Comments

You must log in or register to comment.

chrisdh79 OP t1_j249z9f wrote

From the article: A bug in Google Home smart speaker allowed installing a backdoor account that could be used to control it remotely and to turn it into a snooping device by accessing the microphone feed.

A researcher discovered the issue and received $107,500 for responsibly reporting it to Google last year. Earlier this week, the researcher published technical details about the finding and an attack scenario to show how the flaw could be leveraged.

While experimenting with his own Google Home mini speaker, the researcher discovered that new accounts added using the Google Home app could send commands to it remotely via the cloud API.

Using a Nmap scan, the researcher found the port for the local HTTP API of Google Home, so he set up a proxy to capture the encrypted HTTPS traffic, hoping to snatch the user authorization token.

51

majorgeneralpanic t1_j24enzd wrote

I’m powerfully uncomfortable with the Internet of things for this reason. When the big boys like Samsung TVs and Google Homes are so vulnerable, why would I be able to trust a small startup? They probably have to use off the shelf parts like OpenSSH that open the door for HeartBleed etc, and they can’t afford the security staff that Google can.

45

microgiant t1_j24f44x wrote

God I wish I had something to say that was interesting enough to be worth snooping on.

8

halfanothersdozen t1_j24i9d3 wrote

Well then they probably heard me cussing at rocket league and telling me dogs they are good boys

12

WoodBoogerSpork t1_j24yqgf wrote

Ok so somewhat on topic, but really more just a question for someone else that has "good boys". Do you ever hear Google responding when you ask your dog "Who's a good boy?" or just even "Good boy."? I'll be talking to my dog and from out of left field Google will tell me "Sorry I don't understand."

I AIN'T EVEN TALKING TO YOU, GOOGLE!

2

iotic t1_j253m1r wrote

Old - they patched it

7

Zagrebian t1_j256bns wrote

Community question: How many microphones do you have in your home?

For me, it’s six, I think. Three smartphones, two laptops, and the landline.

1

OfficeChairHero t1_j257qul wrote

I have an 8 year old. I hope they like fart jokes, cause that's what they're going to hear at my house.

10

reichbc t1_j259qtw wrote

The speaker doesn't understand "what you're saying" - it listens for key vocal frequencies that more or less come together to form the expected phrase "Ok, Google" - Assuming you have not fully voice trained your Assistant, it has to fuzz its listening expectations, as it doesn't know your specific voice frequencies that correlate with "Ok, Google".

What you end up with is a system that's listening very broadly for something that sounds like "Ok Google" and with the amount of fuzzing needed to capture that, "good boy" can come close enough on key frequencies to match up with "okay" and then any further speech might match up with a fuzzed expectation of "google".

Think about it, some people repeat phrases to their dogs a few times, "Who's a g__OO__d bo__Y__? wh__OO__'s A good boy?" (cap'd and bolded for fuzzy syllables probably recognized)

5

QkaHNk4O7b5xW6O5i4zG t1_j25bequ wrote

The title reads worse than it is. The account with access needs to add other accounts for the vulnerability to be leveraged.

16

contributes_n0thing t1_j25d37b wrote

Google fixed all problems in April 2021.

Always scroll down to the end of these "sky is falling" tech stories.

15

Adorable-Slip2260 t1_j25hxsr wrote

Shocking. Imagine being one of the dickheads using things like this and Alexa.

1

golden918 t1_j25kefi wrote

Your saying that if the thing that snoops on your conversations is hacked they would snoop on your conversations??

2

Theman00011 t1_j25uajh wrote

Luckily though the initial vulnerability requires the attacker to be within wireless range of the Google Home before they can use it remotely.

5

ZaNobeyA t1_j26b8wo wrote

few days ago. I've had the google hub reset and set up with a different google account. I still had control over it with the previous account from a phone. I wonder if this is correlated somehow.

8

Dont____Panic t1_j279wqg wrote

I run a cybersecurity company that helps companies with exactly this type of thing.

So many companies we talk to simply say “yeah that’s not in the budget unless a customer/government tells us it’s mandatory.

About 10-20% do it anyway.

Hard to tell which is which as a customer.

1

a_white_american_guy t1_j27bzud wrote

OH MY GOD NO WAY WHO COULD’VE PREDICTED THIS?!

MICROPHONES IN OUR HOMES THAT WE CANT CONTROL?

WHO WOULD’VE THOUGH THAT THOSE COULD BE EXPLOITED?!

WOOOOOOOOOOW!

0

PhoibosApollo2018 t1_j27pdcn wrote

No way!! Shocking. Internet connected device with Mic and/or Cameras being used for snooping.

2

xxoahu t1_j286s57 wrote

Is "allowed" the best word here?? If a rapist shoots you and rapes your wife did you allow it to happen? Perhaps "Criminals were able to hack Google home speakers to snoop on conversations?"

2