Skip to main content

White-hat Chinese hackers turn Alexa into a spy, briefly

This won’t come as any surprise to those of you who put tape over your laptop’s cameras, but Alexa might not be 100 percent secure. This week at the Def Con Hacking Conference in Las Vegas, researchers from the Chinese conglomerate Tencent Holdings disclosed that they were able to use a modified Amazon Echo to hack into another Echo running on the same network. The researchers were not only able to take full control over the secondary device but also silently record and transmit audio to a third party, essentially turning the smart speaker into great big bugging devices, as reported by Wired.

If you’re feeling the slightest bit paranoid right now, cool your jets. These white-hat hackers have already informed Amazon of the exploit and the company rolled out security fixes last month.

Recommended Videos

Researchers Wu Huiyu and Qian Wenxiang also explained that their technique involved far more than a straight-up remote hack, fortunately. First, they had to drastically modify a standard Echo by removing a flash memory chip, modify its firmware to get root access, and solder the chip back to the circuit board. Sure, this involves little more than a little engineering knowledge and some things from RadioShack but it’s still not something your average spy is likely to have on hand.

However, once they placed their rogue device on the same network as other Echo devices, they could use Amazon’s proprietary communication protocols plus some undiscovered Alexa interface flaws (address redirection, cross-site scripting, and web encryption downgrades) to gain full access over the device. They could, for a more banal example, play any sound they wanted to. Or, they could silently record and transmit every single sound in the room, including conversations in adjacent rooms.

When we extend the logic, that means that an espionage outfit could simply replace a single Amazon smart speaker in a hotel’s network and take complete command over every smart speaker on the network. Sleep tight.

“After several months of research, we successfully break the Amazon Echo by using multiple vulnerabilities in the Amazon Echo system, and [achieve] remote eavesdropping,” the hackers said in a statement to Wired. “When the attack [succeeds], we can control Amazon Echo for eavesdropping and send the voice data through the network to the attacker.”

In addition to noting that the Alexa interface flaws have been patched, Amazon stressed that this particular hack requires a malicious actor to take physical access over at least one device.

This is just the latest in a series of attempts to crack the smart speaker’s security platform. Last year, British hacker Mark Barnes was able to install malware on an Echo via metal contacts accessible under the speaker’s rubber base. The security firm Checkmarx also revealed a potentially dangerous security flaw earlier this year when it hacked Alexa’s recording function via malware on a seemingly innocuous calculator app.

Clayton Moore
Clayton Moore’s interest in technology is deeply rooted in the work of writers like Warren Ellis, Cory Doctorow and Neal…
Amazon Alexa aims to streamline the EV charging experience
Amazon Alexa lists EV charging station locations on a vehicle touchscreen.

While the number of EV charging stations continues to grow, finding a station and paying for charging can still be a hassle. But soon you'll be able to simply ask Alexa.

At CES 2023, Amazon announced Alexa-enabled charging services that will let EV drivers find a charging station via Alexa, as well as pay for charging at certain stations when they become available to drivers in the U.S. later in 2023. You'll need a car with Alexa integration or an accessory like one of Amazon's Echo Auto devices, however.

Read more
The best Alexa skills to use on your Amazon Echo in 2023
Amazon Echo Show 15 Smart Display on a wall.

Your Alexa-enabled device is a standout gateway into the world of smart home automation. Using voice commands and the intuitive Alexa companion app, Alexa owners can control web-connected devices like smart security cameras, door locks, and A/V hardware like the Amazon Fire Stick 4K Max. In addition to schedule management and other great features, did you know that Alexa is capable of many "skills" too?

Alexa skills are small, free apps (though a few do have a subscription fee) you can download to add functionalities to your smart devices. You can install skills to use voice commands to call Lyft, get Alexa to read you a bedtime story, or turn Alexa into a cooking assistant.

Read more
The best Amazon Echo tips and tricks
Echo 4th Gen on table.

Amazon Echo devices are some of the most popular smart home hubs on the market. These feature-rich, Alexa-powered smart speakers can do it all -- from playing music and dimming your lights to controlling your home security system and checking your calendar, Alexa makes it easy to automate your daily tasks.

While most Echo users know the basics, there are a lot of incredible features that are hidden below the surface. That’s why we’ve put together this guide. Read on to uncover some impressive features across the Echo lineup and make full use of its versatility.
Change Alexa's name or create a nickname for her to call you
Once you've got your Alexa device up and running on your Wi-Fi network, there are still a few more things you might want to do before diving in, so be sure to head over to echo.amazon.com or download the accompanying smartphone app.

Read more