27 Apr Amazon’s Alexa Could be Used to Spy on Users
Researchers at Checkmarx recently revealed that it is possible to create an Alexa skill that made the device eavesdrop on its users indefinitely.
Erez Yalon, Checkmarx’s manager of application security research said that it is possible to send sensitive data such as whole transcripts of anything said within earshot by exploiting the way the device listens. The researchers say they were able to make Alexa’s voice prompt silent so that the user is unaware if the session has already been closed or not.
Yalon said that they did not change anything, but rather they just took advantage of the flawed design of the system.
The issue had already been reported to Amazon, who fixed it immediately.