The Insecurity of Home Digital Voice Assistants – Amazon Alexa as a Case Study Xinyu Lei∗, Guan-Hua Tu∗, Alex X. Liu∗, Kamran Ali∗, Chi-Yu Liy, Tian Xie∗ ∗ Michigan State University, East Lansing, MI, USA Email:
[email protected],
[email protected],
[email protected],
[email protected],
[email protected] y National Chiao Tung University, Hsinchu City, Taiwan Email:
[email protected] Abstract—Home Digital Voice Assistants (HDVAs) are getting security threats due to the openness nature of voice channels. popular in recent years. Users can control smart devices and Both owners and adversaries can speak commands to HDVA get living assistance through those HDVAs (e.g., Amazon Alexa, devices. At this point, the natural question is: Do these Google Home) using voice. In this work, we study the insecurity commercial off-the-shelf (COTS) HDVAs employ necessary of HDVA service by using Amazon Alexa as a case study. We security mechanisms to authenticate users and protect users disclose three security vulnerabilities which root in the insecure from acoustic attacks? access control of Alexa services. We then exploit them to devise two proof-of-concept attacks, home burglary and fake order, Unfortunately, our study on Amazon Alexa devices yields a where the adversary can remotely command the victim’s Alexa negative answer. We identify three security vulnerabilities from device to open a door or place an order from Amazon.com. The them and devise two proof-of-concept attacks. The victims insecure access control is that the Alexa device not only relies may suffer from home security breach and fake order attacks.