Web giants are constantly trying to make our homes “smarter”—or, more precisely, more dependent on their platforms. Shelves and online stores are full of “smart” products that could cause a real security crisis if they fail. That’s how we come to Destin from the Smarter Every Day channel, who decided to join forces with a researcher from the University of Michigan to inject false commands into the main digital assistants… using a laser beam.

Hacking a Smart Home with a Laser
Laser

You probably already have access to an assistant on your mobile device. An Amazon Echo Flex costs barely 20 euros, and if you want an Echo Dot, it’s 10 euros more. The point is that incorporating a digital assistant system into our homes isn’t that expensive. Of course, the price increases with the features included, but if the plan is to listen to music or answer a call... you can already do it.

However, these products being presented as “smart” and having lower prices doesn’t mean they’re more secure. While many people have notably improved their quality of life thanks to them, we must also consider any existing vulnerabilities. That’s exactly what Destin from Smarter Every Day did. He sought the help of Benjamin Cyr, one of the researchers behind the Light Commands project, and they went to buy several smart devices with the goal of injecting false commands into them, purely with a laser.

Light Commands exploits a vulnerability in MEMS microphones (Micro-Electro-Mechanical Systems) that allows sending commands that are completely inaudible and invisible to the user to the main smart assistants on the market. Accessing this vulnerability depends on multiple factors, including brand, model, and device position, but in their initial tests they have managed to attack devices at a distance of 70 meters.

Destin and Benjamin’s experiment was carried out on a much smaller scale, but that doesn’t make it less interesting. Quite the opposite: The first step was to “convince” the Google assistant to raise the thermostat eight degrees, and then lower it by five. In the second test, they attacked an Echo Dot (third generation) and ordered it to turn the hallway light green, but it interpreted the false command as blue.

https://old.neoteo.com/el-laser-asesino-de-camaras/

The third phase took them outside. Destin installed an August smart lock, which has a serious vulnerability: it has no limit on retries for the PIN code. In other words, an attacker could use simple brute force to open a door. It would take a long time... but it would work.

While it’s easy to defend against this attack (try to keep microphones from having a direct line of sight to the outside), it also serves as a warning. These “smart” devices don’t always prioritize security, and before choosing one (giving up part of the control of our homes in the process) we should study that aspect very carefully. Otherwise... “analog and dumb” is always an option.

Editor’s note: August confirmed that a new software update now limits the number of retries to four.

Official Light Commands site: Click here