4 ms·
This will be fixed with a simple software update that ignores all sounds at inaudible frequencies.
by rachitgupta 9y ago
This will be fixed with a simple software update that ignores all sounds at inaudible frequencies.
- carlps 9y agoExcept the inaudible sounds are used for marketing purposes. Most companies aren't going to want to just close that door.
- arkad 9y agoI'm genuinely curious - can you share a link how it works please? I've never heard of it.
- j_s 9y agoWatch the 33c3 presentation linked elsewhere in this discussion, or just skip to solutions/Q&A: https://youtu.be/WW1-xnTIDjQ?t=35m05s https://youtu.be/WW1-xnTIDjQ?t=35m05s You can also read the paper: https://petsymposium.org/2017/papers/issue2/paper18-2017-2-source.pdf https://petsymposium.org/2017/papers/issue2/paper18-2017-2-s... Here is the blurb from their talk: Cross-device tracking (XDT) technologies are currently the "Holy Grail" for marketers because they allow to track the user's visited content across different devices to then push relevant, more targeted content. For example, if a user clicks on a particular advertisement while browsing the web at home, the advertisers are very interested in collecting this information to display, later on, related advertisements on other devices belonging to the same user (e.g., phone, tablet). Currently, the most recent innovation in this area is ultrasonic cross-device tracking (uXDT), which is the use of the ultrasonic spectrum as a communication channel to "pair" devices for the aforementioned tracking purposes. Technically, this pairing happens through a receiver application installed on the phone or tablet. The business model is that users will receive rewards or useful services for keeping those apps active, pretty much like it happens for proximity-marketing apps (e.g., Shopkick), where users receive deals for walk-ins recorded by their indoor-localizing apps. -- https://www.blackhat.com/eu-16/briefings.html#talking-behind-your-back-attacks-and-countermeasures-of-ultrasonic-cross-device-tracking https://www.blackhat.com/eu-16/briefings.html#talking-behind...
- mholmes680 9y agoNot sure if this will help, but I was surprised by this: https://arstechnica.com/tech-policy/2015/11/beware-of-ads-that-use-inaudible-sound-to-link-your-phone-tv-tablet-and-pc/ https://arstechnica.com/tech-policy/2015/11/beware-of-ads-th... SilverPush has since stopped, it seems, but that might just mean others are doing it more profitably that they were...
- sangnoir 9y agoI know of traditional media ad-tech that uses ultrasound markers embedded in ads to track/verify if the ads were really broadcast as promised (number of times & in the correct time slots. So the steps are: 1. Inject ultrasound markers into ad during post-production. 2. Have a server with multiple tuner cards to monitor multiple stations, grab the audio. 3. Filter audio on specific ultrasound frequencies, search for the pre-injected patterns. 4. Generate reports. 5. Get paid.
- dboreham 9y agoIf you were to read the article you'd see this isn't how it works. They're inducing harmonic signals within the speech passband.
- mjlee 9y agoThe post specifically addresses why it's not that simple - they're taking advantage of harmonics to generate signal in the audible frequencies on the microphone itself.
- ChrisRR 9y agoIf I understand this correctly, the phone cannot tell if the audio is outside of human hearing range. The point of the LPF is to filter out all audio that is outside of that range. The attack they are using is transmitting the audio at a high frequency, that when detected by the microphone generates harmonics that are within the normal range and can pass through the filter. By the time the audio signal gets to the processor, it is within audible range.
- j_s 9y ago> This is MUCH bigger deal than most understand. >> This will be fixed with a simple software update that ignores all sounds at inaudible frequencies. In the most helpful and constructive way I can possibly say this directly: the group of individuals not understanding may include you, rachitgupta. According to my very limited understanding, the attack occurs in hardware prior to digitization. See yesterday's discussion for more details.
- femto 9y agoIt's happening at the hardware level, so there is potentially limited scope to fix it in software. My guess is that when the author refers to "harmonics" they are really talking about intermodulation. The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the microphone means the two tones mix together to produce a number of other frequencies, including the frequency "B+A"-"B" = "A". Thus the conversion from ultrasonics to audible is happening in the microphone itself, before the software has a chance to distinguish the difference. The mixing process typically produces other frequencies other than "A", so there might be hope of a countermeasure if the microphone is able to pick up these other frequencies and the software is smart enough to use them to figure out that an attack is in progress. It's not a simple case of just filtering out a particular frequency and an intelligent choice of ultrasonic frequencies may leave only a single frequency in the band of the microphone. It's the same principle that is used in ultrasonic beamforming speakers. That adds another element of stealth to the attack, in that the high frequencies can allow the sound to be beamformed and illuminate the microphone and not much else.
- tzs 9y ago> The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the microphone means the two tones mix together to produce a number of other frequencies, including the frequency "B-A"-"B" = "A". Does this work for ears, too? If so, are the non-linearities of different people's ears similar enough that two people hearing the same A and B would get the same results, or would person to person variations in non-linearity mean they might hear different results?
- femto 9y agoYes it does: https://makezine.com/2008/10/08/homebrew-parametric-speak/ https://makezine.com/2008/10/08/homebrew-parametric-speak/ http://www.soundlazer.com/ http://www.soundlazer.com/ It's reasonably consistent. Differences in non-linearity will result in different amplitudes for each intermodulation product, but not different frequencies. Typically these systems use the "third order" product. I gather that the non-linearity exploited is as much a property of the air as the ear.