The Farmer’s Wife: Handle with Care! Part 1: Angel Advent (2021)service model offered by Amazon Key, which gives the company's delivery corps access to customers' homes via smart lock, sounds kind of sketchy under the best circumstances. Amazon, however, assured potential customers there'd be nothing to worry about with Key — the system offers 24/7 monitoring via the Alexa-enabled Cloud Cam to monitor deliveries.
That security safeguard doesn't look quite so foolproof after a group of researchers from Rhino Security Labs discovered multiple techniques to knock out the Cloud Cam and enter a house equipped with a Key system undetected. The group shared its findings with Wiredand in two videos demonstrated the techniques behind the relatively simple hacks, which could allow unscrupulous delivery people to move around Key-enabled homes undetected.
SEE ALSO: Bluetooth exploit may have impacted 20 million Amazon Echo and Google Home devices, says security firmAll it takes to knock out the camera is a computer running the right software within range of the home's Wi-Fi network. The first demonstration shows the "delivery person" unlocking the door using the PIN code, entering the room to deliver a package, and closing the door behind them, just like they should.
Instead of locking the door, however, the thief runs a "deauth" program to temporarily kick the Cloud Cam off the Wi-Fi network. The denial of service (DoS) script keeps the camera from coming back online for as long as the intruder requires, as the program loops the last frame recorded before going offline. Any live viewers or homeowners reviewing the recording are none the wiser.
After moving out of the camera's range and locking the door to avoid suspicion, the thief could move around the home as they liked.
The second attack is less likely to be put into practice IRL, but it's still worth highlighting. The same style of DoS is used to knock out the Cloud Cam, but the delivery person isn't the thief.
Instead, an unassociated hacker waits for the courier to drop off a package, then triggers the attack before the door is re-locked. Unfortunately, the Key Lock's Wi-Fi connection is through the Cloud Cam — so when the Cam is knocked offline, the Lock goes with it. Once the delivery person is out of the picture, the thief could access the house unimpeded.
Both of these scenarios depend on other variables to actually work without tipping off the system — the delivery person has to exit through another door in the first, while the second hinges on perfect timing and sloppy delivery work — but the vulnerabilities are worth highlighting.
Amazon is aware of the Rhino researcher's findings, but downplayed the actual threat they might pose if put into practice. The company pointed out to us in an email that All Key deliveries have time-stamped reports detailing how long doors are opened and the company alerts customers if the camera goes offline for extended periods of time.
Amazon also trusts its delivery people. A company rep told us that Amazon verifies all of its drivers with a "comprehensive background check," and emphasized how each assignment is tied to an individual driver, so any funny business would be immediately detected.
Still, Amazon will issue an update to the Key software to notify users more quickly if the camera goes offline during delivery, and the service won't unlock the door if the Wi-Fi is disabled and the camera is not online.
Topics Amazon Cybersecurity
Previous:How to Settle Down with Dystopia
Next:Robin Triumphant
'Bachelor' contestant couple slam claims they're in a fake relationshipParents, do not let this dumb sign make you feel guilty about using your phoneRejoice! Hillary Clinton is writing a book of personal essaysWhich news publication is headed to Snapchat Discover?The internet's new favorite meme involves topEver Wonder How the Shazam Algorithm Works?Mind reading tech talks to patients with lockedThe internet's new favorite meme involves topBeyoncé's Coachella performance will be pretty interesting, according to TwitterNothing to see here, just a cricket commentator announcing a match during his vasectomySnapchat will soon make real clouds vomit rainbowsRejoice! Hillary Clinton is writing a book of personal essaysUber is pretty much throwing in the towel in TaiwanInstagram is testing photo albums, because nothing is sacred anymoreDonald Trump is absolutely terrible at handshakesStart your engines for this possible RuPaul's Drag RaceBeyoncé graciously shares even more photos from her pregnancy shootBeyoncé's Coachella performance will be pretty interesting, according to TwitterBryan Singer explains why the XGoogle just added a feature we always wanted for Chrome on iPhone 5 Golden Globe wins we'd love to see Here are 25 speedruns worth watching this week Ed Sheeran is back with two new songs guaranteed to get stuck in your head This city now allows women to carry knives for 'self protection' on metro trains CES 2017: Winners and losers Son organises 50 pole dancing girls on jeeps for father's funeral These simple badges are helping social media users talk about mental illness Listen to the eerie sounds of Mars recorded by a NASA rover This is what you look like from Mars The most excessive tech at Day 3 of CES 2017 Here's a great reason not to get engaged under a waterfall Ed Sheeran's new song is hiding in a Snapchat lens A blind man attached a GoPro to his guide dog Terrified swimming elephant stays afloat in a fantastic Photoshop battle Carrie Fisher's urn is shaped like a giant Prozac pill, like she would've wanted There's a room with a bunch of dudes watching VR porn at CES Dell Canvas gives you Surface Studio abilities without the luxury price tag CES 2017: SwagSurf is like a hoverboard for the ocean This Albert Einstein robot is here to help kids learn science Gorgeous iridescent umbrella tells you when it's supposed to rain
1.668s , 10131.8828125 kb
Copyright © 2025 Powered by 【Farmer’s Wife: Handle with Care! Part 1: Angel Advent (2021)】,Unobstructed Information Network