Skip to main content
  1. Home
  2. Phones
  3. Android
  4. Apple
  5. Mobile
  6. Web
  7. News

Hackers can control Google Now and Siri through your headphones

Add as a preferred source on Google

Many people love their voice assistants, whether it be Siri, Google Now, or Cortana. However, they may not be the most secure feature on your smartphone. As it turns out, it is possible to control both Siri and Google Now through silent radio signals from as far away as 16 feet. A pair of French information security researchers at ANSSI discovered the trick, Wired reports.

The scenario involves targeting a phone that has microphone-enabled headphones plugged into its headphone jack. The hackers use a laptop with the open-source GNU Radio software onboard, a USRP software-based radio, an amplifier, and an antenna to generate electromagnetic waves. The attacker can then exploit the headphone wire itself, simulating audio to make it seem as though it is coming from the microphone. From there, the attacker can control the phone remotely from as far as 16 feet away and ask the digital assistant to perform any action that it’s capable of doing. That includes making calls, navigating the Web, sending texts, and so on.

Recommended Videos

Hackers could even turn your phone into a listening device to spy on your communications, send the browser to a site with malware, or issue spam and phishing messages through your email and social media accounts. The simple brilliance of the hack shows once again how hackers can help expose problems with some of the most common and trusted technology.

Of course, the hack does have its limits. Hackers can only target phones that have microphone-equipped headphones or earbuds plugged in. It doesn’t work if users don’t have Google Now enabled from their lockscreens, or if they have Google Now programed to respond only to their voice. Now that Siri only responds to the voice of the phone’s owner in iOS 9 on the iPhone 6S, it won’t work on the new iPhones, either. Additionally, anyone who looks at their phone regularly would probably see unauthorized voice commands being carried out on their phone — it’s not exactly a discrete hack.

Regardless, the researchers have pointed out that it’s still a vulnerability that could be exploited easily, especially in public spaces where people congregate.

To protect users’ phones against hacks, the security community frequently recommends that users disable the voice-activated assistants from appearing on the default screen, though most people aren’t willing to sacrifice the convenience of the feature. Additionally, the researchers suggest that if Apple and Google allowed users to set their own activation word like the Moto X does, hackers wouldn’t be able to activate Siri or Google Now, unless they knew your specific name or phrase. Of course, that’s something the tech giants will have to consider — not the user. In regards to this particular headphone jack hack, the researchers suggest microphone cords with heavier shielding inside.

For some time, security advocates have been preaching about the hackable potential of our phone’s voice-activated digital assistants. Quite recently, an embarrassing hack of the iOS 9 lock screen involved tricking Siri into giving up contacts and other information. That flaw has since been fixed in a recent update, but the question of voice assistant hackability is still a serious one.

John Casaretto
Former Digital Trends Contributor
John is the founder of the security company BlackCert, a provider of SSL digital certificates and encryption products. A…
Google Photos adds a quick toggle between AI and classic search
Classic search is finally easier to reach for people who enabled Ask Photos
Google's Ask Photos debut.

Google Photos is giving users an easier way to leave its Gemini-powered search when a simple keyword would do. A new toggle now sits at the top of the results page, letting users switch between Ask Photos and classic search without digging through settings.

The change appears to address feedback from people who opted into Ask Photos but wanted a quicker way to return to classic search when Gemini was slower or less useful for a straightforward query.

Read more
Snapseed Camera now lets Android users save original photos and add geotags
Google updates Snapseed Camera with geotag support and non-destructive photo editing
Snapseed App

Google appears to be quietly turning Snapseed into something more than just a photo editing app. Over the past few weeks, the company has been steadily adding new capabilities to Snapseed Camera, its standalone camera app for Android. The latest update introduces two practical features that many smartphone users have come to expect from modern camera apps: the ability to save an untouched copy of every image for future editing and support for embedding location data directly into photos.

Neither feature is flashy, but together they make Snapseed Camera a more capable photography tool, particularly for users who like experimenting with filters without permanently altering their original shots. According to a report by 9to5Google, the features are rolling out with Snapseed Camera version 4.1.1.x on Android.

Read more
Samsung unveils Galaxy credit card ahead of Galaxy Unpacked
Samsung launches Galaxy Card with cashback on Galaxy purchases
Galaxy credit card

For years, Samsung has worked to turn Galaxy into more than a smartphone brand. Today, the company's ecosystem stretches across foldables, smartwatches, televisions, home appliances, smart home products and digital services. Now, it's adding another piece to that puzzle, one that has little to do with hardware.

Samsung has officially introduced the Samsung Galaxy Card, its first branded credit card in the U.S. Designed in partnership with Barclays US Consumer Bank and operating on the Visa network, the card rewards users for everyday spending while offering significantly higher cashback on purchases made directly through Samsung.

Read more