Researchers have discovered that Amazon Alexa and Google Home smart assistants can be hacked by cybercriminals to monitor users' conversations (without them knowing). In addition, hackers can trick usersinto giving up sensitive information.
Alexa and Google Home have been the targets of similar attacks again. In April and August 2018, hackers compromised Alexa. In May 2018, Google Home devices were attacked .
Every time an attack occurs, both companies (Amazon and Google) provide fixes. However, criminals are constantly finding new ways to exploit smart assistants.
The latest breaches have now been made public. They were discovered by Security Research Labs (SRLabs) researchers Luise Frerichs and Fabian Bräunlein earlier this year.
To carry out phishing attacks and monitor conversations , the backend provided by Amazon and Google to developers of Alexa or Google Home custom apps is exploited
Backends provide access to functions used by developers to customize the commands to which a smart assistant responds and to determine how it responds.
Researchers have discovered that hackers add a character sequence (U+D801, period, space) to various points within the backend of an Alexa/Google Home app. In doing so, they can cause long periods of silence (i.e., periods when the assistant is unresponsive). However, the assistant remains active.
The data theft process is as follows: the user asks the assistant something, it replies that there is an error and cannot respond. Then the character sequence (which we saw above) is entered. There is a period of silence and after a few minutes a message (phishing message) arrives, which supposedly has nothing to do with the previous failed command.
In the message, the user may be asked for password their (Amazon/Google), which is supposedly needed to install an update.
An indication that the assistant is still active after a failed response is that the light remains on. This means that it is processing data and that the phishing message is a continuation of the failed response. They are not unrelated.

Monitoring conversations
The above character sequence can also be used for conversation monitoring, beyond phishing attacks. In this case, however, it is inserted after a successful response to a user's command.
The goal is to keep the device active so that it can record the user's conversations . The conversations are stored and sent to the criminals' server
SRLabs researchers said they notified Google and Amazon of this issue earlier this year. However, neither has yet resolved the issue.
“Finding and addressing unexpected behavior, such as long pauses, should be relatively straightforward,” the research team said. “We are surprised that nothing has happened yet, even though we reported the vulnerabilities several months ago.”.
Amazon has not commented on the researchers' report. A Google spokesperson said the company is working on the issue and is putting additional mechanisms in place to prevent similar issues from occurring in the future.
Google also told Home Assistant users not to answer questions that ask for passwords or similar information, because the company would never ask for such things. Such questions indicate that something suspicious is going on.
