Audio Attacks

  • Comments posted to this topic are about the item Audio Attacks

  • When the iPhone 4S came out it was usual to see senior execs placing their iPhones in front of them on meeting room tables.
    One particular character walked into the meeting room, took one look at the phones on the table and said in a loud clear voice "SIRI, FIND PORN".  Cue, extreme executive panic....and obvious followup consequence for the perpetrator.

  • Sigh.

    First rule of security. Reduce attack surface. So what do these bozos do? Increase it! Not by a little either, they increased it by a whole new DIMENSION, a dimension of sound. (the dimension of sight has been included for a while now) :hehe:
    Dimension of Sound

  • At least as far as the echo's in my home or the assistant on my phone go, this is less a security issue and more a manners issue. Yes, the technology is new and fun and some friends will think it's funny to add embarrassing items to the shopping list at first. But after the novelty has worn off, it's really just rudeness to walk into someone's house and set the hue lights to rave mode. 

    To me, anything controlled by these assistants is trivial so it's not really a security concern as much as it is basic manners, and people not being sure what proper manners are (yet) in relation to this new tech.

  • roger.plowman - Thursday, May 25, 2017 6:36 AM

    Sigh.

    First rule of security. Reduce attack surface. So what do these bozos do? Increase it! Not by a little either, they increased it by a whole new DIMENSION, a dimension of sound. (the dimension of sight has been included for a while now) :hehe:
    Dimension of Sound

    There was talk of putting sensors on public rubbish bins outside stores so that personal mobile technology would receive tailored messages to encourage you to shop.
    Personally, I don't find the prospect of having my dress sense critiqued by a rubbish bin particularly endearing.  Douglas Adams would have been amused.

  • There are so many layers to this editorial it's not even funny.
    You've got the data security layer, the "how can we be sure someone hasn't altered this data?"
    You've got the privacy bit, which is one of the reasons I've not considered for more than a few minutes getting an Alexa or Home device.  How can you be SURE they're not listening to what's going on?  Then add in the problem of them currently responding to anyone's voices (witness the Burger King TV commercial that tried to get Google Homes to go to a Wikipedia page about the Whopper).  Heck, I don't even use the voice recognition on my phone.
    As for faking someones voice from recorded samples, I'd bet the software to do that is already out there.  You can do it the "easy" way and grab individual words or phrases from previously recorded audio and stitch it together, or you could track down sufficient recordings to build up a library of phonemes and then record whatever you want in that persons voice.

    Just once, it would be nice if a company would bake in security before releasing nifty-feature-of-the-week.  Voice commanding your phone / house, sure great, wonderful, probably convenient.  Oh, but anyone can control it, so the next thing you know you just ordered a car because of your "prankster" buddy...
    Heck, even an activation password or passphrase wouldn't be a help here, because again someone could hear it / record it.

  • Think about an app that can send audio commands to another phone's Siri or Alexa assistant that are outside the range of human hearing. First send a command to all phones within range telling them to go on mute, and then ask them to send a politically and socially offensive email to everyone in their contacts list. Do that in a crowded place like a mall, and the end result would essentially be a new form of terrorist attack. Are you listening, Apple and Samsung? It's not exactly science fiction.  :unsure:

    "Do not seek to follow in the footsteps of the wise. Instead, seek what they sought." - Matsuo Basho

  • The dictation app on the keyboard iPhone has some specificity to voice. Occasionally while I'm playing a book on CD, I'll try to dictate a message. Usually it isn't a problem, but occasionally I'll get a long stream of text in the message window.

    I wonder how voice similarity mirrors facial similarity. Occasionally uploading pictures to Facebook a suggested tag for my daughter will appear as one of the people on my friends list.

    412-977-3526 call/text

  • As for faking someones voice from recorded samples, I'd bet the software to do that is already out there. You can do it the "easy" way and grab individual words or phrases from previously recorded audio and stitch it together, or you could track down sufficient recordings to build up a library of phonemes and then record whatever you want in that persons voice.

    I've seen an example of this software in action and its crazy how well it works.

    https://arstechnica.com/information-technology/2016/11/adobe-voco-photoshop-for-audio-speech-editing/

  • My wife dictated a text message to me while she was stuck in traffic. Her phone dutifully included the speech of the radio announcer playing in the background.

    (at least that was just humorous)

    ...

    -- FORTRAN manual for Xerox Computers --

  • David.Poole - Thursday, May 25, 2017 1:08 AM

    When the iPhone 4S came out it was usual to see senior execs placing their iPhones in front of them on meeting room tables.
    One particular character walked into the meeting room, took one look at the phones on the table and said in a loud clear voice "SIRI, FIND PORN".  Cue, extreme executive panic....and obvious followup consequence for the perpetrator.

    BWAAAA-HAAAA-HAAAA!!!!  Now THAT's funny!  The guy should have been given a medal!  Thanks for the laugh!

    --Jeff Moden


    RBAR is pronounced "ree-bar" and is a "Modenism" for Row-By-Agonizing-Row.
    First step towards the paradigm shift of writing Set Based code:
    ________Stop thinking about what you want to do to a ROW... think, instead, of what you want to do to a COLUMN.

    Change is inevitable... Change for the better is not.


    Helpful Links:
    How to post code problems
    How to Post Performance Problems
    Create a Tally Function (fnTally)

  • jay-h - Thursday, May 25, 2017 8:31 AM

    My wife dictated a text message to me while she was stuck in traffic. Her phone dutifully included the speech of the radio announcer playing in the background.

    (at least that was just humorous)

    That's funny

  • I bought a 2nd hand car without knowing it had voice recognition. I nearly got run off the road by a lady in an arrogantly driven Porsche.  I  hit what I thought was the horn  and said a rude word only to hear this voice say "Phoning Jenny's Mum"

  • Jeff Moden - Thursday, May 25, 2017 9:02 AM

    David.Poole - Thursday, May 25, 2017 1:08 AM

    When the iPhone 4S came out it was usual to see senior execs placing their iPhones in front of them on meeting room tables.
    One particular character walked into the meeting room, took one look at the phones on the table and said in a loud clear voice "SIRI, FIND PORN".  Cue, extreme executive panic....and obvious followup consequence for the perpetrator.

    BWAAAA-HAAAA-HAAAA!!!!  Now THAT's funny!  The guy should have been given a medal!  Thanks for the laugh!

    Brilliant, but if this fool had done the same thing, only one-on-one with the CIO, they would have considered him a hero for pointing out a potential security issue. However, because he took them all by surprise during a group meeting... now he's the bad guy and probably lost his job.

    "Do not seek to follow in the footsteps of the wise. Instead, seek what they sought." - Matsuo Basho

  • Friends had a nephew hijack their Smart TV and totally confuse them with random channel switching and a volume control that had a mind of its own. He did own up after a while and has not done it again. They also got some proper anti-virus for their PC so he did them a favour!

Viewing 15 posts - 1 through 15 (of 15 total)

You must be logged in to reply to this topic. Login to reply