News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Network Security
Average Rating:
Rate this article:  
Microsoft Downplays Vista Speech-Recognition Hack Microsoft Downplays Vista Speech-Recognition Hack
By Jennifer LeClaire
February 2, 2007 8:27AM

    Bookmark and Share
In light of reports about the speech-recognition exploit, Microsoft is saying that Vista's User Account Control feature -- the new feature responsible for not giving rogue programs administrator-level access to key operating system functions -- can't be circumvented by speech commands. Most security researchers appear to be siding with Microsoft's stance on the issue.
 

Advertisement

According to security Relevant Products/Services researchers, Windows Vista's speech-recognition feature is flawed and hackers could use it to remotely force a PC to execute commands.

Microsoft Relevant Products/Services confirmed the vulnerability on Wednesday -- a day after the consumer launch of the new operating system -- when security researchers began offering details on how pranksters could exploit the speech technology. A malicious Web site, for example, could load an audio file that shouts commands to shut down the operating system without the user's authorization.

While some security researchers believe Vista's first public flaw is, in fact, serious, Microsoft is downplaying the risk, noting that a targeted system's speech-recognition feature would need to be configured correctly for the attack to be successful.

Microsoft Speaks Out

According to the Microsoft Security Response Center (MSRC), a microphone would have to be installed and the speakers turned on for malicious users to take advantage of the weakness. "The exploit scenario would involve the speech-recognition feature picking up commands [from the speaker] through the microphone such as 'copy,' 'delete,' shutdown,' etc. and acting on them," Adrian Stone, MSRC program manager, wrote in an MSRC blog post.

Microsoft maintains that Vista's User Account Control (UAC) feature -- the new Vista feature responsible for not giving rogue programs administrator-level access to key operating system functions without first getting approval from users -- can't be circumvented by speech commands. And Stone said he is confident that consumers don't need to worry about the issue. Microsoft is nonetheless taking the reports seriously and investigating them accordingly, Stone added.

However, Symantec argues that the risk is greater than Microsoft is reporting. "A poster on the Daily Dave mailing [list has] reported that he was able to craft a recording that successfully downloaded and executed a file from the Internet as well as manipulated the file system without requiring user interaction," Symantec said in an alert released to customers.

Much Ado About Nothing?

Most security researchers, however, appear to be siding with Microsoft's stance on the issue. "We don't think this is going to become a big deal in the real world. I guess this shows just how hard it is to think of all possible ways of attacking a system," said Mikko Hypponen, a security researcher with F-Secure.

Fred Doyle, an analyst at Verisign iDefense, said he was not surprised by the flaw. He recalled a similar flaw in the Macintosh operating system that allowed people to shut down a computer by shouting the command from afar. Like Hypponen, Doyle doesn't rate the risk high priority because the speech-recognition feature is not widely used. "As with any new release of any new software, there are bound to be some issues that were overlooked in the design," he explained. "We are researching at this time several potential flaws."

Proof of concepts on the speech-recognition flaw have been published, but Doyle said he is not aware of any malicious Web sites that are actively exploiting the vulnerability. Vista users who are concerned about the vulnerability can simply deactivate the speech-recognition feature until Microsoft issues a patch, he said.

Thomas Kristensen, CTO at Secunia, offered a similar take. "We don't really consider this a vulnerability and only a marginal group of people with this specific support Relevant Products/Services for the disabled are at risk," he said. "The average user need not be concerned about this."
 

Advertisement


Advertisement


 Network Security
1.   Peer-to-Peer Software Ban Sought
2.   Los Alamos Computer Security Weak
3.   Security Firm Fortinet Plans IPO
4.   Heartland Restraining Order Denied
5.   Social-Networking Security a Concern


advertisement
Social-Networking Security a ConcernSocial-Networking Security a Concern
Facebook hijacking shows dangers.
Average Rating:
ICANN Approves International NamesICANN Approves International Names
Dramatic increase in users expected.
Average Rating:
Center Opens To Battle CybercrimeCenter Opens To Battle Cybercrime
Increasing threat from hackers seen.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware

  Go Green with IBM Blade Center
  

Network Security Spotlight
House Lawmakers Push Ban on Peer-to-Peer Software
Stung by an embarrassing electronic leak revealing ethics investigations into dozens of lawmakers, Congress moved to prohibit federal employees from using the file-sharing software blamed for the disclosure.
 
GAO: Los Alamos Computer Security Has Weaknesses
Security weaknesses uncovered in Los Alamos National Laboratory's computer network increase the risk of a classified-information breach, says the Government Accountability Office.
 
Computer Security Firm Fortinet Plans IPO This Week
Fortinet plans to go public in an initial public offering, giving investors a chance to tap a network security provider with sales that are expected to grow. The IPO could be valued at $137.5 million or more.
 

Enterprise Hardware Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
New Pogoplug 'Personal Cloud' Does Social Networking
Cloud Engines has released its newest version of the Pogoplug, a small "multimedia sharing device" that connects hard drives to the Internet and allows a user to access the files remotely.
 
Apple Tablet Rumored Delayed as Publisher Gears Up
There have been so many rumors of an Apple tablet that it has taken on legendary status. But now the legend is being revised with reports of a delay and that a major publisher is getting ready.
 

Enterprise Technology Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
Smartphones: A Bigger Target for Security Threats
Smartphones are increasingly prevalent and adept at handling more tasks, including trading stocks, paying bills, and buying stuff online. That makes them attractive to thieves and hackers.
 
FBI Says Hackers Targeting Law Firms, PR Companies
Hackers are targeting law firms and public relations companies with a sophisticated e-mail scheme that breaks into their computer networks to steal sensitive data, often linked to large corporate clients.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.