The Insecurity of Home Digital Voice Assistants – Vulnerabilities, Attacks and Countermeasures Xinyu Lei∗, Guan-Hua Tu∗, Alex X. Liu∗, Chi-Yu Liy, Tian Xie∗ ∗ Michigan State University, East Lansing, MI, USA Email:
[email protected],
[email protected],
[email protected],
[email protected] y National Chiao Tung University, Hsinchu City, Taiwan Email:
[email protected] Abstract—Home Digital Voice Assistants (HDVAs) are getting the HDVA security should be specially considered. At this popular in recent years. Users can control smart devices and point, a natural question is: Do these commercial off-the- get living assistance through those HDVAs (e.g., Amazon Alexa, shelf (COTS) HDVAs employ necessary security mechanisms Google Home) using voice. In this work, we study the insecurity of to authenticate users and protect users from acoustic attacks? HDVA services by using Amazon Alexa and Google Home as case studies. We disclose three security vulnerabilities which root in Unfortunately, our study on Amazon Alexa and Google their insecure access control. We then exploit them to devise two Home yields a negative answer. We identify three security proof-of-concept attacks, home burglary and fake order, where vulnerabilities from them and devise two proof-of-concept the adversary can remotely command the victim’s HDVA device to open a door or place an order from Amazon.com or Google attacks. The victims may suffer from home security breach Express. The insecure access control is that HDVA devices not and fake order attacks. All the parties including the HDVA only rely on a single-factor authentication but also take voice service provider (i.e., Amazon), HDVA devices, and the third commands even if no people are around them.