit that says I’m sorry, I did not understand that. Can you please repeat it?”), the built-in stop intent which reacts to the user saying “stop” (by changing the functionality of that command after the apps were accepted), and leveraged a quirk in Alexa’s and Google’s Text-to-Speech engine that allows inserting long pauses in the speech output.
Examples of how this was put to work included:
- Requesting the user’s password through a simple back-end change by creating a password phishing Skill/Action. For example, a seemingly innocent application was created such as a horoscope. When the user asked for it, they were given a false error message e.g. “it’s not available in your country”. This triggered a minute’s silence which led to the user being told “An important security update is available for your device. Please say start update followed by your password.” Anything the user said after “start” was sent to the hacker, in this case, thankfully, SRL.
- Faking the Stop Intent to allow eavesdropping on users. For example, when a user gave a ‘stop’ command and heard the ‘Goodbye’ message, the app was able to continue to secretly run and to pick up on certain trigger words like “I” or words indicating that personal information was about to follow, i.e. “email”, “password” or “address”. The subsequent recording was then transcribed and sent back to SRL.
Not The First Time
This is not the first time that concerns have been raised about the spying potential of home smart speakers. For example, back in May 2018, A US woman reported that a private home conversation had been recorded by her Amazon’s voice assistant, and then sent it to a random phone contact who happened to be her husband’s employee. Also, as far back as 2016, US researchers found that they could hide commands in white noise played over loudspeakers and through YouTube videos in order to get smart devices to turn on flight mode or open a website. The researchers also found that they could embed commands directly into recordings of music or spoken text.
Manual Review Opt-Out
After the controversy over the manual, human reviewing of recordings and transcripts taken via the voice assistants of Google, Apple and Amazon, Google and Apple had to stop the practice and Amazon has now added an opt-out option for manual review of voice recordings and their associated transcripts taken through Alexa.
What Does This Mean For Your Business?
Digital Voice Assistants have become a popular feature in many home and home-business settings because they provide many value adding functions in personal organisation, as an information point and for entertainment and leisure. It is good news that SRL has discovered these possible hacking flaws before real hackers did (earning SRL some good PR in the process), but it also highlights a real risk to privacy and security that could be posed by these devices by determined hackers using relatively basic programming skills.
Users need to be aware of the listening potential of these devices, and of the possibility of malicious apps being operated through them. Amazon and Google may also need to pay more attention to the reviewing of third party apps and of the Skills and Actions made available in their voice app stores in order to prevent this kind of thing from happening and to close all loopholes as soon as they are discovered.
Tech Tip – Create Calendar Events Directly From the Taskbar
One of the new features added to Windows 10 with the September (1909) update was to enable Calendar users to be able to simply create a Calendar event directly from the Calendar flyout on the Taskbar.
To add quickly and easily add your Calendar event:
– Click on the date and time at the lower right corner of the Taskbar to open the Calendar flyout.
– Pick your desired date and type your text box to identify your event.
– Use the Inline options to set a time and location.
– And that’s it!
Google’s Chrome To Block Mixed Content Pages Without HTTPS
Google has announced that in a series of steps starting in Chrome 79, all mixed content will gradually be blocked by default.
What Is Mixed Content?
Mixed content refers to the insecure http:// sub-resources that load into https:// pages, thereby creating a possible way in for attackers to compromise what appears to be a secure web page. For example, this could be any audio, video, and images that are loaded insecurely from HTTP but appear as part of an HTTPS page when it loads. Many browsers are already able to block other types of mixed content by default such as scripts and iframes.
Why Worry?
Mixed content from a non-secure source poses privacy and security risks and could provide a way for attackers to spread misinformation. For example, an attacker could alter a chart to mislead viewers or could hide a tracking cookie in a mixed resource load. Also, the mix of secure and insecure content in a page could confuse browser security UX. Google’s own research shows that Mobile devices account for the majority of unencrypted end-user traffic.
What Does HTTPS Do?
HTTPS provides a secure, encrypted channel for web connections that can protect users against issues such as eavesdroppers, man-in-the-middle attacks and hijackers spoofing a trusted website. The kind of encryption offered by HTTPS stops interception of your information and ensures the integrity of the information that you send and receive.
Older hardware and software can pose a privacy and security risk because it often doesn’t support modern encryption technologies.
Progress
Progress has been made to make web browsing more secure with the move towards the full introduction of HTTPS, and Google is keen to point out that Chrome users now spend over 90% of their browsing time on HTTPS on all major platforms.
Google now sees its next task as ensuring that HTTPS configurations across the web are secure and up to date.
Roll-Out In Steps
Google says that the roll-out of its blocking of mixed content will happen in a series of steps starting with the release of Chrome 79 (in December 2019) with its new setting to unblock mixed content on specific sites. Next, Chrome 80 (due for release in January 2020) will auto-upgrade mixed audio and video resources to https://. Chrome 80 will display a “Not Secure” chip in the Omnibox for mixed images.
What Does This Mean For Your Business?
The introduction of measures to display warnings about and to block mixed content will put pressure on some businesses to clean up their web pages and make it more difficult for cyber-criminals to find a way through browser security. This is good news for businesses and web users alike.
It should be remembered, however, that secure websites with encrypted connections can still be harmed by certain cryptographic weaknesses e.g. due to external or related-domain hosts, so it’s important for businesses and individuals to keep up to date with software patches and fixes.
Local Authorities Facing 800 Cyber Attacks Per Hour
Figures gathered by insurance broker Gallagher – through the Freedom of Information (FoI) Act – have shown that UK local authorities were hit by an average of 800 cyber-attacks every hour in the first six months of this year.
Problem Could Be Bigger Than Figures Show
The figures, which were based upon the 203 (out of 408) local authorities that responded, showed that there were more than 263 million incidents in the first six months of 2019. This could mean that even though 76 local authorities reported a cyber-attack between January and June 2019, the fact that only half of UK local authorities responded to the FoI request could mean that the problem may be proportionately much worse than even these figures show.
What Kind of Attacks?
Gallagher’s collected information shows that since the beginning of 2017, 17 of the attacks reported by respondents related to loss of data or money, with an average cost to the victim of around £430,000. Gallagher’s figures also show that only 13% of councils have a standalone cyber insurance policy, meaning that most councils are risking potentially heavy fines under GDPR for any breaches.
Why A Target?
Local authorities and other public sector organisations are attractive targets to cyber-criminals because they hold large quantities of personal data and, perhaps due to a lack of funding and/or getting the most out of IT spending, they may be running older, less secure systems. Also, they have a large number of employees who may lack education about an training in data and cyber-security.
Education A Target
Universities, colleges and schools are also targets for cyber-criminals because they tend to have large numbers of users spread across many different departments, different facilities and faculties, and data is moved between these, thereby making admin and IT security very complicated. Also, universities have a lot of valuable intellectual property as well as student and staff personal data within their systems which are tempting targets for hackers.
Back in July, for example, Lancaster University, which offers a GCHQ accredited cyber-security course and has its own Cyber Security Research Centre was hit by a phishing attack, resulting in the leak of the personal data of new university applicants. Also, in 2018, The Information Commissioner (ICO) fined the University of Greenwich £120,000 for a data breach that left the personal details of thousands of students exposed online.
A National Cyber Security Centre report recently revealed that the UK’s universities lost almost £150m from cyber-attacks in the first six months of 2018 alone.
Lost Mobile Devices
Lost mobile devices, many of which may provide access to cloud-based data, are also known to be a problem for government bodies. For example, an FoI request in July by MobileIron found that government staff had lost 508 mobile and laptop devices between January and April 2019.
What Does This Mean For Your Business?
These figures make worrying reading, especially at a time when council budgets are very limited. Local authorities are already facing serious decisions about what to prioritise in terms of investment, but GDPR and a duty to protect the privacy and security of local authority customers and staff should mean that data security is kept high up the agenda. Part of maximising the value of investments in data security for local authorities should include ensuring that training and software are put in place to enable a more proactive approach to attack prevention and that staff are educated about threats, and how to spot (and what to do with) suspicious communications by email, social media or other means.
Gallagher’s figures may also serve as a reminder to local authorities that it may be a good idea to make sure, in the light of the sheer number of threats (only one of which needs to get through), that they have a good cyber insurance policy in place.
AI and the Fake News War
In a “post-truth” era, AI is one of the many protective tools and weapons involved in the battles that male up the current, ongoing “fake news” war.
Fake News
Fake news has become widespread in recent years, most prominently with the UK Brexit referendum, the 2017 UK general election, and the U.S. presidential election, all of which suffered interference in the form of so-called ‘fake news’ / misinformation spread via Facebook which appears to have affected the outcomes by influencing voters. The Cambridge Analytica scandal, where over 50 million Facebook profiles were illegally shared and harvested to build a software program to generate personalised political adverts led to Facebook’s Mark Zuckerberg appearing before the U.S. Congress to discuss how Facebook is tackling false reports. A video that was shared via Facebook, for example (which had 4 million views before being taken down), falsely suggested that smart meters emit radiation levels that are harmful to health. The information in the video was believed by many even though it was false.
Government Efforts
The Digital, Culture, Media and Sport Committee has published a report (in February) on Disinformation and ‘fake news’ highlighting how “Democracy is at risk from the malicious and relentless targeting of citizens with disinformation and personalised ‘dark adverts’ from unidentifiable sources, delivered through the major social media platforms”. The UK government has, therefore, been calling for a shift in the balance of power between “platforms and people” and for tech companies to adhere to a code of conduct written into law by Parliament and overseen by an independent regulator.
Fact-Checking
One way that social media companies have sought to tackle the concerns of governments and users is to buy-in fact-checking services to weed out fake news from their platforms. For example, back in January London-based, registered charity ‘Full Fact’ announced that it would be working for Facebook, reviewing stories, images and videos to tackle misinformation that could “damage people’s health or safety or undermine democratic processes”.
Moderation
A moderator-led response to fake news is one option, but its reliance upon humans means that this approach has faced criticism over its vulnerability to personal biases and perspectives.
Automation and AI
Many now consider automation and AI to be an approach and a technology that are ‘intelligent’, fast, and scalable enough to start to tackle the vast amount of fake news that is being produced and circulated. For example, Google and Microsoft have been using AI to automatically assess the truth of articles. Also, initiatives like the Fake News Challenge (http://www.fakenewschallenge.org/) seeks to explore how AI technologies, particularly machine learning and natural language processing, can be leveraged to combat fake news, and supports the idea that AI technologies hold promise for significantly automating parts of the procedure human fact-checkers use to determine if a story is real or a hoax.
However, the human-written rules underpinning AI, and how AI is ‘trained’ can also lead to bias.
Deepfake Videos
Deepfake videos are an example of how AI can be used to create fake news in the first place. Deepfake videos use deep learning technology and manipulated images of target individuals (found online), often celebrities, politicians, and other well-known people to create an embarrassing or scandalous video. Deepfake audio can also be manipulated in a similar way. Deepfake videos aren’t just used to create fake news sources, but they can also be used by cyber-criminals for extortion.
AI Voice
There has also been a case in March this year, where a group of hackers were able to use AI software to mimic an energy company CEO’s voice in order to steal £201,000.
What Does This Mean For Your Business?
Fake news is a real and growing threat, as has been demonstrated in the use of Facebook to disseminate fake news during the UK referendum, the 2017 UK general election, and the U.S. presidential election. State-sponsored politically targeted campaigns can have a massive influence on an entire economy, whereas other fake news campaigns can affect public attitudes to ideas and people and can lead to many other complex problems.
Moderation and automated AI may both suffer from bias, but at least they are both ways in which fake news can be tackled, to an extent. Through adding fact-checking services, other monitoring, and software-based approaches e.g. through browsers, social media and other tech companies can take responsibility for weeding out and guarding against fake news.
Governments can also help in the fight by putting pressure on social media companies and by collaborating with them to keep the momentum going and to help develop and monitor ways to keep tackling fake news.
That said, it’s still a big problem, no solution is infallible, and all of us as individuals would do well to remember that, especially today, you really can’t believe everything you read and an eye to source and bias of news coupled with a degree of scepticism can often be healthy.
PayPal Drops Out of Facebook’s Libra Cryptocurrency
PayPal has announced that it is not going to be a part of the Switzerland-based Libra Association that is overseeing the introduction of Facebook’s Libra cryptocurrency.
What Is Libra?
Libra is a cryptocurrency, designed and coded by Facebook, that will enable payments to be made by a special phone app and by messaging services such as WhatsApp so that spending the new currency could be as easy and fast as texting. Libra was announced as being targeted at the 1.7 billion adults worldwide who do not have a bank account (unbanked).
Unlike other cryptocurrencies such as Bitcoin, Libra will offer the security from massive value fluctuation by being asset-backed and pegged to other currencies and it will not have a traditional bank ‘middleman’, therefore enabling fast and frictionless transactions.
Units of Libra units can be purchased via Libra’s platforms and stored it in a digital wallet called “Calibra”.
Libra Association
The Libra Association, which PayPal has just left, is a 28-member (now 27) association of multinational companies and non-profits, hoping to grow to 100 or more members. The Libra Association, based in Switzerland will be responsible for the management of Libra and members of the Association include Mastercard, eBay, Spotify, Uber, Vodafone, and a variety of charities such as Women’s World Banking.
Why Has PayPal Left?
PayPal has not given a clear reason why it has left the Libra Association, but there is speculation among some commentators that it may be due to PayPal wanting to distance its brand from the fact that regulators, particularly in Washington and Brussels, appear to be concerned that the Libra project could be seen as a means to bypass rules relating to money laundering and tax evasion. There is also speculation that PayPal may have been concerned that Facebook executives haven’t paid attention to PR that could counter much of the initial criticism of Libra.
PayPal has said, however, that “We remain supportive of Libra’s aspirations and look forward to continued dialogue on ways to work together in the future”.
Others?
There are also press reports that other Association members such as Mastercard, Visa, and digital payment platform and processor Stripe may be considering leaving the Libra Association due to concerns about the suggestions that Libra could potentially be used for money laundering to tax evasion.
France Says No
In September, France’s finance minister, Bruno Le Maire, said that the development of Facebook’s Libra cryptocurrency will be blocked in Europe unless concerns over risks to consumers and to the monetary systems of countries can be addressed.
Warnings and Concerns
Back in July, finance chiefs from the Group of Seven democracies warned that cryptocurrencies like Libra would have to address “serious regulatory and systemic concerns” before they would be allowed. Also, President Trump has said in a Tweet that he isn’t a fan of Libra, and central bank chiefs, including Mark Carney have also expressed concerns about Libra.
Some sceptical commentators have also noted that Libra may be less about money and blockchain anyway but more about gathering more information about the identity of clients.
What Does This Mean For Your Business?
Libra is now coming under increased scrutiny, and the mention of phrases like ‘money laundering’ or ‘tax evasion’ appear to be enough to scare some of the big financial brands away from the Libra project, at least until regulators’ questions have been answered and the heat has died down. The fact that a big name like PayPal has pulled out, with other big names such as Mastercard and Visa looking likely to follow is undoubtedly going to be a big blow to the image and credibility of Libra, although the Libra Association still has 25+ other members and is hoping to grow this to include 100 or so other big names.
Countries and banks are clearly worried by the possible shift in control to big business that Libra could bring, and this shift in control could have a number of effects on the business environment and the economies of countries if Libra proves to be popular.
Even though Libra users are not intended to be businesses, if Libra does help the ‘unbanked’ this could have a knock-on effect in helping that segment of society to buy more goods and services, thereby helping businesses and the economy.