On TechRepublic: The 5 worst tech products of 2009
BNET Business Network:
BNET
TechRepublic
ZDNet

February 1st, 2007

Disagreement over impact of Vista's analog hole

Posted by George Ou @ 11:17 pm

Categories: Browsers, Desktop, News, Security, Vista

Tags:

In Focus » See more posts on: Vista

Since my initial report on the Vista analog hole and getting confirmation of the flaw from Microsoft, Microsoft's MSRC blog downplayed the significance of this exploit and said that there was "there is little if any need to worry about the effects of this issue on your new Windows Vista installation".

The SANS Institute responded:

Fundamentally they acknowledge the problem, they say that they are looking into it and in the meantime give you an excellent pointer to where the issue could cause real harm, i.e. healthcare.

I also have objections to the fact that you can't do anything dangerous with it: downloading and executing a local privilege escalation is still eminently possible, you just need a suitable 0-day local privilege escalation for Vista. Indeed, any way to download and run arbitrary code as a valid user is never good news, this one just happens to be from the "neat trick" pile.

Scott M. Fulton III of BetaNews characterized this best as the "low-tech attack"

After well over a year of unprecedented beta testing, with engineers and amateurs alike poring over the possibilities of rootkits evading API queries deep in the recesses of memory, perhaps it's no wonder that obvious exploits such as this one went unnoticed until Vista was finally released.

InfoWorld Paul Roberts wrote:

Successful attackers would need to be physically present at the machine, or figure out a way to trick the computer's owner to download and play an audio recording of the malicious commands. Even then, the commands would somehow have to be issued without attracting the attention of the computer's owner.

That is not actually correct Paul.  If you've ever been to those annoying MySpace pages or if you've ever seen those annoying popup/pop-under ads that automatically starts blasting music or sounds, you'd know how easy it is to play unwanted sounds on a computer.  People leave their desks all the time with webpages open and webpages can have rotating ads that eventually play sounds.

Finally, attackers’ commands are limited to the access rights of the logged on user, which may prevent access to any administrative commands, Microsoft said in a statement.

As I've mentioned before, this is not a system level attack.  The simulated attack that I pulled off deleted the documents folder and emptied the trash.  Another attack I suggested using TinyURL to simplify a long URL to an EXE payload for download and execution was verified by a security analyst.  That means user-level code can be executed by this "analog hole".  User-level code can easily steal, delete, or encrypt all of your user data for ransom.  Lastly Paul, this is NOT a SHOUTING hack.  The sound levels did not have to be that loud, normal speaker levels worked fine.

The fundamental problem here is that Microsoft "extended" speech to be able to control the Operating System and Applications without considering the full security implications.  If Microsoft had merely assigned a user-defined password with an automatic lockout after a certain amount of idle time, it would have made the generic attack impossible but they failed do that.  So I'm asking Microsoft to reconsider their stance that "there is little if any need to worry" and implement some sort of safety mechanism rather than relying on the user to be self vigilant.  It doesn't matter that there aren't that many people using this feature; Microsoft should fix it if they're going to offer it and market it as a key Vista advantage.  Since Microsoft is promoting Voice recognition for healthcare, we should consider the safety of patient health records.

At present time, Vista Speech Recognition wakes up to the command "start listening".  How hard would it be for Microsoft to make that a user-definable phrase or word?  For example: A user would pick "Zelda" as the word to wake speech mode while someone else picks "439" as their wake word.  How hard would it be for Microsoft to implement a wake timeout so that Speech Recognition would sleep after 5 minutes idle?  How hard would it be for Microsoft to implement their excellent echo cancellation algorithm in Windows Messenger for Speech Recognition?  I don't believe this is too much to ask.

Should Microsoft patch Voice Recognition?

View Results

Loading ... Loading ...

.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 44 Talkback(s)
A cute exploit  Chad_z | 02/02/07
You're beating a dead unicorn  wolf_z | 02/02/07
Overkill?  georgeou | 02/02/07
KISS  perryroyce@... | 02/02/07
I still think that would be the job of the sound card makers  nucrash | 02/02/07
Yeah...that's the ticket.  Cardinal_Bill | 02/03/07
Oh yeah...  Cardinal_Bill | 02/03/07
You need a 3rd option in your poll George  Badgered | 02/02/07
Actually he needs a 4th choice...  IT_Guy_z | 02/02/07
agreed... somewhat  Badgered | 02/02/07
Both speakers and mic are always on  ablemike | 02/02/07
Wasn't Linux that learned that local exploits become bad  nucrash | 02/02/07
Directional Mics  notsofast | 02/02/07
Let nothing get in the way of Microsoft innovation  YinToYourYang-22527499 | 02/02/07
2.0  John L. Ries | 02/02/07
Sort of like  John Zern | 02/02/07
Apple and Linux fans...  John L. Ries | 02/02/07
Per-application audio -- mute IE  PB_z | 02/02/07
We should learn to accomodate.  Media-Ted@... | 02/02/07
6.0  John L. Ries | 02/02/07
CONTACT THE DESIGN ENGINEER  BALTHOR | 02/02/07
The design engineer may be to blame  Tony Agudo | 02/02/07
Or  notsofast | 02/02/07
People used a similar attack almost 30 years ago.  Resuna | 02/02/07
Right  Richard Flude | 02/02/07
In the case of IE7 protected mode, it does protect data  georgeou | 02/02/07
User Voice Recognition?  kuhnm@... | 02/02/07
Doesn't seem to be user-tuned  Tony Agudo | 02/02/07
Interestingly...  bladehawke@... | 02/02/07
Family photos would be worse  georgeou | 02/02/07
And movies too  Tony Agudo | 02/02/07
Don't worry...  UbiquitousGeek | 02/02/07
Just don't use Vista  wizardb@... | 02/02/07
Doesn't Matter. This does:  alflanagan | 02/02/07
PFFT! This isnt even a new idea.  HexHammer67 | 02/03/07
Amazing Genuses Unite On ZDNet  droby10 | 02/03/07
Genuses  droby10 | 02/03/07
Hey George!  Cardinal_Bill | 02/04/07
Remove Microphones  informationworker | 02/05/07
What happens if you can't use a keyboard because you're disabled?  georgeou | 02/06/07
non issue, lame  splama | 02/20/07
All I intend on saying.  g33kz@... | 05/04/07
Tell that to the disabled person if they think this is "lame"  georgeou | 07/31/07
RE: Disagreement over impact of Vista's analog hole  a1931582 | 11/22/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement
Click Here

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads