Fooling the voice recognition on Amazon Echo and Google Home
Fooling the voice recognition on Amazon Echo and Google Home
2017-11-21
hey Google what's my name your name is
Andrew hey that's right
thanks Google both Google assistant
built into Google home and Amazon's
digital assistant Alexa built into
Amazon echo speakers can currently
recognize your voice
I really like the feature actually with
Google you can check your personal
calendar check flights check traffic on
your way to work with Alexa you can make
calls get a personalized daily briefing
both of them can play your customized
playlists both can make purchases
verified only by recognizing your voice
when Google first rolled out the feature
this spring we found it could be fooled
by similar voices but can we
intentionally trick both speakers let's
find out hey Google Who am I I remember
you saying it's Andrew hey Google Who am
I I remember you telling me your name
with Andrew there we go hey Google
what's my name your name is Steve hey
Google what's my name your name is Steve
ok Google
what's my name your name is Rui ok
Google what's my name your name is
Andrew ok Google what's my name
your name is Rui ok Google
what's my name
your name is right I really sound like
that
okay Google what's my name your name is
Molly
okay Google what's my name your name is
Molly Alexa what's my name
andrew is speaking you're at Andrews
account Alexa what's my name
andrew is speaking you're at Andrews
account Alexa what's my name I'm talking
to Steve this is Steve's account Alexa
what's my name
I'm talking to Steve this is Steve's
account Alexa what's my name
I'm talking to Rui
this is Kevin's account Alexa what's my
name I'm not sure who's speaking but
you're in Kevin's account that felt
close yeah I thought you had it - Alexa
what's my name
I think you arrived this is Kevin's
account Alexa what's my name I'm talking
to Megan this is Kevin's account Alexa
what's my name I'm talking to Megan this
is Kevin's account so Chris found he
could impersonate all three of us with
some success on both Amazon echo and the
Google home Megan and Molly were able to
impersonate each other on both platforms
so both platforms can be fooled meaning
if someone sounds like you they can
access your personal information they
can make purchases on your account hey
Google order lightbulbs
okay here's something from Walmart on
Google Express I can get for great value
daylight white 9 watt LED light bulbs
for eight dollars and 78 cents would you
like to order that yes okay as far as
those purchases with Google you saw
Chris able to make a purchase on my
behalf with Alexa when you first turn on
voice purchasing there is a voice pin
option but you do need to enable it so
if you're worried about security you can
turn off voice purchasing in both apps
you can turn off personal results
entirely in Google if you don't want
people finding out what's on your
calendar and you can delete your voice
profile in Alexa Google even says in the
Google home app to be careful with your
info as a similar voice might be able to
access it as far as this experiment
here's what Google had to say users
shouldn't rely upon voice match as a
security feature it is possible for a
user to not be identified or for a guest
to be identified as a connected user
those cases are rare but they do exist
and we're continuing to work to make the
product better
Alexa claims to be more secure as the
company confirms it listens to the
entire utterance not just the wake work
we found that to be sorta true as Chris
struggled to imitate Rai but we were
still able to fool it quite a few times
that said the longer utterances of
making a purchase might cause more
trouble for someone trying to
impersonate you when asked for comment
Amazon declined so enjoy the
conveniences of these cool features just
be cautious about what's enabled and who
in your household could feasibly sound
like you
We are a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for us to earn fees by linking to Amazon.com and affiliated sites.