Hacker News new | ask | show | jobs
by ksaj 2026 days ago
I'd prefer it be treated like passwords - upon installation, you should change the default immediately.

I refuse to use a service that requires me to say its globally recognized name so often I will probably become brainwashed to it. And then there's the older hacks with TV commercials that took advantage of those defaults, and the (cooler) hypersonic transmitted voice command attacks, or the ones delivered by vibrating the device's microphone with a laser, etc.

None of these attacks would have worked if the product trigger wasn't so predictable from the get-go.

Eventually even Raspberry Pi stopped using the default pi/raspberry default combination. How we invoke our voice-activated programs should be treated with equal care.

1 comments

I assume this lets the wakeword listening model be simpler.