techPowerUp! Forums

Go Back   techPowerUp! Forums > www.techpowerup.com > News

Reply
 
Thread Tools
Old Feb 2, 2007, 02:52 PM   #1
Jimmy 2004
Eligible for custom title
 
Jimmy 2004's Avatar
 
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.65/day)
Thanks: 134
Thanked 276 Times in 185 Posts
Send a message via MSN to Jimmy 2004

System Specs

Vista Speech Recognition Flaw

Three days after being released, the first major flaw has been published for Windows Vista. For anyone with speech recognition enabled, malicious websites or audio files could potentially give commands to hijack the PC and tell it to delete files. It works by playing commands such as shutdown, copy or delete through the speakers which could then be picked up by the microphone, causing the computer to carry out certain tasks. Microsoft admits that the exploit is “technically possible” but doesn’t see it as a major problem. This flaw is more down to new features than problems with the coding of Vista, and it shouldn’t be a problem for most people.

Source: BBC News
Jimmy 2004 is offline  
Reply With Quote
Old Feb 2, 2007, 03:39 PM   #2
EviLZeD
500 Posts
 
EviLZeD's Avatar
 
Join Date: Sep 2006
Posts: 649 (0.27/day)
Thanks: 30
Thanked 48 Times in 44 Posts

System Specs

hehe vista is so stable and bug free
EviLZeD is offline  
Reply With Quote
Old Feb 2, 2007, 03:59 PM   #3
EastCoasthandle
Eligible for custom title
 
EastCoasthandle's Avatar
 
Join Date: Apr 2005
Posts: 6,244 (2.11/day)
Thanks: 382
Thanked 1,526 Times in 865 Posts

System Specs

This makes using AIM, yahoo messenger, etc a cautious thing indeed when speech recognition is enabled. Using the mic feature in these online chatting programs can re-create this very problem.

For example, you decide you want to use the mic feature instead of text messaging and you say:
Quote:
Delete C.....
opposing user's response when balloon pops up on screen = "how did you do that?"
Quote:
......YES, continue
opposing user's response = "wait, stop that!"
[user disconnected]

Wash, rinse, repeat.
EastCoasthandle is offline  
Reply With Quote
Old Feb 2, 2007, 04:02 PM   #4
bhaskar15
75 Posts
 
Join Date: Dec 2006
Posts: 130 (0.06/day)
Thanks: 0
Thanked 0 Times in 0 Posts

System Specs

hmm,this flaw isn't a risk for me. I mostly never use speech recognition while online.
__________________
When u have power it shows.
When u have TPU beside u, it rocks !!
When u have GOD beside u, umm....he's gonna call u up there soon
bhaskar15 is offline  
Reply With Quote
Old Feb 2, 2007, 04:15 PM   #5
tigger
I'm the only one
 
tigger's Avatar
 
Join Date: Mar 2006
Location: HU5 1LL
Posts: 7,214 (2.75/day)
Thanks: 474
Thanked 951 Times in 780 Posts
Send a message via MSN to tigger

System Specs

i wont use speech anyway.and anyone remember how many bugs xp had at first?

i'm using it as my primary os now too.it seems ok to me.
tigger is offline  
Reply With Quote
Old Feb 2, 2007, 05:17 PM   #6
Benpi
Banned
 
Join Date: Dec 2006
Posts: 415 (0.18/day)
Thanks: 6
Thanked 3 Times in 3 Posts

System Specs

LoL, this isn't a hack. So basically if someone puts an audio clip on their website that says "Open My Docuoments, Delete, Empty Recycle Bin" and your speakers are loud enough to be picked up by a mic, and you happen to have voice recognition on, you'll lose your documents folder...... people just try to find things to write stories about. This is retarded.
Benpi is offline  
Reply With Quote
Old Feb 2, 2007, 05:35 PM   #7
lemonadesoda
Eligible for custom title
 
lemonadesoda's Avatar
 
Join Date: Aug 2006
Posts: 5,337 (2.17/day)
Thanks: 749
Thanked 960 Times in 710 Posts

System Specs

This is hilarious! Can't imagine that Vista programmers were so short sighted. Easily solved with a patch. No speech recognition (command recognition) if SOUND OUT (no mic when playing). Easy to implement.
lemonadesoda is offline  
Reply With Quote
Old Feb 2, 2007, 06:07 PM   #8
WarEagleAU
Bird of Prey
 
WarEagleAU's Avatar
 
Join Date: Jul 2006
Location: Gurley, AL
Posts: 9,994 (3.98/day)
Thanks: 3,810
Thanked 557 Times in 521 Posts
Send a message via AIM to WarEagleAU Send a message via Yahoo to WarEagleAU

System Specs

Thats funny. I never thought about it like that. I wonder if this means that Dragon Naturally Speaking (which I think I bought version 4.0 from AOL a loooong time ago) has the same capacity to do such destruction.
__________________
=-TheEagle-=



http://www.heatware.com/eval.php?id=62454
“You crazy? Surfing any website without an antivirus is like freaking with a dirty woman without protection” -OzzmanFloyd120
- Edited for content and clarity
WarEagleAU is offline  
Reply With Quote
Old Feb 2, 2007, 06:36 PM   #9
Alec§taar
Banned
 
Alec§taar's Avatar
 
Join Date: May 2006
Location: Someone who's going to find NewTekie1 and teach him a lesson
Posts: 3,380 (1.32/day)
Thanks: 0
Thanked 102 Times in 101 Posts

System Specs

Quote:
Originally Posted by WarEagleAU View Post
Thats funny. I never thought about it like that. I wonder if this means that Dragon Naturally Speaking (which I think I bought version 4.0 from AOL a loooong time ago) has the same capacity to do such destruction.
"StRaNgE & UnUsUaL" attack vectors abound...



* Odd, I agree, but VERY possible!

APK
Alec§taar is offline  
Reply With Quote
Old Feb 2, 2007, 06:37 PM   #10
Sasqui
Eligible for custom title
 
Sasqui's Avatar
 
Join Date: Dec 2005
Location: Manchester, NH
Posts: 6,066 (2.22/day)
Thanks: 827
Thanked 913 Times in 746 Posts

System Specs

Quote:
Originally Posted by tigger69 View Post
i wont use speech anyway.and anyone remember how many bugs xp had at first?

i'm using it as my primary os now too.it seems ok to me.
Good point - remember history!!! (It almost ALWAYS repeats itself).
Sasqui is offline  
Reply With Quote
Old Feb 2, 2007, 06:42 PM   #11
W1zzard
Benevolent Dictator
 
W1zzard's Avatar
 
Join Date: May 2004
Location: Stuttgart, Germany
Posts: 13,793 (4.18/day)
Thanks: 184
Thanked 10,293 Times in 3,176 Posts
Send a message via ICQ to W1zzard Send a message via AIM to W1zzard Send a message via MSN to W1zzard

System Specs

so you bring a borg infected tape recorder onto the enterprise and it plays back "initiate self destruct sequence" ?
W1zzard is online now  
Reply With Quote
Old Feb 2, 2007, 06:44 PM   #12
Alec§taar
Banned
 
Alec§taar's Avatar
 
Join Date: May 2006
Location: Someone who's going to find NewTekie1 and teach him a lesson
Posts: 3,380 (1.32/day)
Thanks: 0
Thanked 102 Times in 101 Posts

System Specs

Quote:
Originally Posted by W1zzard View Post
so you bring a borg infected tape recorder onto the enterprise and it plays back "initiate self destruct sequence" ?
Aha! See?



* PROOF, that it "comes w/ the territory" in this field, that being a "Sci-Fi" fan IS truly, part of the mixture required... & that I am NOT THE ONLY ONE!

(LOL!)

APK
Alec§taar is offline  
Reply With Quote
Old Feb 2, 2007, 06:53 PM   #13
zekrahminator
McLovin
 
zekrahminator's Avatar
 
Join Date: Jan 2006
Location: My house.
Posts: 6,280 (2.35/day)
Thanks: 105
Thanked 340 Times in 246 Posts
Send a message via ICQ to zekrahminator Send a message via AIM to zekrahminator Send a message via MSN to zekrahminator

System Specs

You know, speech recognition shouldn't be allowed to do those functions anyways.
__________________
“Just because you're hung like a moose doesn't mean you should do porn.”
zekrahminator is offline  
Reply With Quote
Old Feb 2, 2007, 07:02 PM   #14
lemonadesoda
Eligible for custom title
 
lemonadesoda's Avatar
 
Join Date: Aug 2006
Posts: 5,337 (2.17/day)
Thanks: 749
Thanked 960 Times in 710 Posts

System Specs

AGREED, speech recog should not have such commands. It should be to "enchance" not substitute use of keyboard and mouse. It should therefore be to improve workflow of common tasks, e.g. the user selects some text, and says "bold"... and hey presto, the format changes. That saves a lot of mouse movement or key clicks.

But file commands... NO. Not unless it is designed for special purpose needs like "advanced handicapped input" for blind people. However, all it takes is for a meanie to walk into their room and say;

"change password to Supercalifragilisticexpialidocius-muhaha-muhaha" followed by

"Supercalifragilisticexpialidocius-muhaha-muhaha"

"yes"

"delete all pictures"

"all"

"delete all documents"

"all"

"logoff"

OUCH

Last edited by lemonadesoda; Feb 2, 2007 at 07:19 PM.
lemonadesoda is offline  
Reply With Quote
Old Feb 2, 2007, 07:18 PM   #15
Jimmy 2004
Eligible for custom title
 
Jimmy 2004's Avatar
 
Join Date: Jan 2005
Location: England
Posts: 5,047 (1.65/day)
Thanks: 134
Thanked 276 Times in 185 Posts
Send a message via MSN to Jimmy 2004

System Specs

Quote:
Originally Posted by WarEagleAU View Post
Thats funny. I never thought about it like that. I wonder if this means that Dragon Naturally Speaking (which I think I bought version 4.0 from AOL a loooong time ago) has the same capacity to do such destruction.
It is true that this isn't actually Microsoft messing up so much as the fact that people won't bother exploiting things until they become mainstream - Firefox is (was?) a good example of this. Now it is actively being hacked, which is why it is relatively less secure than it used to be, same goes for voice control.

I think you guys are right - built in voice control shouldn't have such power... but then again, to stop things like this you would need to prevent it doing certain tasks from a command prompt ect. and you can see it might get difficult to prevent all the apps that might have the ability to delete files.
Jimmy 2004 is offline  
Reply With Quote
Old Feb 3, 2007, 12:37 AM   #16
Mussels
Doctor Moderator
 
Mussels's Avatar
 
Join Date: Oct 2004
Location: Bendigo, Australia (NOT THE USA)
Posts: 34,561 (10.96/day)
Thanks: 3,700
Thanked 8,697 Times in 6,394 Posts

System Specs

"But i dont wanna format my C: drive!"

Vista hears ' Format C:'

Gotta admit - its bloody funny.
Mussels is offline  
Reply With Quote
Old Feb 3, 2007, 12:43 AM   #17
Lazzer408
2000 Posts
 
Lazzer408's Avatar
 
Join Date: Jan 2007
Location: Illinois
Posts: 2,394 (1.03/day)
Thanks: 80
Thanked 320 Times in 242 Posts

System Specs

Quote:
Originally Posted by tigger69 View Post
i wont use speech anyway.and anyone remember how many bugs xp had at first?

i'm using it as my primary os now too.it seems ok to me.
Yes and I also remember how much faster XP was before they "patched" all the "bugs". Maybe these "updates" are an excuse to modify a value on the "hidden system latency timer". If Vista is such a pig now I can't imagine how slow it'll be after a few updates.

I don't think Vista will actually execute system commands from a voice command without some sort of verification prompt...can it? If so that's a major fuk-up on Micro$haft's part.
Lazzer408 is offline  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT. The time now is 06:28 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts