Skip to main content

Don’t be fooled if your smart speaker asks for your password

Your smart speakers could be listening for way more than you want them to. Recently, Security Research Labs (SRLabs), a hacking research group and think tank based in Germany, released a report on their findings that Alexa and Google Home expose users to phishing and eavesdropping due to third-party skills and apps. The labs found two possible scenarios that can be played out on both Amazon Alexa and Google Home where a hacker can listen to your interactions with your smart speaker and phish for sensitive information. They dubbed the vulnerabilities Smart Spies, recorded their results, and put them in four videos to explain how they work.

Basically, a hacker can make a third-party app that can trick users into giving away certain information or keep listening after ending a task with the user, using the speaker’s built-in voice command system. In their tests, using these vulnerabilities, SRLabs was able to request and collect personal data, including user passwords, and eavesdrop on users.

Recommended Videos

Google smart speakers are particularly vulnerable to eavesdropping. One of the vulnerabilities involves recording people after the user thinks the smart speaker has stopped listening. With Alexa, certain trigger words must be said to start recording, but with Google, that’s not the case. As long as the device hears someone talking every 30 seconds, a hacker can keep the voice recording going, possibly infinitely.

Safety checks that are run by Amazon and Google are part of the problem that allows these vulnerabilities to exist. SRLabs also found that even if Google or Amazon reviews a third-party app or skill for safety and it passes, the app can be changed after the safety review to phish or eavesdrop on users.  Making these changes didn’t trigger another safety check from either Google or Amazon.

The best strategy to avoid hackers eavesdropping on your sensitive information? If an app or skill asks for a password, don’t answer. No trustworthy app or skill will ask you to say passwords. Most require you to go to the app and link your accounts, which is safer. Your smart speaker won’t ask you for passwords to perform system or account updates, either. In addition, don’t give your smart speaker your credit card information or other sensitive data. Avoid saying sensitive data out loud after recently using your smart speaker, too.

Alina Bradford
Alina Bradford has been a tech, lifestyle and science writer for more than 20 years. Her work is read by millions each month…
Your Google smart home devices just got a lot less talkative
A person standing in a living room while looking at a Google device.

Smart assistants are an indispensable part of any smart home, making it easy to give hands-free commands and control a variety of gadgets. Google is looking to further streamline the performance of its smart assistant, with the expansion of chime alerts to cut down on how talkative your Google Nest gadgets are when responding to instructions.

For example, after asking Google to turn on a fan, you’ll now be able to hear a quick chime to confirm the assistant has heard your instructions. Previously, confirmation would come in the form of a short sentence, such as “OK, turning on your fan.”

Read more
During spring cleaning, don’t forget smart home security
A physical lock placed on a keyboard to represent a locked keyboard.

With warmer weather sweeping across the nation, folks around the country are using spring as a time to clean their homes and declutter all the junk they’ve accumulated during the dark, dreary winter months. And while organizing your home is a great way to ring in the spring, consider taking a few minutes to perform a bit of smart home spring cleaning, too.

From upgrading your gadgets and changing your passwords to enabling two-factor authentication and performing software updates, here are a few ways to expand your spring cleaning chores to your smart home.

Read more
Sonos One vs. Google Nest Audio: which is the best smart speaker?
The Google Nest Audio speaker on a table.

The Sonos One and Google Nest Audio are two of the best smart speakers of 2023. Both can pump out impressive sound, respond to a wide variety of voice commands, and easily sync up with the rest of your smart home. But with the Sonos One costing more than $200 and the Google Nest Audio clocking in at just $100, you might be wondering if the Sonos One is truly worth your money -- or if you’d be better off saving $100 and opting for the cheaper Google product.

Before picking up either smart speaker, here’s a closer look at the Sonos One and Google Nest Audio.
Pricing and availability

Read more