Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

The New Coffee Room

  1. TNCR
  2. General Discussion
  3. Amazon Sidewalk

Amazon Sidewalk

Scheduled Pinned Locked Moved General Discussion
9 Posts 6 Posters 68 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • MikM Offline
    MikM Offline
    Mik
    wrote on last edited by
    #1

    Do you want to share with your neighbors? Another good reason why I do not have a device in my house that listens to what I say and orders stuff it thinks I want.

    https://www.forbes.com/sites/paullamkin/2020/11/27/what-is-amazon-sidewalk-and-why-is-it-on-your-echo-smart-speaker/?sh=18f9444acfd5

    "The intelligent man who is proud of his intelligence is like the condemned man who is proud of his large cell." Simone Weil

    George KG 1 Reply Last reply
    • MikM Mik

      Do you want to share with your neighbors? Another good reason why I do not have a device in my house that listens to what I say and orders stuff it thinks I want.

      https://www.forbes.com/sites/paullamkin/2020/11/27/what-is-amazon-sidewalk-and-why-is-it-on-your-echo-smart-speaker/?sh=18f9444acfd5

      George KG Offline
      George KG Offline
      George K
      wrote on last edited by
      #2

      @Mik said in Amazon Sidewalk:

      Do you want to share with your neighbors? Another good reason why I do not have a device in my house that listens to what I say and orders stuff it thinks I want.

      https://www.forbes.com/sites/paullamkin/2020/11/27/what-is-amazon-sidewalk-and-why-is-it-on-your-echo-smart-speaker/?sh=18f9444acfd5

      Not no, but hell no.

      It's the same reason I didn't get an XFinity router/modem for my internet. You can be part of "XFinityWiFi" and allow guests to hop onto your part of a larger network.

      Screen Shot 2020-12-05 at 11.14.49 AM.png

      "Now look here, you Baltic gas passer... " - Mik, 6/14/08

      The saying, "Lite is just one damn thing after another," is a gross understatement. The damn things overlap.

      1 Reply Last reply
      • AxtremusA Away
        AxtremusA Away
        Axtremus
        wrote on last edited by
        #3

        “Amazon Sidewalk” is arguably worse than XfinityWifi in that, when Comcast sticks XfinityWifi into your Comcast-provided routers, Comcast have enough sense to use a separate channel for XfinityWifi data traffic, separate from your own data traffic, and where there are “data caps” Comcast knows to separately account for XfinityWifi traffic so it won’t count against your “data cap.” “Amazon Sidewalk” gives your no such consideration, Amazon by itself has no capability to get your ISP to separately account for “Amazon Sidewalk” traffic apart from your regular data traffic. So, yeah, you will foot the bill to carry the data traffic for “Amazon Sidewalk.”

        1 Reply Last reply
        • George KG Offline
          George KG Offline
          George K
          wrote on last edited by
          #4

          More good news from Amazon.

          Remember that Echo Dot you "reset" and sold on eBay?

          Guess what, you didn't wipe it after all.

          https://arstechnica.com/gadgets/2021/07/passwords-in-amazon-echo-dots-live-on-even-after-you-factory-reset-them/

          Researchers from Northeastern University bought 86 used devices on eBay and at flea markets over a span of 16 months. They first examined the purchased devices to see which ones had been factory reset and which hadn’t. Their first surprise: 61 percent of them had not been reset. Without a reset, recovering the previous owners' Wi-Fi passwords, router MAC addresses, Amazon account credentials, and information about connected devices was a relatively easy process.

          The next surprise came when the researchers disassembled the devices and forensically examined the contents stored in their memory.

          “An adversary with physical access to such devices (e.g., purchasing a used one) can retrieve sensitive information such as Wi-Fi credentials, the physical location of (previous) owners, and cyber-physical devices (e.g., cameras, door locks),” the researchers wrote in a research paper. “We show that such information, including all previous passwords and tokens, remains on the flash memory, even after a factory reset.”

          In addition to the 86 used devices, the researchers bought six new Echo Dot devices and over a span of several weeks provisioned them with test accounts at different geographic locations and different Wi-Fi access points. The researchers paired the provisioned devices to different smart home and Bluetooth devices. The researchers then extracted the flash contents from these still-provisioned devices using the techniques described earlier.

          After extracting the flash contents from their six new devices, the researchers used the Autospy forensic tool to search embedded multimedia card images. The researchers analyzed NAND dumps manually. They found the name of the Amazon account owner multiple times, along with the complete contents of the wpa_supplicant.conf file, which stores a list of networks the devices have previously connected to, along with the encryption key they used. Recovered log files also provided lots of personal information.

          Because the researchers provisioned the devices themselves, they knew what kinds of information the devices stored. They used this knowledge to create a list of keywords to locate specific types of data in four categories: information about the owner, Wi-Fi-related data, information about paired devices, and geographic information. Knowing what kinds of data are on the device can be helpful, but it’s not necessary for carrying out the attack.

          After dumping and analyzing the recovered data, the researchers reassembled the devices. The researchers wrote:

          "We confirmed that the device connected successfully, and we were able to issue voice commands to the device. When asked “Alexa, Who am I?”, the device would return the previous owner’s name. The re-connection to the spoofed access point did not produce a notice in the Alexa app nor a notification by email. The requests are logged under “Activity” in the Alexa app, but they can be deleted via voice commands. We were able to control smart home devices, query package delivery dates, create orders, get music lists and use the “drop-in” feature."

          "One of the queries is “Alexa, Who am I,” and the device will tell the owner's name. All services that the previous owner used are accessible. For example, you can manage your calendar through the Echo. Also, the Echo will get notifications when packages are about to arrive or you can use the Drop-In feature (as in, talking to another Echo of yours). If someone does not use any smart home devices, then you obviously cannot control them.

          "Now look here, you Baltic gas passer... " - Mik, 6/14/08

          The saying, "Lite is just one damn thing after another," is a gross understatement. The damn things overlap.

          1 Reply Last reply
          • L Offline
            L Offline
            Loki
            wrote on last edited by
            #5

            It’s still just a gadget to me and it never found a useful place in my life. Play Jeopardy on it with the fam and then unplug it again.

            George KG 1 Reply Last reply
            • L Loki

              It’s still just a gadget to me and it never found a useful place in my life. Play Jeopardy on it with the fam and then unplug it again.

              George KG Offline
              George KG Offline
              George K
              wrote on last edited by
              #6

              @loki said in Amazon Sidewalk:

              It’s still just a gadget to me and it never found a useful place in my life. Play Jeopardy on it with the fam and then unplug it again.

              When you want to get rid of it, break it into little pieces with a hammer...

              "Now look here, you Baltic gas passer... " - Mik, 6/14/08

              The saying, "Lite is just one damn thing after another," is a gross understatement. The damn things overlap.

              1 Reply Last reply
              • MikM Offline
                MikM Offline
                Mik
                wrote on last edited by
                #7

                Never had one, never will.

                "The intelligent man who is proud of his intelligence is like the condemned man who is proud of his large cell." Simone Weil

                1 Reply Last reply
                • Catseye3C Offline
                  Catseye3C Offline
                  Catseye3
                  wrote on last edited by
                  #8

                  It's getting harder for marketers to flog stuff that they can successfully convince us we can't live without.

                  Success is measured by your discipline and inner peace. – Mike Ditka

                  1 Reply Last reply
                  • KlausK Offline
                    KlausK Offline
                    Klaus
                    wrote on last edited by
                    #9

                    be aware that Sidewalk can only manage a speed of 80Kbps

                    Costs for traffic wouldn't be my main concern.

                    Theoretically, it would be possible to design such a system in a secure way, or at least as secure as your WiFi password, but one has to have a lot of trust in Amazon and there is no way to check what they are actually doing.

                    1 Reply Last reply
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Don't have an account? Register

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • Users
                    • Groups