Live data from Hacker News

Using ultrasound attack to disarm a smart-home system

theregister.com

31–37 of 37 posts

Re: Using ultrasound attack to disarm a smart-home system

#32
This doesn't make any sense to me.

Why would voice recognition software be interpreting ultrasonic (or near-ultrasonic) signals at all?

First, it doesn't make sense they'd be trained on them. So why would models be interpreting these as speech at all?

And second, it doesn't make sense they'd make it from the microphone to the recognition engine -- surely there's a low pass filter in there to remove all extraneous noise above the vocal range?

I don't get it.

(Edit: could it be some kind of downsampling aliasing artifact that is interpreted as normal vocal frequency, precisely because they skip a low pass filter that would prevent it?)

Re: Using ultrasound attack to disarm a smart-home system

#33
post #20

Quite sure the microphones on any smart speaker or phone do not have the build quality to 'hear' near ultrasonic audio.

Near ultrasound audio doesn't need any special microphone. I just tested with my Samsung Galaxy S3 (i9300 version) and it has no trouble detecting 20kHz. I don't see why newer phones couldn't do the same.

Re: Using ultrasound attack to disarm a smart-home system

#34
post #7

> could be remotely hijacked, using carefully crafted near-ultrasonic sounds, and forced to make unwanted phone calls and money transfers, disable alarm systems, or unlock doors. I know Siri is much too dumb to facilitate a money transfer…

For six months Siri interpreted my requests to call anyone as "Call Paul." It still might, but at that point I gave up and changed Paul's name in Contacts to stop accidentally bothering the poor guy.

Re: Using ultrasound attack to disarm a smart-home system

#35
post #2

The article taught me that I can control Siri’s feedback volume by for example saying “Hey Siri, speak 25 percent.”

I learned that too, but now I'm wondering why her voice suddenly went silent a few weeks ago...

My guess is that the combination of a power button long-press continued by pressing the volume down button is something that might happen accidentally while you have the iPhone in your pocket.

Once Siri is active, using the hardware volume buttons control the feedback volume.

Re: Using ultrasound attack to disarm a smart-home system

#36
post #33
post #20

Quite sure the microphones on any smart speaker or phone do not have the build quality to 'hear' near ultrasonic audio.

Near ultrasound audio doesn't need any special microphone. I just tested with my Samsung Galaxy S3 (i9300 version) and it has no trouble detecting 20kHz. I don't see why newer phones couldn't do the same.

20kHz is not ultrasonic.

Re: Using ultrasound attack to disarm a smart-home system

#37
post #16
post #12

Earlier quoted context omitted.

That's on purpose. They created a specific inaudible frequency that the Alexa listens for which causes it to ignore the wake word. This is how they keep from annoying everyone and also blowing up their own servers if, for example, they want to run an Alexa commercial during the Superbowl.

> Reddit user aspyhackr may have figured out the trick Amazon uses here. Apparently, the Alexa commercials are intentionally muted in the 3,000Hz to 6,000Hz range of the audio spectrum, which apparently tips off the system that the “Alexa” phrase being spoken isn’t in fact a real command and should be ignored. Seems to be the inverse - if the wake word _lacks_ these frequencies, then Echos ignore it.

Yes, I had misremembered it. That does leave a mystery of why they are listening for inaudible frequency. I wonder if it might have to do with their plans of having devices that can connect to other connected devices when they aren't connected to the user's wifi.
Post reply on HN