I simply do not expose critical switches to Siri from Home Assistant.
I only have Siri kick in when I press the button.
Using ultrasound attack to disarm a smart-home system
21–30 of 37 posts
Re: Using ultrasound attack to disarm a smart-home system
#22Re: Using ultrasound attack to disarm a smart-home system
#23> could be remotely hijacked, using carefully crafted near-ultrasonic sounds, and forced to make unwanted phone calls and money transfers, disable alarm systems, or unlock doors. I know Siri is much too dumb to facilitate a money transfer…
Re: Using ultrasound attack to disarm a smart-home system
#24The article taught me that I can control Siri’s feedback volume by for example saying “Hey Siri, speak 25 percent.”
Re: Using ultrasound attack to disarm a smart-home system
#25The article taught me that I can control Siri’s feedback volume by for example saying “Hey Siri, speak 25 percent.”
I learned that too, but now I'm wondering why her voice suddenly went silent a few weeks ago...
When I say across a room to set a reminder or add something to my shopping list my Homepods will just silently do so, with no indication but a flash of the screen. I have no idea if it's registered what I was saying or not.
When I ask to turn on the lights in a room, it'll do a bing-bong noise at me to indicate that it's registered despite the fact I can see the lights turning on. It's utter nonsense.
Re: Using ultrasound attack to disarm a smart-home system
#26Why the heck wouldn't they have the wake-word listener confine itself to human-audible frequency ranges? Seems like that would be a really simple fix with zero loss of real-world functionality....
I also remember seeing a presentation on the first gen Echo which went into its noise cancelling tech, making sure that stuff coming out of the speaker wasn't received by the mic, so the success of the speaker-to-mic attack vector also seems totally bizarre.
1: https://www.wired.com/2016/11/block-ultrasonic-signals-didnt...
Re: Using ultrasound attack to disarm a smart-home system
#27> It's also worth noting that the length of malicious commands must be below 77 milliseconds — that's the average reaction time for the four voice assistants across multiple devices. I don't get it. Why? You can speak to smart assistants much longer than that isn't it?
This har me confused at first too. Basically you are playing audio on the device and that audio will send a command to the same device. If I’m watching a video on my phone and say hey siri, it will interrupt the audio playing from my phone as it listens to me. But it isn’t instantly interrupting the audio, it apparently takes about 77 milliseconds.
Re: Using ultrasound attack to disarm a smart-home system
#28Earlier quoted context omitted.
I only have Siri kick in when I press the button.
I disabled it after a very potentially awkward event. I was talking to my wife while Siri on my Apple Watch misunderstood me, triggered itself and sent a text saying "I love you" to our previous maid (which we had fired because of reasons).
Re: Using ultrasound attack to disarm a smart-home system
#29Phreaking is back?
Re: Using ultrasound attack to disarm a smart-home system
#30> It's also worth noting that the length of malicious commands must be below 77 milliseconds — that's the average reaction time for the four voice assistants across multiple devices. I don't get it. Why? You can speak to smart assistants much longer than that isn't it?
What I'm wondering is how a useful command can be expressed in 77 ms?