The publication by WikiLeaks of documents it says are from the CIA’s secret hacking program describe tools that can turn a world of increasingly networked, camera- and microphone-equipped devices into eavesdroppers.
Smart televisions and automobiles now have on-board computers and microphones, joining the ubiquitous smartphones, laptops and tablets that have had microphones and cameras as standard equipment for a decade. That the CIA has created tools to turn them into listening posts surprises no one in the security community.
Q: How Worried Should Consumers Be Who Have Surrounded Themselves with These Devices?
A: Importantly, the intrusion tools highlighted by the leak do not appear to be instruments of mass surveillance. So, it’s not as if everyone’s TV or high-tech vehicle is at risk.
“It’s unsurprising, and also somewhat reassuring, that these are tools that appear to be targeted at specific people’s (devices) by compromising the software on them — as opposed to tools that decrypt the encrypted traffic over the internet,” said Matt Blaze, University of Pennsylvania computer scientist.
The exploits appear to emphasize targeted attacks, such as collecting keystrokes or silently activating a Samsung TV’s microphone while the set is turned off. In fact, many of the intrusion tools described in the documents are for delivery via “removable device.”
Q: Once Devices Are Compromised They Need To Be Internet-Connected in Order To Share Collected Intelligence with Spies. What Can Be Done To Stop That?
A: Not much if you don’t want to sacrifice the benefits of the device.
“Anything that is voice-activated or that has voice- and internet-connected functionality is susceptible to these types of attacks,” said Robert M. Lee, a former U.S. cyberwar operations officer and CEO of the cybersecurity company Dragos.
That includes smart TVs and voice-controlled information devices like the Amazon Echo, which can read news, play music, close the garage door and turn up…