Skip to main content

Amazon has fixed a bug that allowed hackers to listen in on Alexa devices

Image used with permission by copyright holder

One of the most convenient things about Amazon’s Echo smart speaker is that Alexa is always ready to listen to your commands. However, a team from the Checkmarx, a security testing firm, wanted to see if that always-on feature could turn the gadget into a hacking device — and it turns out the answer was yes.

Checkmarx was able to create a skill that allowed hackers to listen in on Echo devices and their users’ conversations. Amazon fixed the problem earlier this month, but the incident serves as a cautionary tale as our homes become more connected and voice assistant speakers become more common.

Recommended Videos

Here’s how Checkmarx did it: Ordinarily, Alexa stops listening after it carries out your command and doesn’t start again until you say the “Alexa” wake word. However, the researchers figured out that hackers could take advantage of Alexa’s “re-prompt” feature. If Alexa doesn’t understand what you say the first time, she lets you know that and keeps listening until you repeat yourself.

Checkmarx’s researchers found it would be possible for hackers to develop an Alexa skill that made the virtual assistant continue to listen despite initially understanding a command. They were also able to mute the follow-up Alexa gives, when she asks users to repeat a prompt, thereby making the speaker stay silent but continue to listen. The next part of the Checkmarx hack involved orchestrating a way for Alexa not only to keep listening without people realizing it, but also to transcribe what she heard. Amazon’s servers store the audio content of people when they are speaking to Alexa.

Usually, developers who make skills get transcriptions of those conversations as long as spoken words are in the context of the skill. In this case, Checkmarx’s team made the skill record any word that was part of Alexa’s built-in dictionary.

Users have plenty of security considerations to worry about when it comes to cloud stored-data. With that in mind, Checkmarx’s researchers wanted to ensure their findings held true in real life. They created a seemingly innocent calculator skill that made Alexa keep listening for over a minute until someone from Checkmarx told it to stop. People in the room talked as the skill kept running. They found that, sure enough, the dialogue got captured in a word-for-word transcript, effectively giving a person the ability to “eavesdrop” by reading the text.

Checkmarx reached out to Amazon to tell the company about the device’s flaw earlier this month, and Amazon fixed the problem on April 10.

Amit Ashbel, Checkmarx’s director of product marketing, said Amazon shortened the amount of time Alexa continues to listen and removed the ability to silence Alexa’s reprompting dialog. Those adjustments make it impossible to re-create the hack. Amazon did not comment on the hack.

If you’re worried about Alexa listening in on you, you can always go into the app and delete your history.

Kayla Matthews
Former Digital Trends Contributor
Kayla Matthews has written about smart homes and technology for Houzz, Dwell, Curbed and Inman. She is a senior writer for…
The Amazon Echo Hub is almost the whole-home hub I’ve always wanted
Amazon Echo Hub.

I’ve long dreamed about having a proper sort of home hub. One that’s always on, always showing me the things I want to control at any given time. Not huge. Not obtrusive.

The new Amazon Echo Hub, one several new Echo devices announced at Amazon's 2023 devices event at HQ2 in Arlington, Virginia, very much seems to fit that bill. It’s a touchscreen that you’ll use to control all your things.

Read more
Everything announced at Amazon’s fall 2023 devices event
The Amazon Echo Show 8 at the Devices Event 2023.

The leaves are starting to turn color, and you know what that means: Amazon's annual fall Devices and Services event is upon us, bringing with it a veritable smorgasbord of product announcements, from new Fire TV streaming gadgets and Echo devices to Amazon smart home gear like Blink and Ring cameras, as well as Eero Wi-Fi routers and Alexa galore.

Taking place Wednesday, September 20, from Amazon's shiny new HQ2 second headquarters in the Crystal City neighborhood of Arlington, Virginia, the invite-only event was heavy on themes of generative AI and its use in the home, specifically how it relates to its own products. Dave Limp, Amazon's outgoing senior vice president of devices and services, delivered his last keynote, spilling the details on Alexa's most significant AI upgrade yet. Limp revealed its all-new advanced large language model (LLM), which will make the smart assistant more intuitive, conversational, and able to understand more complex nomenclature and nuances. And it's all integrated with Amazon's Alexa devices throughout your smart home.

Read more
At long last, Amazon brings AI features to Alexa
Amazon SVP of Devices and Services Dave Limp demonstrates the Let's Chat feature of Alexa, powered by AI.

Nearly a year after ChatGPT introduced the world to the uncannily human possibilities of generative AI, Amazon has unveiled new Alexa features powered by large language models (LLM). At the annual Amazon Devices Event hosted at its new Arlington, Virginia, headquarters, the company announced some major Alexa improvements that will attempt to make replies much more conversational and lifelike, with less waiting time between your interactions and more meaningful replies.

A new feature called Let's Chat mimics the ChatGPT experience by allowing you to have a fluid conversation with Alexa, asking questions about everything from the voice assistant's football team allegiance to recipes. You can even ask it to write emails for you. In the demo with Dave Limp, outgoing senior vice president of devices and services, Alexa sometimes stalled and needed a second prompt to answer questions, suggesting the feature may still need some polish.

Read more