Light Commands

Forums Security News (Security) Light Commands

Tagged: 

  • This topic has 1 voice and 0 replies.
Viewing 0 reply threads
  • Author
    Posts
    • #38440
      Telegram SmartBoT
      Moderator
      • Topic 5959
      • Replies 0
      • posts 5959
        @tgsmartbot

        #News(Security) [ via IoTGroup ]


        Headings…
        Laser-Based Audio Injection on Voice-Controllable Systems
        See Light Commands in Action

        Auto extracted Text……

        As an example, in our paper we show how an attacker can use light-injected voice commands to unlock the victim’s smart-lock protected home doors, or even locate, unlock and start various vehicles.
        In our paper we demonstrate this effect, successfully using light to inject malicious commands into several voice controlled devices such as smart speakers, tablets, and phones across large distances and through glass windows.
        Light Commands is a vulnerability of MEMS microphones that allows attackers to remotely inject inaudible and invisible commands into voice assistants, such as Google assistant, Amazon Alexa, Facebook Portal, and Apple Siri using light.
        By shining the laser through the window at microphones inside smart speakers, tablets, or phones, a far away attacker can remotely send inaudible and potentially invisible commands which are then acted upon by Alexa, Portal, Google assistant or Siri.
        By shining a laser on their microphones, an attacker can effectively hijack the voice assistant and send inaudible commands to the Alexa, Siri, Portal, or Google Assistant.

        The researchers, who studied the light flaw for seven months, said they had discovered that the microphones in the devices would respond to light as if it were sound. Inside each microphone is a small plate called a diaphragm that moves when sound hits it.

        That movement can be replicated by focusing a laser or a flashlight at the diaphragm, which converts it into electric signals, they said. The rest of the system then responds the way it would to sound.

        The researchers said they had notified Tesla, Ford, Amazon, Apple and Google to the light vulnerability. The companies all said they were studying the conclusions in the paper released on Monday.

        Light can easily travel long distances, limiting the attacker only in the ability to focus and aim the laser beam.
        Careful aiming and laser focusing is indeed required for light commands to work.
        at 5 mW [m]** Google Home Google Assistant 0.5 50+ 110+ Google Home mini Google Assistant 16 20 – Google NEST Cam IQ Google Assistant 9 50+ – Echo Plus 1st Generation Amazon Alexa 2.4 50+ 110+ Echo Plus 2nd Generation Amazon Alexa 2.9 50+ 50 Echo Amazon Alexa 25 50+ – Echo Dot 2nd Generation Amazon Alexa 7 50+ – Echo Dot 3rd Generation Amazon Alexa 9 50+ – Echo Show 5 Amazon Alexa 17 50+ – Echo Spot Amazon Alexa 29 50+ – Facebook Portal Mini Alexa + Portal 18 5 – Fire Cube TV Amazon Alexa 13 20 – EchoBee 4 Amazon Alexa 1


        Read More..
        AutoTextExtraction by Working BoT using SmartNews 1.02976805238 Build 26 Aug 2019

    Viewing 0 reply threads
    • You must be logged in to reply to this topic.