Virtual Assistants: A Threat to Cyber Security




Faculty Mentor:
Ms. Priyanka Gandhi

Student Name:
Manav Bansal (MCA-1st Year)
Rishabh Jain (MCA-1st Year)
Sumit Gupta (MCA-1st Year)



ABSTRACT

Voice or Virtual Assistants are becoming a very crucial part of today’s tech savvy world. People are using these assistants for making their life very easy. We can observe that western culture is a lot dependent on these virtual assistant devices. But, the question arises, that are these devices actually safe? Is the data that is being collected by the companies sold to any third party source without the consent of the user? There are many such questions in mind and let’s try to give a unseen picture of these assistants, how dangerous they can be and how a user can remain safe from these assistants.

1. INTRODUCTION

Imagine a day when everything that we speak is being done automatically in seconds! Just a matter of command and the things are done. The most astonishing thing is that the commands are not given to a physical being. Then how it is possible? Here comes the role of smart home technology and IOT. But how these commands will be analyzed, that’s a big question. Here comes the role of Voice Assistants. Voice or Virtual Assistant is a software agent that can perform tasks for an individual based on the questions and commands given to it. These assistants are totally virtual and use different technologies to interpret a user command. Some of them are like speech recognition, speech synthesis, natural language processing, etc.

2. NEED OF VIRTUAL ASSISTANTS

Let us have a look at some key needs of these Virtual Assistants. In today’s fast world, everyone wants to live a stress-free life and wants to get their work done at their convenience. Now in 2019, big giants have made it possible, we can get our tasks done without a physical person. We just need to give a command and the work gets done.

  • Saves Time and Resources
  • Works without any questions asked from you.
  • Increases the productivity of a person.
  • Smart devices can be developed with assistants.
  • Reminders, Shopping, Alarms etc. can be set with assistants in a second.


3. PLAYERS WORKING ON VIRTUAL ASSISTANTS

There are various Companies or Brands in market who are working on Virtual Assistants. These brands are making various smart devices and integrating their various products with these assistants. Let us see some names of these assistants:-

S.No. Brand Assistant
1. Apple Siri
2. Google Assistant
3. Samsung Bixby
4. Microsoft Cortana
5. Amazon Alexa
6. Tencent Xiaowei
7. Alibaba Group AliGenie

image

4. TECH MADE THROUGH ASSISTANTS

As claimed by various companies that they listen to all the voice commands given by the user, the data is accumulated with them which is used to refine these Assistants or to develop new technology products in the market. Let us discuss about one of the most popular tech built via data of these assistants: “GOOGLE DUPLEX”.

In the annual event of Google last year named “GOOGLE I/O”, companies CEO Mr. Sundar Pichai showcased a technology where if a user wants to fix some appointments or want to book a table or for any enquiry in real time, the google assistant will call the person and will have a conversation itself without letting the person on the other side know that the call is made by an Artificial Voice and not a physical person. Google also clearly said that the tech has been made by listening to many voice samples that they have collected via their Google assistant on mobiles and Website.

Image

These companies claim that these devices are secure and users can use them with full convenience. But think deeply and analyze that whenever we say “OK GOOGLE” or “HEY SIRI” or “HEY CORTANA”, these devices get activated. This means, their microphones are switched on 24 X 7. So they can record each and every talk and command given around these devices. There are many incidents and instances rolling out in the market where it has been observed that these Virtual Assistants are not safe to use. Companies who develop these assistants themselves claim that they listen to all the commands that the users give to these devices supporting assistants. If we check the official blogs of Google and Amazon, they clearly mentioned that they have been listening to all the recordings. There has been various incidents in the past where users had to face a security issue due to these Virtual Assistants. As this technology does not recognize and perform tasks for only one voice that is assigned to it so any person can give commands to it. A person from outside can fail the whole security of home in just a fraction of minutes. getting compromised every single second by themselves. Let us quote some incidents happened in past;

  • On 12th April 2019, The Times of India published an article with the headline “Thousands of Amazon Workers are listening to what you tell Alexa”. Amazon replied that it’s true.

  • A person in America was casually surfing some expensive televisions on Google and all the bank details were linked to his google account. While discussing the products, the product was ordered and the payment deducted from account without any consent.

There are many such incidents that have occurred in real life since these assistants have turned out smarter. Mainly these assistants are installed on all smartphones and people use them as well. Companies have given a disable button on their smart speakers and claims that when a user presses that button, assistants stops replying you. But what’s the guarantee that the conversation is still not heard as speakers are still on. All these recordings are stored on the company’s data servers. The data collected on these servers is used for making new products or to enhance the existing tech. Maybe this data is also sold to advertisers for showing advertisements according to person’s likes but there is no scientific proof for selling of assistant’s data to advertisers.
A major threat is to personal and sensitive information available on these assistants. People around world order items directly from these smart devices supporting assistants but they don’t think about the information stored with these devices like Bank Details, Credit Card Information, PINs etc.

6. HOW CAN WE REMAIN SAFE?

Think over the sensitive information that all users give to these devices without knowing the consequences. The Account details can be used to steal the hard-earned money and to make invalid transactions. The personal details like Date of Birth, address etc. can be used for making fake IDs. The possibilities are endless of these assistants that how much they can steal our data and use it. Due to their very beginning phase, people are not aware of all this and they must be aware about the data that is getting compromised every single second by themselves.

Let us see some measures through which we, as a user can be protected to an extent from the web of these assistants.
Image

  • Refrain from saving your sensitive information on these virtual assistant devices and accounts. Instead input the details every time manually only. Protect to place automatic orders using Smart assistants.
  • Try to make the settings of the assistants on manual mode rather than automatic.
  • Refrain from connecting assistants to all the applications on the smartphone and smart home devices.
  • Read the Manuals and Terms and Conditions of the smart devices that we are using. Do check for the information before purchasing the device and installing at home.
  • Avoid granting unnecessary permissions to these assistants. Do have a sharp look at the granted permissions and use the assistants.

We are not asking or requesting users to completely refrain from using assistants and smart devices but at the stake of user’s privacy is not a good step.

7. CONCLUSION

Virtual assistants have made it possible to get our work done without the involvement of a third person. Just by speaking some phrases, virtual assistants may do anything for you. Yes, these virtual assistants can make our life simpler and convenient, but at the same time, they are becoming a threat to our privacy also. Some people just focus on their user experience, and they don’t care about their privacy. Their personal and sensitive information is at stake. Everything in the universe has two sides like a coin. One is positive and the other is negative. But, if you use these things carefully, then these things can really be helpful but if not, then the consequences can be fatal. We are not asking users to totally ignore this evolving technology but to stake a personal life is not appropriate action.

Image

Companies must not store the information on their servers. Users should feel safe while using these assistants. If companies store the information then it must be in encrypted form. Also, proper clarity of data which is collected must be informed prior by these companies via campaigns or blogs and e-mails.

8. REFERENCES

[1] https://bit.ly/2X25yvQ
[2] https://ai.googleblog.com/2018/05/duplex-ai-system-for-natural-conversation.html
[3] https://bit.ly/2kngtTm
[4] https://bit.ly/2xJ9gSU
[5] https://surfshark.com/blog/the-always-listening-virtual-assistants-and-threats-to-privacy
[6] https://en.wikipedia.org/wiki/Virtual_assistant