6 ms·
Google Chromecast, and Home are actually pretty horrible when it comes to security. For example, if you lose internet connection, they will start broadcasting
by unsignedint 8y ago
Google Chromecast, and Home are actually pretty horrible when it comes to security.
For example, if you lose internet connection, they will start broadcasting SSID. At this point, there's nothing in place to prevent someone launching Google Home app and hijack those devices.
Even Chromecast and Hub displays codes, they are only to identify the device. Instead of the Google Home app asking you "what are the letters shown on your device?" it just tell you "Press OK if your device is showing ABCD" -- that's very dumb implementation.
I don't know why they simply couldn't stand by to wait for the network connection to recover or require being present next to your device to press a reset button if their Network connection really needs to be updated -- or at least used simple authentication process to provision the device
- VikingCoder 8y agoYou're hijacking them, but only if you get them on your own WiFi. And then they can't do anything to devices on my Wifi any more. They don't use my bandwidth, they can't control my devices, they're not connected to my account... So yes, you could make them play loud music, or make me miss my alarms. What other harm can you do? Genuine question.
- unsignedint 8y ago> So yes, you could make them play loud music, or make me miss my alarms. Isn't that bad enough? I would be fairly pissed if someone do that. If someone hijack my device in the middle of night and start streaming loud music, I would be pretty pissed. Maybe not so much for alarms, though (As current design, if network goes out, alarm won't sound, so better to have backup anyways.) I'm mainly questioning Google's decision of why they designed the device to scream out loud "hey I'm here, and I can be hijacked!" while sporadic outage of the internet is not that uncommon in residential setting where it is mainly targeted for. And remember, those devices (especially Google Home) are capable, and often used to capture more than a directive of streaming media. Asking for your schedule, making a phone call, etc.
- dragonwriter 8y ago> And remember, those devices (especially Google Home) are capable, and often used to capture more than a directive of streaming media. Asking for your schedule, making a phone call, etc. But that's not super exploitable even with a hijack. You can know I asked for my schedule if you took control of my device, and feed me a fake one, but the work to make that useful rather than just a dead giveaway that something is wrong is non-trivial, and involves getting a bunch of personal info more worrying than the hack itself. And you can know I tried to call a particular named contact, but again doing much with that is non-trivial.
- unsignedint 8y agoWell, you can ask more specific questions, not just "what's my schedule" -- it is true but mileages may vary how much of information you can get out of hijacking. Since all the words followed by "Ok Google" will be captured and saved to attackers' Google account. Regardless of impact this problem may exhibit, my point still stands that it shouldn't be hijackable, let alone at this ease.
- Operyl 8y agoIf there’s ever a security exploit that can persist reboots .. that’s be a fun scenario.
- creato 8y ago> and hijack those devices. And do what then? Serious question, I'm not a heavy user of Google Home/Chromecast, but my impression is that even if you hijack a device this way, the worst you can do is start streaming netflix or spotify, but with your own account to boot (not the account owner of the device you hijacked).
- hadrien01 8y agoYou can stream many types of content on a Chromecast (porn from a Chrome tab for instance, or your Android screen), and you don't need a Google account.
- lozaning 8y agoYou've got to be on the network to execute this attack, which means you could already cast all the porn you wanted to the device anyway.
- robohoe 8y agoTurn on all your lights!
- dragonwriter 8y agoThe hijack described takes them off the local network, but IIRC Home will only control devices on the same network, unless you—after you hijack it—you have access to connect it to some other service that controls the device, which requires already having the control you want to use the hijacked device for.
- lozaning 8y agoNah, they've got cloud to to cloud integrations for stuff like LIFX bulbs, which only connect back to the LIFX cloud.
- dragonwriter 8y ago
- sneak 8y agoI discovered this a couple weeks ago and reported it to Google. Filed WONTFIX. A blog post is coming. Forget hijacking. The issue is that it broadcasts the room name in beacon packets. Imagine things like Project Dragonfly Deployment Conference Room or <unique first name> Bedroom. There are lots of reasons one doesn’t want these broadcast unencrypted into the street for wardrivers.
- gowld 8y agoIf you don't want to broadcast private data via the device name, simply don't put private data in the device name
- sneak 8y ago"If you don't want your nudes to leak, simply don't take pictures of yourself naked." "If you don't want people to read your email, just don't email anything you don't want printed in the newspaper." Perhaps you don't understand the meaning of the word leak.
- sneak 8y agoAlso, it's not apparent it does it until it loses internet access. There is no warning or disclosure indication. It doesn't do it in normal operation; only when it loses internet connectivity, so there's nothing to indicate to even a savvy user that it will rat you out. I of course went through and renamed my rooms to remove anything I don't want associated with my latitude/longitude for permanent record by wardrivers, but that's not the point.
- mortehu 8y agoThe 4 digit authentication code prevents you from sending your WiFi password to an evil device.
- awirth 8y agoYeah, I'm not sure what flow lets you bypass that that GP is refering to. My impression was there aren't any, you always need to be able to see the screen to get the PIN code, and presumably there's rate limiting on trying codes.
- unsignedint 8y agoI'm referring to that four letter code. Google Home app does not even request user to input that. This screen only protect you from entering wi-fi details to third party that's potentially malicious. However, since the implementation does not ask users to input that code into Google Home app, it won't protect someone other than you (as long as they are in wi-fi coverage of the device) to configure or hijack your device. (and Google Chrome/Home drops down to this "waiting for configuration" state every time internet connection becomes unavailable.) Latter is the issue I have raised.
- awirth 8y agoAh, I misremembered I guess. I could have sworn I had to type it in to authenticate the chromecast device to my phone for initial bootstrapping.
- bigiain 8y agoFWIW, this "fixed" the security of both the Google Home and the Chromecast on the network I' connected to right now: for i in {1..255}; do curl -Lv -H Content-Type:application/json --data-raw '{ "wpa_id": 0 }' http://192.168.1.$1:8008/setup/forget_wifi; http://192.168.1.$1:8008/setup/forget_wifi; done
- zifnab06 8y agoChromecast displays a pin on the display it's attached to and requires that pin to pair to a new account. I'm unsure what (if anything) Google home does (I remember "your home device played a sound", I don't remember if there was anything else.