Amazon Echo, Google Home devices at risk of hacker attacks, US-Israel firm warns
US giants have been informed of vulnerability and have released security patches, Armis says
Shoshanna Solomon was The Times of Israel's Startups and Business reporter
As many as 20 million Amazon Echo and Google Home personal assistant devices have been at risk of hacking attacks using a security blind-spot called BlueBorne, US-Israeli IoT cyber security firm Armis said Wednesday.
“By exploiting unpatched devices, hackers can take them over, spread malware, and establish a ‘man-in-the-middle’ attack to gain access to critical data, personal information, traffic and networks,” Armis said in a statement.
The firm said it informed both Google and Amazon of the vulnerabilities before it issued its statement, allowing the US giants to release security patches and updates before hackers got to know about the security flaws. Google has already released patches to its partners to address the BlueBorne vulnerabilities, Armis said. Both Amazon and Google have released security updates to the Echo and Home respectively. Updates are automatic and users do not have to do anything to get them, the statement said.
BlueBorne is one of eight vulnerabilities discovered in the Bluetooth protocol that affect billions of devices globally, using the short-range wireless communication technology.
“BlueBorne is especially dangerous, as hackers can execute airborne attacks through any vulnerable Bluetooth-enabled device without having to fool users by clicking on malicious links, downloading a file, or interacting with them in any way,” Armis said in the statement. In the first wave of BlueBorne vulnerabilities found by Armis in September, the firm revealed that more than 5 billion devices were subject to attack.
There are some 15 million Amazon Echoes sold and 5 million Google Home devices sold, according to September report by market research firm Consumer Intelligence Research Partners (CIRP). Additional estimates indicate that more than 128 million Echoes will be installed by 2020, Armis said in the statement. These devices are also making their way into businesses, with Armis data showing that 82 percent of its customers have the Amazon Echo in their offices.
“Burgeoning demand for digital personal assistants is expanding the avenues by which attackers can infiltrate consumers’ lives to steal personal information and commit fraud,” said Yevgeny Dibrov, CEO of Armis. “Consumers and businesses need to be aware how their devices are connecting via Bluetooth, and the networks they may be accessing, in order to take security precautions to protect their information.”
Armis is a privately held company and headquartered in Palo Alto, California, with an office in Tel Aviv.
“Users do not need to take any action,” a Google spokesperson said by email. “We automatically patched Google Home several weeks ago, and neither Google nor Armis found evidence of this attack in the wild. As always, we appreciate researchers’ efforts to help keep all users safe.”
There was no immediate response from Amazon in Israel to an email requesting a comment.
The Times of Israel Community.








