It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Alexa, can you send all your recordings to hackers? Alexa, can you send all your recordings to hackers?
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Alexa, can you send all your recordings to hackers?
Reply
 
Thread Tools
Old 19th August 2020, 06:49   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 148,797
Stefan Mileschin Freshly Registered
Default Alexa, can you send all your recordings to hackers?

Check Point makes charlies out of Amazon security

Israeli Security outfit Check Point have told Wired that Alexa's Web services had bugs that a hacker could have exploited to grab a target's entire voice history, meaning their recorded audio interactions with Alexa.

Amazon has patched the flaws, but the vulnerability could have also yielded profile information, including home address, as well as all of the "skills," or apps, the user had added for Alexa. An attacker could have even deleted an existing skill and installed a malicious one to grab more data after the initial attack.

For an attacker to exploit the vulnerabilities, they would need first to trick targets into clicking a malicious link, a common attack scenario. Underlying flaws in certain Amazon and Alexa subdomains, though, meant that an attacker could have crafted a genuine and normal-looking Amazon link to lure victims into exposed parts of Amazon's infrastructure. By strategically directing users to track.amazon.com -- a vulnerable page not related to Alexa, but used for tracking Amazon packages -- the attacker could have injected code that allowed them to pivot to Alexa infrastructure, sending a special request along with the target's cookies from the package-tracking page to skillsstore.amazon.com/app/secure/your-skills-page.

https://fudzilla.com/news/51368-alex...ngs-to-hackers
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
iOS 13.2 beta gives you more control over Siri recordings Stefan Mileschin WebNews 0 11th October 2019 11:58
Apple will still review Siri recordings, but only if you opt in Stefan Mileschin WebNews 0 29th August 2019 10:35
Amazon's new opt-out keeps people from 'reviewing' your Alexa recordings Stefan Mileschin WebNews 0 5th August 2019 09:02
Amazon sent private Alexa audio recordings to a random person Stefan Mileschin WebNews 0 24th December 2018 05:46
Alexa can send SMS messages using your voice Stefan Mileschin WebNews 0 4th February 2018 10:48
Sling TV’s improved DVR won’t delete your recordings Stefan Mileschin WebNews 0 16th June 2017 08:13
Sky Q smartphone app lets you take your recordings with you Stefan Mileschin WebNews 0 21st October 2016 05:43
UK's first cloud DVR lets you watch recordings anywhere Stefan Mileschin WebNews 0 15th August 2016 16:09
Mac keychain flaw can send your passwords to hackers via text Stefan Mileschin WebNews 0 3rd September 2015 07:07
Boxee TV web app gets autocompleting searches, revamped recordings view Stefan Mileschin WebNews 0 6th February 2013 08:31

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 04:58.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO