Light-commands for Alexa, Siri and Google Home

--

I always have a paper to read on my trip into work in the morning, and this week it is [here]:

The paper outlines that Siri, Alexa and Google Home can have commands (Light Commands) injected using a laser. In their experiment the researchers show how a laser can be focused onto device which is 360 feet away, and get it to respond to commands. This means that devices near a window could be vulnerable to the attack, or where there must be a direct line-of-sight connection. At the core of the attack is the usage of MEMS (micro-electro-mechanical systems), and where microphones respond to light in a way that matches sound. Basically the laser is focused on microphone, and where it produces an acoustic pressure wave:

The researchers were even able to brute force a PIN code on the devices. An outline of the attack is:

--

--

Prof Bill Buchanan OBE FRSE
ASecuritySite: When Bob Met Alice

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.