Live data from Hacker News

Hackers send silent commands to speech recognition systems with ultrasound

techcrunch.com

41–50 of 88 posts

Re: Hackers send silent commands to speech recognition systems with ultrasound

#41
post #26
post #20

Earlier quoted context omitted.

It's happening at the hardware level, so there is potentially limited scope to fix it in software. My guess is that when the author refers to "harmonics" they are really talking about intermodulation. The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the micropho…

> The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the microphone means the two tones mix together to produce a number of other frequencies, including the frequency "B-A"-"B" = "A". Does this work for ears, too? If so, are the non-linearities of different people…

There are (marginally) commercialized ultrasonic speakers:

https://en.wikipedia.org/wiki/Sound_from_ultrasound

The air acts as the demodulator though.

Shaping the ultrasound to modulate the eardrum sounds scary.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#42
post #3

This is MUCH bigger deal than most understand. This will cost less than $10 to build and their is no hardware solution on phones or Alexia. Phreaking is back.

Unplug Alexa, turn "Hey Siri" off. Schlep to store for Cheerios.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#43
post #29
post #20

Earlier quoted context omitted.

It's happening at the hardware level, so there is potentially limited scope to fix it in software. My guess is that when the author refers to "harmonics" they are really talking about intermodulation. The idea is that if you want to create a frequency of "A", you can emit two powerful tones at frequencies "B" and "B+A", where the frequency B is high enough to be out of hearing range. The non-linearity of the micropho…

> the author refers to "harmonics" they are really talking about intermodulation. No, he's talking about harmonics. It's a different effect from intermodulation. It's true that intermodulation involves the sum and difference two or more frequencies. Harmonics, however, involves integer multiples of a single frequency. But the impact is the same as intermodulation in that it's really a hardware issue and cannot be cou…

Harmonics are multiples of the fundamental, so in this case they will also be ultrasonic.

Equation 2 in the paper and the subsequent paragraph shows what is going on. They use an ultrasonic carrier with modulation. The non-linearity causes the carrier to mix with the sidebands, the third-order intermodulation product being a copy of the modulation centred on 0Hz (ie. a baseband signal).

Edit: Figure 12 talks about harmonics, in the context of harmonics of the third order intermodulation product. What they are really refering to are the higher order: 5th, 7th, and so on intermodulation products, which in this case will be multiples of the third order product's frequency.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#44
post #9

Even if the commands are not inaudible it's a security issue if the device performs a dangerous action because someone in the neighborhood said something. The feature is presented as if it only responds to the owner but realistically that distinction doesn't work at all. If you shout 'hey Siri' into the microphone at a large event, a lot of phones are going to respond.

> If you shout 'hey Siri' into the microphone at a large event, a lot of phones are going to respond.

Curious - anybody ever tried that?

Re: Hackers send silent commands to speech recognition systems with ultrasound

#45
post #24

These speech recognition tools need to have some sort of authentication: - How about having a secret "wake word" instead of "Alexa" or "Hey Siri"? - Only treating signals using human voice range - Voice identification If this isn't patched soon (excluding ultrasounds), it could mean that these tools are already using inaudible signals for other purposes. For example, commercials could add ultrasounds to know who's wa…

> Only treating signals using human voice range

Inter-modulation will let you create something hardware can't tell isn't. Two inaudible sounds, both getting received end up looking like an audible one to the hardware.

The harmonic effect described in the article is similar, and damn hard to filter against physically.

> For example, commercials could add ultrasounds to know who's watching them

Yep, and we're already there. [0]

[0] https://www.blackhat.com/eu-16/briefings.html#talking-behind...

Re: Hackers send silent commands to speech recognition systems with ultrasound

#46
post #3

This is MUCH bigger deal than most understand. This will cost less than $10 to build and their is no hardware solution on phones or Alexia. Phreaking is back.

Unplug Alexa, turn "Hey Siri" off. Schlep to store for Cheerios.

Turn Alexa on, order Cheerios, turn Alexa off.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#47
post #24

These speech recognition tools need to have some sort of authentication: - How about having a secret "wake word" instead of "Alexa" or "Hey Siri"? - Only treating signals using human voice range - Voice identification If this isn't patched soon (excluding ultrasounds), it could mean that these tools are already using inaudible signals for other purposes. For example, commercials could add ultrasounds to know who's wa…

You know, I'm ok with a physical button press as the authentication method.

Preferably some kind of hardware on-off switch for the physical microphone.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#49
post #24

These speech recognition tools need to have some sort of authentication: - How about having a secret "wake word" instead of "Alexa" or "Hey Siri"? - Only treating signals using human voice range - Voice identification If this isn't patched soon (excluding ultrasounds), it could mean that these tools are already using inaudible signals for other purposes. For example, commercials could add ultrasounds to know who's wa…

You know, I'm ok with a physical button press as the authentication method.

Most of the point of "Hey Siri" and similar features is for when your hands are occupied, soiled, or otherwise unavailable.

Re: Hackers send silent commands to speech recognition systems with ultrasound

#50
post #9

Even if the commands are not inaudible it's a security issue if the device performs a dangerous action because someone in the neighborhood said something. The feature is presented as if it only responds to the owner but realistically that distinction doesn't work at all. If you shout 'hey Siri' into the microphone at a large event, a lot of phones are going to respond.

There are others issues with out user keyed audio triggers.

Stand outside a living room door and yell "Alexa, open the door" and it may open. Even before this finding, there is the ability to embed things in app/game audio or advertisements. This now also lets commands be embedded here as well and not be audible. Soon, we'll have secret commands hidden in songs that try to turn on all your tvs and audio players and switch everything to play a band's song or youtube channel.

Post reply on HN