Criminals could use 'skill squatting' to hijack your smart speaker

Amazon Echo speaker

Researchers have demonstrated how crooks could use the idiosyncrasies of voice recognition to carry out unwanted commands on a smart speaker. 

A team from the University of Illinois showed that by giving a malicious application or Alexa skill a name that sounds the same as a legitimate one, criminals could trick a device into triggering it – a tactic it calls 'skill squatting'.

The words didn't even have to be exact homophones. Results varied depending on the speaker's accent and gender, but the team found that 'coal' was easily misinterpreted as 'call', 'dime' as 'time' and 'wet' as 'what'.

There are already some examples of this happening on the Alexa Skill Store. For example, both 'cat facts' and 'cat fax' give information about cats, but from different providers.

Sounds suspicious

The principle is much like domain squatting (also called cybersquatting). Domain squatters register domain names that are identical or similar to names used by real companies. The squatters use these domains to trick people into viewing their own content, or offer to sell them to the business whose name they're using at an inflated price.

The university's researchers used Amazon Alexa, but the same principle could apply to other voice-activated virtual assistants, including Google Home, Siri and Cortana. It's a thorny problem, and as voice recognition is integrated into ever more products, it will be increasingly important to solve.

Via Ars Technica

Cat Ellis
Homes Editor

Cat is TechRadar's Homes Editor specializing in kitchen appliances and smart home technology. She's been a tech journalist for 15 years and is an SCA-certified barista, so whether you want to invest in some smart lights or pick up a new espresso machine, she's the right person to help.

Latest in Smart Home
Nanoleaf PC Screen Mirror Lightstrip set up on gaming PC
This Nanoleaf light strip adds Ambilight-style illumination to your gaming setup – and it's amazingly cheap
Philips Hue
Setting up your Philips Hue lights is now quicker and easier than ever thanks to the latest app update
Two Ring video doorbells on blue background with white text reading 'TechRadar Price Cut'
Ring doorbells and cameras crash to record-low prices in Amazon sale
Alexa privacy
Amazon's big Alexa voice processing change may not be the privacy nightmare you think it is
Panos Panay and Alexa Plus
Amazon's Panos Panay teases future Alexa+ devices from speakers to possible wearables
Beatbot
Save big on the industry's best robotic pool vacuum with our exclusive Beatbot coupon
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)