3 ms·
But it'd be trivial for them to slip an extra bit of hardware, wire it to the existing mic and use that to do all the actions they wish. At the point where some
by rightos 9y ago
But it'd be trivial for them to slip an extra bit of hardware, wire it to the existing mic and use that to do all the actions they wish. At the point where someone has physical access to the device the game is over.
This is not an attack - its an immutable law, if someone else has unrestricted physical access to your device, it's not your device anymore.
- TeMPOraL 9y agoTo be fair, planting a physical bug for longer-term surveillance is more difficult, because you need to worry about providing power to it, and about exfiltrating the data. A home assistant device, by its nature, has its owner ensuring both of those problems are solved for you.
- kelnos 9y agoRight, and you also need to worry about it being found. There's nothing physical about this hack that would tip off the owner that they have an (unauthorized) listening device in their home.
- rightos 9y agoYou still need to worry about it being found in the pure software case - there's far higher odds of me seeing some suspicious traffic than a small custom bit of RF gear inside. If someone's taking the thing apart and sees your physical extra bits, odds are they're doing so to dump the firmware, just like this guy... if they're not doing that, they're not necessarily skilled enough to spot whatever modifications you may have planted either. It really depends on the target though I suppose. Of course, at the point you have physical access, all bets are off, they could swap chips on the board with identically labeled ones which serve different functions - replace the firmware and signing with their own, etc. An essentially undetectable hardware modification.
- kelnos 9y agoTwo things: 1) I doubt most people are monitoring their home LAN traffic at all, let alone to the degree that would let them detect something odd here. Even if they are, there are ways around it -- like simply compressing and storing the extra voice data and only sending it out when someone makes a legit request to their Echo. Certainly that's more data, but the access pattern would make it easier to hide. 2) This hack doesn't require any (lasting) physical modification to the Echo. You connect to the debug pads on the bottom, do some stuff, disconnect, and you're done. So there are no physical extra bits to find. But yeah, my point here was exactly #2 -- physically there is nothing in your home that was not there before. In the case of a dedicated bug, that's something physical that the target of surveillance could find and know that someone is messing with them.