Source |
The Hacker News |
Identifiant |
2402636 |
Date de publication |
2021-02-26 01:03:59 (vue: 2021-02-26 09:05:50) |
Titre |
ALERT: Malicious Amazon Alexa Skills Can Easily Bypass Vetting Process |
Texte |
Researchers have uncovered gaps in Amazon's skill vetting process for the Alexa voice assistant ecosystem that could allow a malicious actor to publish a deceptive skill under any arbitrary developer name and even make backend code changes after approval to trick users into giving up sensitive information.
The findings were presented on Wednesday at the Network and Distributed System Security |
Notes |
|
Envoyé |
Oui |
Condensat |
actor after alert: alexa allow amazon any approval arbitrary assistant backend bypass can changes code could deceptive developer distributed easily ecosystem even findings gaps giving have information make malicious name network presented process publish researchers security sensitive skill skills system trick uncovered under users vetting voice wednesday |
Tags |
|
Stories |
|
Move |
|