SlideShare a Scribd company logo
1 of 41
Alexa is a snitch!
WesWidner – CrowdStrike
tl;dr Alexa collects your audio
www.hackerhalted.com 2
• But you already knew that..
• What you may not know is what that audio contains
• ..or how its stored
• ..or who it’s shared with
• ..or what to do about it!
Alexa is always listening
www.hackerhalted.com 3
• The mute button is designed to be irritating
• Alexa is almost the perfect listening device
• Alexa is basically an excellent microphone with a computer attached
• 2nd gen Alexa’s had a 7 mic array
• Newest one comes with 4 far-field microphones
• Easily triggered by design
• The inverse square law means sound drops by 6db for every doubling of
distance
• So far-field mics must be extra-sensitive
www.hackerhalted.com 4
www.hackerhalted.com 5
Alexa is always recording
www.hackerhalted.com 6
• Recordings are kept indefinitely
• Recordings are kept in a large collection
• Recordings are not protected by strong access controls
www.hackerhalted.com 7
www.hackerhalted.com 8
And when a customer interacts with an Alexa
skill, that skill developer may also retain
records of the interaction.
www.hackerhalted.com 9
www.hackerhalted.com 10
Kept in a large repository..
www.hackerhalted.com 11
www.hackerhalted.com 12
Alexa doesn’t just record voice
www.hackerhalted.com 13
• The audio landscape around us rarely has a single sound event going
on
• New apps and papers reveal that voice is not the only thing that's
recorded
• Environment, emotions and health are also recorded
www.hackerhalted.com 14
www.hackerhalted.com 15
www.hackerhalted.com 16
www.hackerhalted.com 17
www.hackerhalted.com 18
www.hackerhalted.com 19
A treasure trove of fingerprints
www.hackerhalted.com 20
www.hackerhalted.com 21
Say AHHHH..
www.hackerhalted.com 22
www.hackerhalted.com 23
www.hackerhalted.com 24
I’m sorry Dave…
www.hackerhalted.com 25
Predictive crime
Alexa is not the only snitch
www.hackerhalted.com 26
• Google and Siri are also designed
this way
• Google plans to turn some
phones into Alexa devices
• Baidu and Sonos are catching up
• Even without these, listening
devices are pretty cheap
www.hackerhalted.com 27
Et tu, Google?
www.hackerhalted.com 28
A few bad Apples..
www.hackerhalted.com 29
Smart speakers everywhere!
Snitches get stitches
www.hackerhalted.com 30
• You knew this was coming..
• Be mindful of the audio you produce
• Consider shaping that landscape
• Dampen or mask areas like you were a
cold war spy
• Help out with an open source on-prem
voice assistant
• Shut your mouth
• Know and respect the actors trying
to protect you
www.hackerhalted.com 31
www.hackerhalted.com 32
If you’re not paying for it..
www.hackerhalted.com 33
Sound cloaking
www.hackerhalted.com 34
www.hackerhalted.com 35
But in all seriousness
www.hackerhalted.com 36
Manhandle Alexa
www.hackerhalted.com 37
Setting expectations
Shout out to the Mozilla Voice project
www.hackerhalted.com 38
https://voice.mozilla.or
g
www.hackerhalted.com 39
Conclusion
www.hackerhalted.com 40
• Alexa is always listening
• Amazon is always recording
• Alexa doesn’t just record voices
• Alexa isn’t the only snitch
• Snitches get stitches
The end – Thanks for coming!
Wes Widner
Cloud Engineering Manager Crowdstrike (we’re hiring engineers)
wes.widner@crowdstrike.com
@kai5263499
https://github.com/kai5263499/audio-security-awesome
www.hackerhalted.com 41

More Related Content

More from Wes Widner

"make secure" securing the development supply chain All Things Open 2019
"make secure" securing the development supply chain All Things Open 2019"make secure" securing the development supply chain All Things Open 2019
"make secure" securing the development supply chain All Things Open 2019Wes Widner
 
DIY Jarvis All Things Open 2019
DIY Jarvis All Things Open 2019DIY Jarvis All Things Open 2019
DIY Jarvis All Things Open 2019Wes Widner
 
Containing the cloud
Containing the cloudContaining the cloud
Containing the cloudWes Widner
 
The sound of evil
The sound of evilThe sound of evil
The sound of evilWes Widner
 
Homeland security
Homeland securityHomeland security
Homeland securityWes Widner
 
A worm in the apple
A worm in the appleA worm in the apple
A worm in the appleWes Widner
 

More from Wes Widner (6)

"make secure" securing the development supply chain All Things Open 2019
"make secure" securing the development supply chain All Things Open 2019"make secure" securing the development supply chain All Things Open 2019
"make secure" securing the development supply chain All Things Open 2019
 
DIY Jarvis All Things Open 2019
DIY Jarvis All Things Open 2019DIY Jarvis All Things Open 2019
DIY Jarvis All Things Open 2019
 
Containing the cloud
Containing the cloudContaining the cloud
Containing the cloud
 
The sound of evil
The sound of evilThe sound of evil
The sound of evil
 
Homeland security
Homeland securityHomeland security
Homeland security
 
A worm in the apple
A worm in the appleA worm in the apple
A worm in the apple
 

Recently uploaded

Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024StefanoLambiase
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsAhmed Mohamed
 
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...stazi3110
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...MyIntelliSource, Inc.
 
Implementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureImplementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureDinusha Kumarasiri
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantAxelRicardoTrocheRiq
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Andreas Granig
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...gurkirankumar98700
 
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataAdobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataBradBedford3
 
Professional Resume Template for Software Developers
Professional Resume Template for Software DevelopersProfessional Resume Template for Software Developers
Professional Resume Template for Software DevelopersVinodh Ram
 
React Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaReact Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaHanief Utama
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...OnePlan Solutions
 
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmSujith Sukumaran
 
Asset Management Software - Infographic
Asset Management Software - InfographicAsset Management Software - Infographic
Asset Management Software - InfographicHr365.us smith
 
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...soniya singh
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based projectAnoyGreter
 
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样umasea
 
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWhat is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWave PLM
 

Recently uploaded (20)

Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...Call Girls In Mukherjee Nagar 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
Call Girls In Mukherjee Nagar 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SE...
 
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
Dealing with Cultural Dispersion — Stefano Lambiase — ICSE-SEIS 2024
 
Unveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML DiagramsUnveiling Design Patterns: A Visual Guide with UML Diagrams
Unveiling Design Patterns: A Visual Guide with UML Diagrams
 
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
Building a General PDE Solving Framework with Symbolic-Numeric Scientific Mac...
 
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
Steps To Getting Up And Running Quickly With MyTimeClock Employee Scheduling ...
 
Implementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with AzureImplementing Zero Trust strategy with Azure
Implementing Zero Trust strategy with Azure
 
Salesforce Certified Field Service Consultant
Salesforce Certified Field Service ConsultantSalesforce Certified Field Service Consultant
Salesforce Certified Field Service Consultant
 
Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024Automate your Kamailio Test Calls - Kamailio World 2024
Automate your Kamailio Test Calls - Kamailio World 2024
 
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
(Genuine) Escort Service Lucknow | Starting ₹,5K To @25k with A/C 🧑🏽‍❤️‍🧑🏻 89...
 
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer DataAdobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
Adobe Marketo Engage Deep Dives: Using Webhooks to Transfer Data
 
Professional Resume Template for Software Developers
Professional Resume Template for Software DevelopersProfessional Resume Template for Software Developers
Professional Resume Template for Software Developers
 
React Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief UtamaReact Server Component in Next.js by Hanief Utama
React Server Component in Next.js by Hanief Utama
 
Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...Advancing Engineering with AI through the Next Generation of Strategic Projec...
Advancing Engineering with AI through the Next Generation of Strategic Projec...
 
Intelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalmIntelligent Home Wi-Fi Solutions | ThinkPalm
Intelligent Home Wi-Fi Solutions | ThinkPalm
 
Asset Management Software - Infographic
Asset Management Software - InfographicAsset Management Software - Infographic
Asset Management Software - Infographic
 
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
Russian Call Girls in Karol Bagh Aasnvi ➡️ 8264348440 💋📞 Independent Escort S...
 
MYjobs Presentation Django-based project
MYjobs Presentation Django-based projectMYjobs Presentation Django-based project
MYjobs Presentation Django-based project
 
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
办理学位证(UQ文凭证书)昆士兰大学毕业证成绩单原版一模一样
 
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort ServiceHot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
Hot Sexy call girls in Patel Nagar🔝 9953056974 🔝 escort Service
 
What is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need ItWhat is Fashion PLM and Why Do You Need It
What is Fashion PLM and Why Do You Need It
 

Alexa is a snitch collects your audio indefinitely

Editor's Notes

  1. https://www.forbes.com/sites/charlesradclyffe/2018/08/29/the-deliberate-design-flaw-in-every-amazon-echo/#640e5bc931b0
  2. https://www.forbes.com/sites/charlesradclyffe/2018/08/29/the-deliberate-design-flaw-in-every-amazon-echo/#640e5bc931b0
  3. https://threatpost.com/amazon-admits-alexa-voice-recordings-saved-indefinitely/146225/?fbclid=IwAR3YFpZBQ0fDw-HL5pXRxiMUA0c8BWMNNKEGzgfOS08pT6fbw7tw5R0xX2o
  4. Amazon’s letter to U.S. Senator Chris Coons (D-Del.) https://www.coons.senate.gov/imo/media/doc/Amazon%20Senator%20Coons__Response%20Letter__6.28.19%5b3%5d.pdf
  5. https://arstechnica.com/information-technology/2018/08/researchers-show-alexa-skill-squatting-could-hijack-voice-commands/
  6. https://threatpost.com/amazon-1700-alexa-voice-recordings/140201/
  7. https://www.forbes.com/sites/kateoflahertyuk/2019/04/12/amazon-staff-are-listening-to-alexa-conversations-heres-what-to-do/#4f57d8ef71a2
  8. https://www.seattletimes.com/business/amazon/suit-alleges-amazons-alexa-violates-laws-by-recording-childrens-voices-without-consent/
  9. https://developer.amazon.com/blogs/alexa/post/d6fe5fef-b546-430c-8dcc-5cd4fecd410b/audio-watermarking-algorithm-is-first-to-solve-second-screen-problem-in-real-time
  10. https://nypost.com/2017/07/10/alexa-calls-cops-on-man-allegedly-beating-his-girlfriend/
  11. https://www.newsweek.com/amazon-alexa-recordings-romania-sex-privacy-1452173
  12. https://techcrunch.com/2018/11/14/amazon-echo-recordings-judge-murder-case/
  13. https://pdfs.semanticscholar.org/a641/3620dcf0a21f10d22e01427121cc7c6dc8fa.pdf
  14. https://www.cnet.com/how-to/alexa-can-tell-you-if-someone-breaks-into-your-house/
  15. https://thenextweb.com/artificial-intelligence/2018/10/15/amazons-new-patent-will-allow-alexa-to-detect-your-illness/
  16. https://www.theverge.com/2019/4/4/18295260/amazon-hipaa-alexa-echo-patient-health-information-privacy-voice-assistant
  17. https://www.theregister.co.uk/2019/06/21/alexa_heart_attack/
  18. https://www.businessinsider.com/amazon-patent-alexa-emotional-intelligence-2018-10
  19. https://features.propublica.org/aggression-detector/the-unproven-invasive-surveillance-technology-schools-are-using-to-monitor-students/
  20. https://www.wsj.com/articles/google-contractors-listen-to-recordings-of-consumers-addressing-virtual-assistant-11562865883
  21. https://www.theverge.com/2019/7/26/8932064/apple-siri-private-conversation-recording-explanation-alexa-google-assistant
  22. https://www.bbc.com/news/technology-49343262
  23. https://www.engadget.com/2014/03/12/acoustic-invisibility-cloak/?guccounter=1&guce_referrer=aHR0cDovL3Rla2RlZi5jb20vYWNvdXN0aWMtY2xvYWstc2hpZWxkLXN1Ym1hcmluZXMtY29uZS1zaWxlbmNlLw&guce_referrer_sig=AQAAAC4swWpHRc3psg61j8qIKtDYJn5ygtTQLxuutIzFTFA0baK0TSCPTZknm1pA43nH7d21qIA01wpMCviKeTszk1BGNvZmKIYWxSPZ5H4jixRB1WcSYCzrYeVnTFT4FU0S9LLsrMCT3VDaVzvKKA2kn21YakyabzXv39PJQQbjTC1d https://www.youtube.com/watch?time_continue=9&v=k13L8u2tACY
  24. https://www.cnet.com/news/helmfon-noise-isolating-helmet-hochu-rayu-work/
  25. https://www.instructables.com/id/Project-Alias/
  26. https://cambridgesound.com/wp-content/uploads/2015/10/Speech-Privacy-Standards.pdf
  27. https://voice.mozilla.org/en
  28. https://github.com/mozilla/DeepSpeech