How Amazon Echo and Kindle got KRACKed

14:18 - 15.11.2019


November 15, Fineko/abc.az. ESET Smart Home Research Team recently discovered that the popular Amazon Echo – the original hardware of Amazon Alexa – was open to a number of the ten Key Reinstallation Attack (KRACK) vulnerabilities. This was also the case for at least one generation of Amazon’s widely used Kindle e-readers. Identified flaws were reported to, and subsequently patched by, Amazon’s security team.

In 2017, two Belgian researchers, Mathy Vanhoef and Frank Piessens found serious weaknesses in the WPA2 standard, a protocol that at that time was securing virtually all modern Wi-Fi networks. KRACK attacks were mostly aimed against the four-way handshake – a mechanism used for two purposes: confirming that both the client and access point possess the correct credentials, and negotiation of the key used for encryption of the traffic. Even now, two years later, many Wi-Fi enabled devices are still vulnerable to KRACK attacks.

“In recent years, hundreds of millions of homes have become smarter and internet-enabled via one of the many popular home assistant devices available on the market. Despite the efforts of some vendors to develop these devices with security in mind, these often remain vulnerable,” said ESET Researcher Miloš Čermák. “We identified multiple flaws in at least three Amazon devices, which could have posed a far-reaching security risk due to the numbers in which they have been sold,” explained Čermák.

The Echo first generation and Amazon Kindle eighth generation devices were found to be vulnerable to two KRACK vulnerabilities. These vulnerabilities are quite severe as they allow an attacker to execute a DoS attack, decrypt any data or information transmited by the victim, forge data packets, cause the device to dismiss packets or even inject new packets or intercept sensitive information such as passwords or session cookies.

“It should be noted that KRACK attacks – similar to any other attack against Wi-Fi networks – require close proximity to be effective,” added Miloš Čermák.

ESET reported all identified vulnerabilities in Echo and Kindle, and assisted Amazon’s security team while they fixed the issues.

For more details, read the blog, “What was wrong with Alexa? How Amazon Echo and Kindle got KRACKed.“ Make sure to follow ESET research on Twitter for the latest news.

 

Other news