Why voice squatting is the big smart speaker threat

All the big stories from the week

The week in smart home

Welcome to The Week in Smart Home, our round-up of the week's stories you might have missed.

This week we've got the results of a new study that highlights one of the more worrying security and privacy scenarios we've seen to date, when it comes to smart speakers. We also have details on Nest's service outage and the impending (lack of) carnage and, best of all, a video of a parrot who loves Alexa.

Have a great weekend.

Why voice squatting is the big smart speaker threat

Voice squatters big risk for smart speaker security

We’ve heard a lot about the security and privacy concerns about smart speakers, but a new study detailed on ThreatPost has found what could be the biggest threat to date. It’s called “voice squatting” and essentially picks up on the ambiguities of the way we use our voices for search.

The study set up bogus Alexa skills and Google Actions, hoovering up slight nuances in people’s commands. Instead of installing a skill by saying “Alexa, start Capital One” (a banking skill), the team set up bogus skills installed by “Alexa, start Capital Won” or “is start Capital One Please”.

“We registered five skills with Amazon and one with Google. All these skills passed the Amazon and Google’s vetting process,” reads the whitepaper.

Once the user has installed the skill, the team were able to start controlling that device:

This involved “yielding control to another skill or service, yet continue to operate stealthily to impersonate these targets and get sensitive information from the user,” the paper continued.

The whitepaper also outlined a known attack called voice masquerading. This exploits how Alexa and Google Assistant can indefinitely keep a skill running, as long as it’s picking up audio. While that skill is running it’s allowed to record your conversations, as the background voices track Alexa/Assistants kill timings. It’s a small window into how someone could turn a smart speaker into a fairly feasible recording device.

Why voice squatting is the big smart speaker threat

Nest goes down, nothing bad happened

It was red faces at Nest this week, as services experienced a three hour outage that rendered its smart home devices unresponsive. Much has been made of the outage, which lasted significantly longer than the SmartThings one earlier this year.

Yes, doors could no longer be remotely unlocked, cameras were offline and doorbells weren’t sending video to smartphones – but to a certain extent it was a success. Most critical devices have fail safes, so locked doors remained locked (and openable with a key), and thermostats were still controllable manually. It’s not great PR, but everything behaved the way it was supposed to – and service was quickly restored.

Why voice squatting is the big smart speaker threat

Google Home Max latency slashed

Google has slashed the latency of its Google Home Max speaker by a whopping 93%, opening up brand new use cases for the smart speaker. Anyone hooking their Max up for soundbar-type functionality would have been mightily disappointed by the lag between audio and video – but with latency slashed from 550 to 39 milliseconds. A victory for AV heads – and you can thank The Next Web.

Why voice squatting is the big smart speaker threat

HP all-in-one Alexa PC lands

Alexa is rolling out into Windows 10 – but the all new HP Envy Curved AiO all-in-one has built Amazon’s assistant into the hardware, and The Verge got some hands on time. The base of this swanky-looking has a blue light offering the usual visual feedback for engaging with Alexa, and has the voice assistant app pre-installed. There’s no detail on price or exact release date yet.

Parrot 4 Alexa 4eva

It’s the ultimate “and finally” story – so we left it until last. Using voice assistants is so easy that even this parrot has got to grips with it. Buddy, the African Grey from Florida, has learned to turn the lights on and off – and seems quite affectionate to his voice assistant friend – he even tells Alexa “I love you” at the end.


Smart home deals of the week

Deals of the Week

Nest Thermostat - Save $45
Nest Thermostat - Save $45
Amazon
$204.99
Echo Plus & Hue Bulb - $14.99 off
Echo Plus & Hue Bulb - $14.99 off
Amazon
$$149.99
Wemo Light Switch - 22% off
Wemo Light Switch - 22% off
Amazon
$38.90
iRobot Roomba 960 - Save $150
iRobot Roomba 960 - Save $150
Amazon
$548.75

The Ambient may get a commission


TAGGED   smart home

What do you think?

Reply to
Your comment