Friday, February 2nd 2007

Vista Speech Recognition Flaw

Three days after being released, the first major flaw has been published for Windows Vista. For anyone with speech recognition enabled, malicious websites or audio files could potentially give commands to hijack the PC and tell it to delete files. It works by playing commands such as shutdown, copy or delete through the speakers which could then be picked up by the microphone, causing the computer to carry out certain tasks. Microsoft admits that the exploit is "technically possible" but doesn't see it as a major problem. This flaw is more down to new features than problems with the coding of Vista, and it shouldn't be a problem for most people.
Source: BBC News
Add your own comment

16 Comments on Vista Speech Recognition Flaw

#1
EviLZeD
hehe vista is so stable and bug free
Posted on Reply
#2
EastCoasthandle
This makes using AIM, yahoo messenger, etc a cautious thing indeed when speech recognition is enabled. Using the mic feature in these online chatting programs can re-create this very problem.

For example, you decide you want to use the mic feature instead of text messaging and you say:
Delete C.....
opposing user's response when balloon pops up on screen = :wtf: "how did you do that?"
......YES, continue
opposing user's response = :twitch: "wait, stop that!"
[user disconnected]

Wash, rinse, repeat.
Posted on Reply
#3
bhaskar15
hmm,this flaw isn't a risk for me. I mostly never use speech recognition while online.
Posted on Reply
#4
Unregistered
i wont use speech anyway.and anyone remember how many bugs xp had at first?

i'm using it as my primary os now too.it seems ok to me.
#5
Benpi
LoL, this isn't a hack. So basically if someone puts an audio clip on their website that says "Open My Docuoments, Delete, Empty Recycle Bin" and your speakers are loud enough to be picked up by a mic, and you happen to have voice recognition on, you'll lose your documents folder...... people just try to find things to write stories about. This is retarded.
Posted on Reply
#6
lemonadesoda
This is hilarious! Can't imagine that Vista programmers were so short sighted. Easily solved with a patch. No speech recognition (command recognition) if SOUND OUT (no mic when playing). Easy to implement.
Posted on Reply
#7
WarEagleAU
Bird of Prey
Thats funny. I never thought about it like that. I wonder if this means that Dragon Naturally Speaking (which I think I bought version 4.0 from AOL a loooong time ago) has the same capacity to do such destruction.
Posted on Reply
#8
Alec§taar
WarEagleAUThats funny. I never thought about it like that. I wonder if this means that Dragon Naturally Speaking (which I think I bought version 4.0 from AOL a loooong time ago) has the same capacity to do such destruction.
"StRaNgE & UnUsUaL" attack vectors abound...

:)

* Odd, I agree, but VERY possible!

APK
Posted on Reply
#9
Sasqui
tigger69i wont use speech anyway.and anyone remember how many bugs xp had at first?

i'm using it as my primary os now too.it seems ok to me.
Good point - remember history!!! (It almost ALWAYS repeats itself).
Posted on Reply
#10
W1zzard
so you bring a borg infected tape recorder onto the enterprise and it plays back "initiate self destruct sequence" ?
Posted on Reply
#11
Alec§taar
W1zzardso you bring a borg infected tape recorder onto the enterprise and it plays back "initiate self destruct sequence" ?
Aha! See?

:)

* PROOF, that it "comes w/ the territory" in this field, that being a "Sci-Fi" fan IS truly, part of the mixture required... & that I am NOT THE ONLY ONE!

(LOL!)

APK
Posted on Reply
#12
zekrahminator
McLovin
:roll: You know, speech recognition shouldn't be allowed to do those functions anyways.
Posted on Reply
#13
lemonadesoda
AGREED, speech recog should not have such commands. It should be to "enchance" not substitute use of keyboard and mouse. It should therefore be to improve workflow of common tasks, e.g. the user selects some text, and says "bold"... and hey presto, the format changes. That saves a lot of mouse movement or key clicks.

But file commands... NO. Not unless it is designed for special purpose needs like "advanced handicapped input" for blind people. However, all it takes is for a meanie to walk into their room and say;

"change password to Supercalifragilisticexpialidocius-muhaha-muhaha" followed by

"Supercalifragilisticexpialidocius-muhaha-muhaha"

"yes"

"delete all pictures"

"all"

"delete all documents"

"all"

"logoff"

OUCH :roll:
Posted on Reply
#14
Jimmy 2004
WarEagleAUThats funny. I never thought about it like that. I wonder if this means that Dragon Naturally Speaking (which I think I bought version 4.0 from AOL a loooong time ago) has the same capacity to do such destruction.
It is true that this isn't actually Microsoft messing up so much as the fact that people won't bother exploiting things until they become mainstream - Firefox is (was?) a good example of this. Now it is actively being hacked, which is why it is relatively less secure than it used to be, same goes for voice control.

I think you guys are right - built in voice control shouldn't have such power... but then again, to stop things like this you would need to prevent it doing certain tasks from a command prompt ect. and you can see it might get difficult to prevent all the apps that might have the ability to delete files.
Posted on Reply
#15
Mussels
Freshwater Moderator
"But i dont wanna format my C: drive!"

Vista hears ' Format C:'

Gotta admit - its bloody funny.
Posted on Reply
#16
Lazzer408
tigger69i wont use speech anyway.and anyone remember how many bugs xp had at first?

i'm using it as my primary os now too.it seems ok to me.
Yes and I also remember how much faster XP was before they "patched" all the "bugs". Maybe these "updates" are an excuse to modify a value on the "hidden system latency timer". :rolleyes: If Vista is such a pig now I can't imagine how slow it'll be after a few updates.

I don't think Vista will actually execute system commands from a voice command without some sort of verification prompt...can it? If so that's a major fuk-up on Micro$haft's part.
Posted on Reply
Add your own comment
Nov 30th, 2024 00:28 EST change timezone

New Forum Posts

Popular Reviews

Controversial News Posts