Live data from Hacker News

Hackers send silent commands to speech recognition systems with ultrasound

techcrunch.com

31–40 of 88 posts

Re: Hackers send silent commands to speech recognition systems with ultrasound

#32
post #14
post #3

This is MUCH bigger deal than most understand. This will cost less than $10 to build and their is no hardware solution on phones or Alexia. Phreaking is back.

Yeah, those parts are easily available on Aliexpress in droves. Imagine this in the crowded subway. "hey siri" "show me pictures of CENSORED " "send the first picture to mom" "yes, send it" :S

[deleted]

Re: Hackers send silent commands to speech recognition systems with ultrasound

#33
As the article says, there is a physical presence bar to meet to make this workable now, but I can't not think about clever ways that this could become a "worm" or spread digitally. Infected viral (actually viral!) YouTube videos? Robocalls that you hope go on speakerphone (where the fidelity of the attack signal may be questionable)? Or drive a car with big speakers around a neighborhood? How about a mobile phone botnet that just constantly speaks to digital assistants?

Re: Hackers send silent commands to speech recognition systems with ultrasound

#37
post #23
post #8

Earlier quoted context omitted.

Except the inaudible sounds are used for marketing purposes. Most companies aren't going to want to just close that door.

I'm genuinely curious - can you share a link how it works please? I've never heard of it.

Watch the 33c3 presentation linked elsewhere in this discussion, or just skip to solutions/Q&A: https://youtu.be/WW1-xnTIDjQ?t=35m05s

You can also read the paper: https://petsymposium.org/2017/papers/issue2/paper18-2017-2-s...

Here is the blurb from their talk:

Cross-device tracking (XDT) technologies are currently the "Holy Grail" for marketers because they allow to track the user's visited content across different devices to then push relevant, more targeted content. For example, if a user clicks on a particular advertisement while browsing the web at home, the advertisers are very interested in collecting this information to display, later on, related advertisements on other devices belonging to the same user (e.g., phone, tablet).

Currently, the most recent innovation in this area is ultrasonic cross-device tracking (uXDT), which is the use of the ultrasonic spectrum as a communication channel to "pair" devices for the aforementioned tracking purposes. Technically, this pairing happens through a receiver application installed on the phone or tablet. The business model is that users will receive rewards or useful services for keeping those apps active, pretty much like it happens for proximity-marketing apps (e.g., Shopkick), where users receive deals for walk-ins recorded by their indoor-localizing apps.

-- https://www.blackhat.com/eu-16/briefings.html#talking-behind...

Re: Hackers send silent commands to speech recognition systems with ultrasound

#38
post #23
post #8

Earlier quoted context omitted.

Except the inaudible sounds are used for marketing purposes. Most companies aren't going to want to just close that door.

I'm genuinely curious - can you share a link how it works please? I've never heard of it.

Not sure if this will help, but I was surprised by this: https://arstechnica.com/tech-policy/2015/11/beware-of-ads-th...

SilverPush has since stopped, it seems, but that might just mean others are doing it more profitably that they were...

Re: Hackers send silent commands to speech recognition systems with ultrasound

#39
post #24

These speech recognition tools need to have some sort of authentication: - How about having a secret "wake word" instead of "Alexa" or "Hey Siri"? - Only treating signals using human voice range - Voice identification If this isn't patched soon (excluding ultrasounds), it could mean that these tools are already using inaudible signals for other purposes. For example, commercials could add ultrasounds to know who's wa…

You know, I'm ok with a physical button press as the authentication method.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#40
post #26
post #20

Earlier quoted context omitted.

It's happening at the hardware level, so there is potentially limited scope to fix it in software. My guess is that when the author refers to "harmonics" they are really talking about intermodulation. The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the micropho…

> The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the microphone means the two tones mix together to produce a number of other frequencies, including the frequency "B-A"-"B" = "A". Does this work for ears, too? If so, are the non-linearities of different people…

Yes it does:

https://makezine.com/2008/10/08/homebrew-parametric-speak/

http://www.soundlazer.com/

It's reasonably consistent. Differences in non-linearity will result in different amplitudes for each intermodulation product, but not different frequencies. Typically these systems use the "third order" product. I gather that the non-linearity exploited is as much a property of the air as the ear.

Post reply on HN