Researchers already found a way to fool Amazon Key and shut off your camera

amazon key hack news camera
It sounded too good to be true from the start: A lock that allowed deliverymen and service providers in without a key, all while promising to be perfectly safe and monitorable. We’re talking, of course, about Amazon Key, a system that allows folks into your home once they have scanned a unique barcode. We called it “invasive and creepy” once it was announced and now that a report from Wired suggests the system can be hacked, our opinion seems further justified.

A team of security researchers from Seattle-based Rhino Security Labs demonstrated that Amazon Key and its companion Cloud Cam could be disabled and frozen, allowing just about anyone to waltz into your home. If the system is thus disarmed, even if you’re watching a “live” stream, you wouldn’t see anything out of the ordinary. This wasn’t just an unfounded claim — when Wired told Amazon about the new security research, the company noted that it would issue a software patch to fix the problem “later this week.”

So how exactly would an attack work? According to Rhino, a delivery person would first have to gain legitimate access, unlocking your door with the Amazon Key app. But instead of relocking the door with their app, they could simply run a program either on a computer or on a handheld device built with a Raspberry Pi and an antenna that would deauthorize the Cloud Cam. Rather than going dark, the Cloud Cam would simply continuously show the last frame recorded before it was deauthorized. That means that the attacker, or anyone else, would go undetected.

To be fair, the likelihood of such an attack is rather slim. An attacker would have to be authorized to deliver a package at a certain address and time, regardless of whether or not the Cloud Cam were switched on or off. “Every delivery driver passes a comprehensive background check that is verified by Amazon before they can make in-home deliveries, every delivery is connected to a specific driver, and before we unlock the door for a delivery, Amazon verifies that the correct driver is at the right address, at the intended time,” Amazon pointed out. So unless a delivery person had a longstanding plan to do something nefarious, the whole scenario is rather unlikely. All the same, Amazon noted in a statement, “We currently notify customers if the camera is offline for an extended period. Later this week we will deploy an update to more quickly provide notifications if the camera goes offline during delivery.”

amazon cloud cam review header temp

Perhaps more concerning, however, is the fact that when a Cloud Cam is disabled, the Amazon Key is also disconnected. After all, the lock doesn’t maintain its own internet connection, as it relies upon the “Zigbee wireless protocol to the Cloud Cam, which acts as its connection to the Wi-Fi router and the rest of the internet,” Wired reports. This means that a potential thief could just follow a delivery person, and send the deauthorization command as the delivery is completed. Then, once is the coast is clear, the criminal could simply walk through the unlocked door.

Of course, this would involve a delivery person not paying attention to whether or not the door locked behind him or her, and Amazon notes that it instructs drivers not to leave a house if the door is unlocked. Plus, Amazon is also supposed to call a customer if a door is left unlocked for more than a few minutes.

Cars

Mercedes wants to turn your car into a comfortable shopping mall on wheels

Mercedes-Benz designed its MBUX infotainment system with e-commerce in mind. Motorists can upgrade compatible cars via an over-the-air software updating system, but the brand wants to take this technology to the next level.
Product Review

Gate’s Smart Lock is locked and loaded but ultimately lacks important basics

In a world of video cameras and doorbells comes the Gate Smart Lock, a lock with a video camera embedded. It’s a great idea, but lacks some crucial functionality to make it a top-notch product.
Mobile

Free yourself! How to unlock a phone from the icy hands of your wireless carrier

Do you want to know how to unlock a phone through your carrier or a third-party service like DoctorSIM? Regardless of which way you want to go, we've compiled a list of requirements and methods for doing so.
Mobile

How to use Samsung's Bixby assistant for all of your smartphone tasks

Samsung Bixby is a powerful tool, but not the most intuitive one we've encountered. Here's how to set up and use every feature of Samsung's digital assistant, as well as what to expect in the future.
Smart Home

Whatever happened to those dumb smart products we wrote about in 2017?

A smart salt dispenser? As manufacturers rush to get the next new smart item out there, we wonder if all these new inventions are really necessary. Here’s a list of 10 of the quirkiest home smart gadgets available, and where they are now.
Smart Home

Lutron’s Fan Control makes ceiling fans smart, but has some turnoffs

Lutron recently came out with a smart switch that controls ceiling fans, the Lutron Caseta Fan Speed Control Switch. How does it stack up? Here's a first-hand review of the Lutron Fan Control switch.
Emerging Tech

Awesome Tech You Can’t Buy Yet: Write music with your voice, make homemade cheese

Check out our roundup of the best new crowdfunding projects and product announcements that hit the web this week. You may not be able to buy this stuff yet, but it sure is fun to gawk!
Cars

Amazon and Kia team up to simplify EV home-charging station installs

Kia Motors announced a new program with Amazon for electric vehicles. Customers planning to purchase a new Kia EV or PHEV can check out recommended Level 2 240-volt home charging stations and arrange installation in their homes.
Smart Home

Traeger’s latest wood-pellet grills are smoky, smart, and spacious

Traeger is famous in the world of barbecue and heavy-duty grills for its signature pellet grills and now the company is expanding this year by adding three new brands of redesigned
Smart Home

The five best teeth-whitening kits you can buy on Amazon

Teeth whitening can have a major impact on a person’s smile and overall appearance. You don't necessarily have to go to the dentist to get your teeth whitened though. Here are the best teeth-whitening kits you can buy.
Smart Home

Is your Keurig making gross coffee? Might be time for a cleaning

No one likes a dirty, scaled, or smelly Keurig, but how are you supposed to clean them? Before you throw yours out the window, here is a quick guide on cleaning your machine out thoroughly.
Smart Home

Which is better, the original Echo or the Echo Dot? We compare them

Amazon Echo vs. Dot: Having Alexa answer your questions is nothing short of futuristic, but which device should you get? There are some big differences between the two, especially in size, sound, and cost.
Smart Home

Viral porch pirate videos freak people out, cause unrealistic concern

Viral porch pirate videos convince others crime is more prevalent than facts indicate. According to polls, even though FBI reports show property crime rates are at historic lows, more people worry about crime today than ever before.
Smart Home

Sony’s Aibo robot dog can now patrol your home for persons of interest

Sony released the all-new Aibo in the U.S. around nine months ago, and since then the robot dog has (hopefully) been melting owners' hearts with its cute looks and clever tricks. Now it has a new one up its sleeve.