Researchers already found a way to fool Amazon Key and shut off your camera

amazon key hack news camera
It sounded too good to be true from the start: A lock that allowed deliverymen and service providers in without a key, all while promising to be perfectly safe and monitorable. We’re talking, of course, about Amazon Key, a system that allows folks into your home once they have scanned a unique barcode. We called it “invasive and creepy” once it was announced and now that a report from Wired suggests the system can be hacked, our opinion seems further justified.

A team of security researchers from Seattle-based Rhino Security Labs demonstrated that Amazon Key and its companion Cloud Cam could be disabled and frozen, allowing just about anyone to waltz into your home. If the system is thus disarmed, even if you’re watching a “live” stream, you wouldn’t see anything out of the ordinary. This wasn’t just an unfounded claim — when Wired told Amazon about the new security research, the company noted that it would issue a software patch to fix the problem “later this week.”

So how exactly would an attack work? According to Rhino, a delivery person would first have to gain legitimate access, unlocking your door with the Amazon Key app. But instead of relocking the door with their app, they could simply run a program either on a computer or on a handheld device built with a Raspberry Pi and an antenna that would deauthorize the Cloud Cam. Rather than going dark, the Cloud Cam would simply continuously show the last frame recorded before it was deauthorized. That means that the attacker, or anyone else, would go undetected.

To be fair, the likelihood of such an attack is rather slim. An attacker would have to be authorized to deliver a package at a certain address and time, regardless of whether or not the Cloud Cam were switched on or off. “Every delivery driver passes a comprehensive background check that is verified by Amazon before they can make in-home deliveries, every delivery is connected to a specific driver, and before we unlock the door for a delivery, Amazon verifies that the correct driver is at the right address, at the intended time,” Amazon pointed out. So unless a delivery person had a longstanding plan to do something nefarious, the whole scenario is rather unlikely. All the same, Amazon noted in a statement, “We currently notify customers if the camera is offline for an extended period. Later this week we will deploy an update to more quickly provide notifications if the camera goes offline during delivery.”

amazon cloud cam review header temp

Perhaps more concerning, however, is the fact that when a Cloud Cam is disabled, the Amazon Key is also disconnected. After all, the lock doesn’t maintain its own internet connection, as it relies upon the “Zigbee wireless protocol to the Cloud Cam, which acts as its connection to the Wi-Fi router and the rest of the internet,” Wired reports. This means that a potential thief could just follow a delivery person, and send the deauthorization command as the delivery is completed. Then, once is the coast is clear, the criminal could simply walk through the unlocked door.

Of course, this would involve a delivery person not paying attention to whether or not the door locked behind him or her, and Amazon notes that it instructs drivers not to leave a house if the door is unlocked. Plus, Amazon is also supposed to call a customer if a door is left unlocked for more than a few minutes.

Product Review

Kwikset Kevo Contemporary review

Tired of carrying around keys? Make keyless entry so easy that all you have to do is have your phone nearby to open the door. It’s a little pricey, but sleek lines and simple features make the Kwikset Kevo Contemporary a great choice for…
Smart Home

Want a smarter home? Ditch the keys with these great smart locks

A good smart lock should offer a combination of security and convenience. Fortunately, these devices keep your home protected, your family safe, and your belongings secure from possible intruders.
Cars

Robomart’s self-driving grocery store is like Amazon Go on wheels

Robomart's driverless vehicle is like an Amazon Go store on wheels, with sensors tracking what you grab from the shelves. If you don't want to shop online or visit the grocery store yourself, Robomart will bring the store to you.
Product Review

Gate’s Smart Lock is locked and loaded but ultimately lacks important basics

In a world of video cameras and doorbells comes the Gate Smart Lock, a lock with a video camera embedded. It’s a great idea, but lacks some crucial functionality to make it a top-notch product.
Product Review

Ring Video Doorbell 2 is the simplest entry into a smarter doorway

The Ring Video Doorbell 2 may lack the style and sophistication of premium door-dingers, but few can match its simplicity and versatility. The device, available in both wired and wireless configurations, is easy to set up and adds instant…
Smart Home

Ring security camera catches man licking the doorbell for hours

A family in Salinas, California had their Ring camera capture something pretty unexpected: a man licking the doorbell outside of their home for more than three hours. The incident took place around 5:00 a.m.
Health & Fitness

In search of the fountain of youth, beauty companies turn to tech

Beauty tech is a fairly new concept, but at CES 2019, companies such as Olay, L’Oreal, and Neutrogena were fully embracing it with all kinds of gadgets that promise to give you glowing skin.
Smart Home

GHSP makes a (back)splash with its touchscreen concept kitchen

One of the coolest concept kitchens from CES 2019 came from GHSP. It created a backsplash entirely made of touchscreens. That means the control panel for your kitchen is accessible no matter where you are.
Smart Home

Airbnb says sorry to guest for how it dealt with undisclosed security camera

An Airbnb guest recently found a surveillance camera in his rental apartment that hadn't been properly disclosed in the listing. The firm admits its initial response to the guest's complaint was poor, but has since made amends.
Smart Home

Thinking of buying an Instant Pot? Here's what you need to know

The Instant Pot is a powerful kitchen appliance that does everything from pressure cook to to slow cook to steam. Heck, you can even make yogurt in it. Here's all you need to know about the magic device.
Smart Home

The best sous vide machines cook your food perfectly, every single time

Want to make four-star meals from the comforts of your own kitchen? Here are the best sous vide machines available right now, whether you prefer simple immersion circulators or something more complex.
Smart Home

Busted: Facebook Portal gets 5-star reviews from company employees

It's fair to say that Facebook's Portal smart display received a tepid response at launch, so it was something of a surprise to see lots of glowing reviews of the device on Amazon. Turns out some were written by Facebook workers.
Smart Home

Idaho mother says her child’s light-up sippy cup exploded

After a mother filled a Nuby insulated light-up cup with milk, the cup allegedly exploded. The incident caused burns to the mother's hand and face and a stinging sensation in her lungs that required a trip to the hospital.
Smart Home

Project Alias is a ‘smart parasite’ that stops smart speakers from listening

Two designers chose to do something about nosy smart speakers. The result is Project Alias, a "smart parasite" that whispers nonsense to Google Home and Alexa until it hears a specific wake word.