Jump to content

Attacked by light - Vulnerabilities in MEMS microphones

lewdicrous
Go to solution Solved by rcmaehl,

Some additional info from my November thread:

 

 

I'll have to read your sources to see what all has changed

  Researchers at the University of Michigan & the University of Electro-Communications found a way to exploit microphones inside smart hubs by using lasers.

Quote

The “light commands” attack exploits a design flaw in the smart assistants microelectro-mechanical systems (MEMS) microphones. MEMS microphones convert voice commands into electrical signals, but researchers demonstrated that they can also react to laser light beams.

Quote

Light Commands was discovered this year in May. It allows attackers to remotely inject inaudible and invisible commands into voice assistants, such as Google assistant, Amazon Alexa, Facebook Portal, and Apple Siri using light. This vulnerability can become more dangerous as voice-control devices gain more popularity.

They were able to use their lasers on smart assistants from Google, Amazon, Apple, as well as others.

Some products required authentication, some of them don't have a limit to how many pass codes you can try, while other products, like Apple devices (Siri) would require you to unlock your phone in order to let the command go through.

 

Ways to mitigate this sort of attack:

Quote

Researchers suggested to set up a PIN or a security question before executing the commands.

By applying physical barriers, you can restrict light waves reaching the devices.

 

Sources:

Original paper:

Related video by SmarterEveryDay:

Spoiler

 

 

Thoughts:

This might make some people, especially government officials or company executives, reconsider getting devices that are vulnerable to this kind of attack, at least until the manufacturers find a way to fix it, both in terms of hardware (making it difficult for the lasers to see the MEMS units) and software (adding extra precautions/authentication processes).

Link to comment
Share on other sites

Link to post
Share on other sites

Some additional info from my November thread:

 

 

I'll have to read your sources to see what all has changed

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, rcmaehl said:

- Snip -

I tried searching for a tech news thread on this subject, but I didn't find one, that's why I made this.. My bad.

 

I guess the new thing here would be the SmarterEveryDay video.

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, lewdicrous said:

I tried searching for a tech news thread on this subject, but I didn't find one, that's why I made this.. My bad.

 

I guess the new thing here would be the SmarterEveryDay video.

Forum search function sucks and there's new info so it's fine. I'll definitely be checking out the video

 

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Guest
This topic is now closed to further replies.

×