A team of researchers from the University of Cambridge in the United Kingdom has discovered how voice assistants can cause leaks . They observed that the assistants have the ability to store whatever is typed on a smartphone that is in close proximity to them.

In this way, a hacker could obtain personal information by compromising a Voice Assistant.
As the researchers explained, almost every voice assistant, such as Alexa, Echo , and Google Assistant, has multiple sensitive microphones. As a result, they can record sounds that we don't or can't easily hear. For example, the sound of typing on virtual smartphone keyboards.
Additionally, these microphones remain in an “always-on” state. Even though the assistants are only activated by keywords, such as “Alexa” or “Hey Google,” they remain active and record sounds all the time. This functionality helps them activate immediately when we need them. However, constantly recording sounds, in essence, violates privacy for users.
Microphones in smartphones are also vulnerable, but exploiting them requires access to the device itself. However, in the case of microphones found in smart speakers, a hacker can spy on multiple devices at once. As the researchers noted, attacks on virtual keyboards do not necessarily require access to the device and can be carried out via external microphones.
In their study, the researchers demonstrated that by exploiting a Voice Assistant, an attacker can steal recordings taken through its microphone. Then, processing and reconstructing these recordings allows the decryption of what a user typed on a smartphone by detecting the positions of the taps on the screen. The attack could work up to half a meter away from the smart speaker.

How will you protect yourself?
The first thing you can do is use screen protectors and cases on your devices, which change the way typing sounds on them, thus providing some protection against this attack.
The researchers also advise smartphone manufacturers to introduce “silent tap-like sounds,” which are triggered when the keyboard is opened. Such sounds will increase false positives, thereby mitigating the attack.
