Skip to main content

White-hat Chinese hackers turn Alexa into a spy, briefly

This won’t come as any surprise to those of you who put tape over your laptop’s cameras, but Alexa might not be 100 percent secure. This week at the Def Con Hacking Conference in Las Vegas, researchers from the Chinese conglomerate Tencent Holdings disclosed that they were able to use a modified Amazon Echo to hack into another Echo running on the same network. The researchers were not only able to take full control over the secondary device but also silently record and transmit audio to a third party, essentially turning the smart speaker into great big bugging devices, as reported by Wired.

If you’re feeling the slightest bit paranoid right now, cool your jets. These white-hat hackers have already informed Amazon of the exploit and the company rolled out security fixes last month.

Researchers Wu Huiyu and Qian Wenxiang also explained that their technique involved far more than a straight-up remote hack, fortunately. First, they had to drastically modify a standard Echo by removing a flash memory chip, modify its firmware to get root access, and solder the chip back to the circuit board. Sure, this involves little more than a little engineering knowledge and some things from RadioShack but it’s still not something your average spy is likely to have on hand.

However, once they placed their rogue device on the same network as other Echo devices, they could use Amazon’s proprietary communication protocols plus some undiscovered Alexa interface flaws (address redirection, cross-site scripting, and web encryption downgrades) to gain full access over the device. They could, for a more banal example, play any sound they wanted to. Or, they could silently record and transmit every single sound in the room, including conversations in adjacent rooms.

When we extend the logic, that means that an espionage outfit could simply replace a single Amazon smart speaker in a hotel’s network and take complete command over every smart speaker on the network. Sleep tight.

“After several months of research, we successfully break the Amazon Echo by using multiple vulnerabilities in the Amazon Echo system, and [achieve] remote eavesdropping,” the hackers said in a statement to Wired. “When the attack [succeeds], we can control Amazon Echo for eavesdropping and send the voice data through the network to the attacker.”

In addition to noting that the Alexa interface flaws have been patched, Amazon stressed that this particular hack requires a malicious actor to take physical access over at least one device.

This is just the latest in a series of attempts to crack the smart speaker’s security platform. Last year, British hacker Mark Barnes was able to install malware on an Echo via metal contacts accessible under the speaker’s rubber base. The security firm Checkmarx also revealed a potentially dangerous security flaw earlier this year when it hacked Alexa’s recording function via malware on a seemingly innocuous calculator app.

Editors' Recommendations

Clayton Moore
Clayton Moore’s interest in technology is deeply rooted in the work of writers like Warren Ellis, Cory Doctorow and Neal…
Amazon to pay $30M in FTC settlements over Alexa, Ring privacy violations
Amazon logo on the headquarters building.

Amazon has agreed to pay $25 million to the Federal Trade Commission (FTC) to settle charges over privacy violations linked to its digital assistant, Alexa.

In a separate case, Amazon-owned Ring will pay $5.8 million for violations of users’ privacy.

Read more
What does the Amazon Echo yellow ring color mean?
Amazon Echo Dot (4th Gen) LED light ring

Amazon’s Echo devices come in all shapes and sizes -- including cylinders, orbs, and screens. But there’s one thing they all have in common: Every Echo houses the Alexa voice assistant and uses an LED indicator light to provide clues on what Alexa may be doing right now. On classic Echo speakers, this light took the form of a pulsing ring, which can change to different colors based on activity.

We’ve come across many Alexa users who have noticed that their Echo device has started showing a yellow ring and aren’t really sure what that means or what they should do about it. A yellow ring isn’t typically anything to worry about, but our FAQ will go over the details so you know what’s going on!
What does the yellow ring look like exactly?
Your Echo device will pulse a yellow color that will die down for a few seconds, then pulse again. This may or may not be accompanied by an audio alert, one that's easy to miss if no one is around paying attention, which is why it’s common to be surprised by a yellow pulse from your Echo.

Read more
The most common Echo Show problems and how to fix them
Amazon Echo Show 10.

If you're looking to add a smart display to your home, the Amazon Echo Show is a great option. Bringing the best of Alexa into the visual realm, the Echo Show allows you to tap into real-time video from your home's smart security system, have video calls with friends and family using Alexa's Drop In feature, stream from Hulu and Prime Video, run photo slideshows, and so much more.

But glitches happen, and the Echo Show is not without its small trail of troubles. Fortunately, many of these issues have straightforward fixes. In this deep dive, we'll be taking a look at the most common Echo Show problems and how you can fix them.
Echo Show screen is flickering

Read more