Voice assistants are now ubiquitous and listen in on our everyday lives. Ever since they became commercially available, privacy advocates worried that the data they collect can be abused: might private conversations be extracted by third parties? In this paper we show that privacy threats go beyond spoken conversations and include sensitive data typed on nearby smartphones. Using two different smartphones and a tablet we demonstrate that the attacker can extract PIN codes and text messages from recordings collected by a voice assistant located up to half a meter away. This shows that remote keyboard-inference attacks are not limited to physical keyboards but extend to virtual keyboards too. As our homes become full of always-on microphones, we need to work through the implications.
翻译:语音助理现在无处不在,在日常生活中倾听我们的声音助理。 自从他们进入商业市场以来,隐私倡导者担心他们收集的数据可能被滥用:私人谈话可能会被第三方提取吗? 在本文中,我们显示隐私威胁超出了口头交谈的范围,并包含在附近智能手机上输入的敏感数据。我们用两种不同的智能手机和平板显示攻击者可以从距离半米远的语音助理收集的录音中提取 PIN 代码和短信。这表明远程键盘推断攻击不仅限于物理键盘,而且还延伸到虚拟键盘。随着我们家的住宅总是满满满着麦克风,我们需要研究其影响。