When Dolphins Outsmart the Smart Home - InnovationFestival @karlsruhe.digital

A review and video of the event can be found in the article How the Dolphin Attack opens the door for attackers in the smart home .

InnovationFestival @karlsruhe.digital on Oct 16, 2020, from 2 PM

Livestream from the ZKM | Center for Art and Media Karlsruhe
10-minute keynote starting at approximately 6 PM
"When Dolphins Outsmart the Smart Home"
Further information about the event: InnovationFestival @karlsruhe.digital

As a partner of the Bunte Nacht der Digitalisierung (Colorful Night of Digitalization), aramido GmbH already supported the goal of making digitalization visible and tangible for everyone in Karlsruhe back in October 2019. This year, aramido is once again part of the InnovationFestival, which showcases the best digital innovations from the technology region. From around 60 applications, the jury—comprising steering committee members of the karlsruhe.digital initiative—selected 15 digital innovations from Karlsruhe's science, business, culture, and administration. The highlights will be presented on stage at the ZKM on October 16 and made available free of charge and without registration via livestream.

How you hear, you hear nothing

At around 6 PM, Maximilian Stauß will present the Dolphin Attack in his keynote "When Dolphins Outsmart the Smart Home". Using an attack on an Amazon Echo Dot, he demonstrates how smartphones and smart home devices can be attacked through voice commands in the ultrasonic range, without humans hearing them. The focus of the presentation is on live hacking and the discussion of potential attack scenarios. He also provides tips on how to use innovative technologies without literally opening the door and gate to attackers.

The vulnerability of smart home devices often remains overlooked

Voice assistants like Siri, Google Now, or Alexa have become increasingly widespread in recent years. While the integration of these devices into so-called smart homes leads to a multitude of new application possibilities, it also creates a whole series of new security risks. In this context, data protection and the transmission of voice recordings are primarily discussed, while the vulnerability of the devices themselves often remains overlooked—or unheard, as with the Dolphin Attack.

The Dolphin Attack, first scientifically published in 2017, targets voice recognition systems in frequency ranges inaudible to humans. To achieve this, voice messages are transformed into imperceptible frequencies and played through powerful speakers. Due to the physical properties of the installed microphones, the received audio signal is demodulated and the original voice message is recovered, allowing it to be processed and executed.

The goal of the Dolphin Attack is to send commands unnoticed

If an attack can be technically carried out, the limitation lies in the capabilities of the targeted device. Depending on the degree of networking—for example, in a smart home—lights, thermostats, shutters, or even doors can be operated via the voice assistant, representing significant security breaches. Without other networked devices, it is possible to order Amazon Echo products in the account holder's name, which an attacker could then intercept. Access to the account and thus to the identity of the victim can also be exploited by sending messages such as emails or SMS in the victim's name. Connected services like calendars, shopping lists, or taxi services like Uber can also be maliciously abused.

The speaker

Maximilian Stauss
As an information security consultant, Maximilian Stauß develops security concepts according to Security-by-Design principles with the goal of enabling companies to achieve a better understanding of threats and protective measures in the digital world. He had already implemented the Dolphin Attack during his studies at the Karlsruhe Institute of Technology.