Technology News

Google Home Smart Speakers Permit Hackers to Tune in Chats

Recently, a researcher discovered that a bug in Google Home smart speakers allowed hackers to install a backdoor account. It could be used remotely as a snooping device by accessing the microphone feed.

Earlier this week, the prober published technical details about his findings alongside an attack scenario. It aims to show how the flaw could be leveraged.

While experimenting with his Google Home mini speaker, the investigator found that new accounts added through the Home app could send commands remotely via the cloud API.

Further, he found the device’s port for the local HTTP API using a Nmap scan and set up a proxy to catch the encrypted HTTPS traffic. This trick was made to snatch the user authorization token.

By doing so, he discovered that adding a new user to the earmarked gadget is a two-step process that needs the device name, certificate, and “cloud ID” from its local API. Using this information, hackers could send a link request to the Google server.

Related Post

Hence, the proof of concept took things a step further from just situating a rogue user and enabling spying using the microphone. This method makes arbitrary HTTP requests on the victim’s network and reads or writes haphazard files on the device.

Chrome to Block Insecure HTTP Downloads on Samsung Phones

Generally, Google Chrome on Samsung or another Android phone marks insecure HTTP websites as “not secure” in the address bar.

Now, the company unveiled a new toggle that can be found inside security settings. By turning on “Always use secure connections”, Chrome would be forced to connect to the HTTPS version of the website. In context, URLs with HTTPS websites are secured compared to HTTP.

This new feature comes in handy in situations when a user accidentally navigates an unsecured version of a particular website.

In cases wherein no secure version is available, a warning message will pop up if the user would like to continue navigating insecurely.

User Review
0 (0 votes)

Recent Posts

  • Technology News

Nio Unveils Its First Onvo EV in Direct Challenge to Model Y

On Wednesday, Nio introduced the first offering of its new low-priced Onvo brand, the L60…

11 seconds ago
  • Commodity News

Cocoa Price Recovery Boosted by Lacking Liquidity

On Wednesday, cocoa prices spiked due to a lack of liquidity, with open interest in…

5 mins ago
  • Stock News

Boeing Stock Dips Amid Deal Breach on 737 MAX Accident

On Tuesday, the US Department of Justice (DOJ) revealed that Boeing had violated its obligations…

22 hours ago
  • Commodity News

Wheat Prices Rally Amid Weather Developments

On Wednesday, wheat futures spiked as the winter season’s grains entered their late growth stages…

23 hours ago
  • Technology News

Google Revamps Search Results to Prioritize GenAI Responses

On Tuesday, Google retooled its search engine results pages (SERPs) to rank generative AI (GenAI)…

24 hours ago
  • Trading Education

Evaluating ICOs and STOs for Investment Potential

Quick Overview ICOs, starting with Mastercoin in 2013, revolutionized digital fundraising, peaking with Ethereum's launch…

2 days ago

This website uses cookies.