Is Your Amazon Smart Device Secure?

With more than 200 million Alexa devices sold, Amazon has a firm grip on the smart speaker market and there is every chance that you will already own one yourself. Even if you just muttered “Alexa”, we bet some device near you would wake up and start listening to you.

Alexa is Amazon’s cloud-based voice service that is used across many of Amazon’s own product ranges. From tablets to television sticks, Alexa is everywhere. The full list of Alexa-enabled devices includes:

  • Echo – Smart Speaker
  • Show – Smart Display
  • Fire TV – Streaming Device
  • Fire Tablet – Smart Tablet
  • Buds – Earphones
  • Auto – Add Alexa to a vehicle
  • Fitbit – Fitness Smartwatch
  • Link – Stream hi-fi music to stereo
  • Sub – Smart Subwoofer

This will be sure to increase in no time at all! With the demand for smart homes increasing every day, more devices will be popping up in people’s homes.

A common question that many people (rightly) have, is if Alexa is actually taking everything you say and storing this data. The simple answer is yes, Alexa is always listening as it is waiting for a command from the user. Amazon states that a very small sample of Alexa interactions are listened to by employees to understand a correct interpretation. We would recommend opting out of this by turning this off in the Alexa settings on the device and here’s how to do so:

  1. Open up the Amazon Alexa app and tap More
  2. Tap Settings and then Alexa Privacy
  3. From here, scroll down and select Manage Your Alexa Data
  4. Tap on Choose How Long to Save Recordings before selecting Don’t Save Recordings
  5. Finally, Confirm your selection and you’re all set

You can also add an additional layer of reassurance by scrolling down to further options, tapping on Help Improve Alexa and switching the Use of Voice Recordings off.

Amazon claims that they don’t access this data and use it for other purposes other than complimenting the machine learning process. But the reality is that hackers can and have been able to.

An Alexa smart speaker is always monitoring everything around it with the microphone always active, waiting to hear its ‘wake word’ to start functioning and help the user. Without constant monitoring, there is no way it would be able to hear the user. This is known as ‘keyword spotting’ technology, and Amazon only processes and records what the software deems to be Alexa commands.

Whilst Amazon claims that it does nothing with the stored data, there have been reports of hackers breaching the device and getting access to the information stored. The BBC reported that there was:

A flaw in Amazon's Alexa smart home devices could have allowed hackers access to personal information and conversation history

Check Point Research

bbc.co.uk

and Mashable reported that there has been major security flaws, and that hackers could also install or delete Alexa Skills.

What you can do to stay safe

There are a number of precautionary measures you can do to stay safe from potential hackers:

Ensure that you only buy your device from Amazon directly

If purchasing from a 3rd party seller, there is no way to know if your device has been tampered with beforehand.

Never post videos or audio clips of you using your Alexa enabled device online

This opens potential hackers to use these clips to control your device if it is located within a distance of them. It has been reported that smart devices can hear commands from outside houses, and you don’t want someone sneakily accessing your device!

Check the Alexa Skills

As mentioned above, hackers have been able to modify Alexa Skills on the device. Make sure you regularly check the device to see if the correct and official applications are installed on the Amazon device.

Alexa-enabled Amazon devices can be helpful and make your life easier at home, but as with any form of technology, always be mindful of how it’s being used. Your online safety must always be your priority.

App icon - download from the App Store and Google Play

Download Revoke Today

Start protecting yourself with Revoke, and take back control of your personal data.

Download on the App Store - icon Get it on Google Play - icon
Cyber Essentials certified logo

Cyber Essentials Certified

We take security seriously which is why we’ve been assessed and certified for addressing cybersecurity effectively and mitigating the risk from Internet-based threats.