Hackers Can Silently Control Siri, Alexa & Other Voice Assistants Using Ultrasound


What if your smartphone starts making calls, sending text messages, and browsing malicious websites on the Internet itself without even asking you?This is no imaginations, as hackers can make this possible using your smartphone’s personal assistant like Siri or Google Now.A team of security researchers from China’s Zhejiang University have discovered a clever way of activating your voice recognition systems without speaking a word by exploiting a security vulnerability that is apparently common across all major voice assistants.DolphinAttack (Demo): How It WorksDubbed DolphinAttack, the attack technique works by feeding the AI assistants commands in ultrasonic frequencies, which are too high for humans to hear but are perfectly audible to the microphones on your smart devices.With this technique, cyber criminals can “silently” whisper commands into your smartphones to hijack Siri and Alexa, and could force them to open malicious websites and even your door if you have a smart lock connected.The attack works on every major voice recognition platforms, affecting every mobile platform including iOS and Android. So, whether you own an iPhone, a Nexus, or a Samsung, your device is at risk. The attack takes advantage of the fact that human ears generally can’t hear sounds above 20kHz. But the microphone software still detects signals above 20 kHz frequency.So, to demonstrate the DolphinAttack, the team first translated human voice commands into ultrasonic frequencies (over 20 kHz), then simply played them back from a regular smartphone equipped with an amplifier, ultrasonic transducer and battery—which costs less than $3.”DolphinAttack voice commands, though totally inaudible and therefore imperceptible to [a] human, can be received by the audio hardware of devices, and correctly understood by speech recognition systems,” the researchers explain in their research paper [PDF].DolphinAttack Makes Hacking Siri, Alexa & Google Now EasySince smartphone allows users to do a broad range of operation via voice commands like dialling a phone number, sending short messages, opening a web page, and setting the phone to the airplane mode, the researchers were able to order an iPhone to dial a specific number.However, according to the researchers, an attacker can send inaudible voice commands to instruct a device to perform several malicious tasks including:Visiting a malicious website—which can launch a drive-by-download attack or exploit the victim’s device with 0-day vulnerabilities.Spying—the attacker can instruct the victim’s device to initiate outgoing video or phone calls, thereby getting access to the image and sound of device surroundings.Injecting fake information—the attacker can instruct the victim’s device to send fake text messages or emails to publish fake online posts or add fake events to a calendar.Denial of Service—the attacker can inject commands to turn on the ‘airplane mode,’ thereby disconnecting all wireless communications and taking the device offline.Concealing attacks—since the screen display and voice feedback could expose the attacks, the attacker can decrease the odds by dimming the screen and lowering the volume to hide the attack.Typically, the signal sent out by the researchers was between 25 and 39kHz. As for range, the team managed to make the attack work maximum at 175cm, which is certainly practical. What’s scary? DolphinAttack works on just about anything including Siri, Google Assistant, Samsung S Voice, Huawei HiVoice, Cortana, and Alexa, on devices such as smartphones, iPads, MacBooks, Amazon Echo and even an Audi Q3—total 16 devices and 7 systems.What’s even worse? The inaudible voice commands can be accurately “interpreted by the SR [speech recognition] systems on all the tested hardware” and work even if the attacker has no direct access to your device and you have taken all the necessary security precautions.How to prevent DolphinAttacks?The team goes on to suggest device manufacturers make some hardware alterations to address this vulnerability simply by programming their devices to ignore commands at 20 kHz or any other voice command at inaudible frequencies.”A microphone shall be enhanced and designed to suppress any acoustic signals whose frequencies are in the ultrasound range. For instance, the microphone of iPhone 6 Plus can resist to inaudible voice commands well,” the researchers say.For end users, a quick solution to prevent such attacks is turning off voice assistant apps by going into settings, before an official patch lands for your device.How to disable Siri on iPhone, iPad, or iPod touch: Go to your iOS device’s Settings → General → Accessibility → Home Button → Siri and then toggle Allow “Hey Siri” to off.How to turn off Cortana: Open Cortana on your Windows PC, select the Notebook icon on the right side, click on Settings and then toggle “Hey Cortana” to off.How to turn off Alexa on Amazon Echo: Simply press the microphone on/off button on the top of the unit. When

Source: Hackers Can Silently Control Siri, Alexa & Other Voice Assistants Using Ultrasound

First Pakistani Anti Virus and Recovery Tool developed.


Although I am very much against the Windows system and have opted for Ubuntu system around two or three years back. More details about installing Ubuntu can be found here.(https://salmankhwaja.wordpress.com/tag/ubuntu/)

Official Ubuntu circle with wordmark. Replace ...

Image via Wikipedia

It is the work of those two young bright students who created their very own first PAKISTANI ANTI VIRUS cum RECOVERY software known as “Instant Virus Killer“. They say, their software can detect the virus within 10 SECONDS, yes 10 seconds a USB is inserted in the system.

Windows 7, the latest client version in the Mi...

Image via Wikipedia

Below the video I would like to share in which the Developer

  1. Quick Formats the D Drive (the thing we can only dream about doing it).
  2. install a virus in background
  3. fiddles with the Windows Registry.
  4. and then he restores everything back.

I present the demonstration video here. You do have to bear the accent of the compare. ;). For my international visitors, this video is mostly in URDU.

If you are interested in giving this Anti Virus a go, the First Pakistani Anti virus can be downloaded from the following URL.

http://www.instantviruskiller.com/

http://www.instantviruskiller.com/ivkdownloads.html

As an end note, I am really against Anti Viruses and in particular Windows, because, viruses are one of curses of using windows, but I am dedicating a complete post for the purpose of showcasing Pakistani Talent. The developers have developed this Anti Virus keeping in mind the licensing requirements too. One License will only install on one PC. Obviously, they have monitored the System hardware setting with which they will be restricting the installation.

They should be praised by what they are doing.

Although I am very much against the Windows system and have opted for Ubuntu system around two or three years back. More details about installing Ubuntu can be found here.(https://salmankhwaja.wordpress.com/tag/ubuntu/)