HomeSecurityHackers use radio waves to take control of devices

Hackers use radio waves to take control of devices

José Lopes Esteves and Chaouki Kasmi, two security researchers at Anssi (Agence Nationale de la Sécurité des Systèmes d'Information), a French national agency dedicated to IT security, have created a special build consisting of an antenna, a USRP radio, an amplifier, and a laptop running the GNU Radio software.This build is able to send radio waves to an iPhone or Android with headphones still on, using the headphone cable as an antenna that detects the radio waves and relays them to the operating system's voice recognition software.

By implementing this simple method, hackers will be able to silently force the phone to perform malicious actions, all provided that the user is not looking at their screen while this is happening.

Anything Siri and Google Now, the voice assistants for iOS and Android respectively, can do, a hacker can do too. This includes sending texts, making phone calls, opening websites, installing apps, and so on.

Hackers use radio waves to take control of devices radio waves radio waves radio waves

However, there are some limitations to this attack as you may have already guessed. First of all, it only works when headphones are plugged into the device and the headphones have a built-in microphone, meaning they're not just for listening to music.

Secondly, the structure is quite bulky and has a reduced attack range. If the attacker wants to use a small structure, then he will not be able to reach phones at a distance of more than 2 meters. If he wants to use the entire structure, then he will need a car to hide it and move it, but in this case, he will be able to use it at a distance of 5 meters. You can see how big the antenna is from the video below:

 

The attack will not work for versions of Google Now and Siri (iPhone 6s) that are set to recognize their owner's voice. Additionally, for locked phones, the voice assistant feature must be enabled for the lockscreen.

On older iPhones, where Siri can be activated by long-pressing a button on the headphones, hackers would also have to mimic this electrical signal when sending radio waves, making the attack even more complicated.

What should be done?

To protect against this type of attack, researchers encourage users to not leave their headphones plugged into their devices when not in use. In addition, they should also use headphones without a microphone and activate voice assistance software only when needed.

For manufacturers, the researchers recommend better shielding of headphone cables, implementing voice recognition features for all services that use voice assistance, adding a sensor to detect abnormal electromagnetic activity, and additionally encouraging users to use custom commands to activate the voice assistant, instead of the classic “Hey Siri” and “OK Google”.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS