Voice assistants: 7 reflexes to protect your data and take back control

Voice assistants such as Alexa, Siri or Google Assistant are taking an increasingly important place in our daily lives. They can play music, create reminders, answer our questions, make purchases or control the connected objects in the home. Behind this simplicity, however, hides a device that is constantly connected to the Internet, to a personal account and sometimes to several other technologies. Default settings, retention of voice commands, access to the main account or unintentional activation of the microphone: voice assistants can expose personal information and present certain risks to our privacy and digital security. Here are seven reflexes to adopt so you can enjoy their convenience while keeping control over your data.

Sarine Bedrossian
By Sarine Bedrossian ·

assistants-vocaux-7-reflexes-pour-proteger-vos-donnees-et-reprendre-le-controle

A voice assistant is much more than a simple smart speaker. To respond to its user’s commands, it must be connected to a network, to an application and generally to an Amazon, Google or Apple account.

Depending on the features used, it can also be linked to smart bulbs, cameras, a television, a lock, a thermostat, a calendar, a contact list or a payment method.

All these connections make the device convenient, but they also increase the amount of data and personal information it can access. A poor configuration can therefore have consequences on your privacy and your digital identity.

This does not mean you necessarily have to give up voice assistants. Instead, you need to understand how they work, limit unnecessary features and adopt a few good practices.

1. Check the settings enabled by default

When you set up a voice assistant, several settings are proposed or enabled automatically. In the rush to finish the installation, it is easy to accept all the options without really understanding what they are for.

Some features notably allow the device to:

  • communicate with other nearby devices
  • automatically connect to smart objects
  • share part of the internet connection
  • keep a history of voice commands
  • use certain recordings to improve services
  • authorize purchases by voice command
  • access external applications or services

These options are not necessarily dangerous. However, when they are enabled without being used, they can create additional access points and reduce the control you have over the device.

It is a bit like leaving several doors ajar in a house. Each door may have a purpose, but it should not stay open if no one is using it.

So take the time to review the settings of the application associated with your assistant, such as Alexa, Google Home or Apple Home.

Disable the features that do not match your needs. As a general rule, a device should only have access to the information and services necessary for its operation.

Also make sure the voice assistant is connected to a secure Wi-Fi network. The network should be protected by a strong password and use a recent security protocol. Avoid connecting this type of device to a public or shared network whose configuration you do not control.

2. Limit connections with your other devices

One of the main advantages of voice assistants is their ability to control several connected objects. With a single command, you can turn on the lights, adjust the temperature, start the television or check a camera.

However, the more the assistant is connected to other devices, the greater the consequences can be if the main account is compromised.

Someone who manages to access this account could potentially view the linked devices, change certain settings or obtain information about the user’s habits.

Before connecting a new object to your voice assistant, ask yourself the following questions:

  • Is this connection really necessary?
  • What type of data does the device share?
  • Does the connected object still receive security updates?
  • Is it protected by a unique password?
  • Can it be controlled remotely?
  • Does it present a significant risk if it is compromised?

Avoid needlessly connecting sensitive devices, particularly locks, cameras, alarm systems or devices that give access to private information.

Also remember to regularly review the list of devices associated with your assistant. Remove old objects, devices you no longer use and connections you do not recognize.

3. Secure the account associated with the voice assistant

A voice assistant is generally linked to an Amazon, Google or Apple account. This account is the real control center of the device.

It can contain your name, your address, your phone number, your payment methods, your purchase history, your connected devices and certain information about your habits. Together, this information makes it possible to build a detailed picture of your digital identity and your lifestyle.

In other words, this account is a far more interesting target for fraudsters than the speaker itself.

If it is compromised, a malicious person could access a large amount of information. They could also use this information to prepare a highly personalized phishing attempt.

For example, a fraudster who knows the services you use, the products you buy or the devices you own can create a particularly convincing email or text message.

Securing only the voice assistant without protecting the main account is like installing a sophisticated alarm system but leaving the key under the mat.

To protect your account:

  • use a long, strong and unique password
  • do not use this password for another service
  • enable two-factor authentication
  • check the devices connected to the account
  • disconnect the devices you do not recognize
  • monitor login notifications
  • remove old access and unused applications

Also avoid sharing the main password with every member of the family or the team. When the service allows it, instead create separate profiles with access tailored to each user.

4. Manage purchases and sensitive commands

Some voice assistants allow you to make purchases, add products to an order or access paid services simply by using your voice.

This option can be convenient, but it can also lead to accidental or unauthorized purchases. A child, a visitor or even a recording played nearby could trigger a command in certain circumstances.

If you do not use voice purchases, the best reflex is to disable them.

If you want to keep this feature, add a validation step, such as:

  • a confidential code
  • a confirmation in the application
  • voice recognition
  • a purchase limit
  • a notification sent after each transaction

Also check whether a payment method is registered in the account. It is not always necessary to keep a credit card associated with the voice assistant.

Voice recognition can help the device distinguish certain users, but it should not be considered an infallible security measure. A voice can be imitated, recorded or reproduced.

Important commands should therefore always require a second form of confirmation.

5. Control the microphone and the context of use

To detect its trigger word, a voice assistant must keep listening to the sounds around it. This can be, for example, “Alexa,” “Siri” or “Hey Google.”

In principle, the device begins processing the command after hearing this word. However, it can sometimes activate by mistake when a phrase, a sound or a conversation resembles the trigger word.

Part of the conversation may then be captured and transmitted to the provider’s servers. The context of use is therefore particularly important.

A voice assistant installed in a living room does not present the same issues as a device located in a meeting room, a closed office or a space where confidential information is regularly exchanged.

In a professional environment, the device could capture discussions concerning:

  • personal information
  • client files
  • financial information
  • confidential projects
  • passwords or access codes
  • internal decisions
  • information about employees
  • security incidents

Before installing a voice assistant in a workplace, ask yourself whether it is really necessary and whether its use is compatible with the nature of the information that circulates in that space.

During a confidential discussion, mute the microphone or unplug the device completely. On some models, an indicator light shows that the microphone is disabled.

Depending on the device, it is also possible to temporarily disable listening for the trigger word or to change the settings related to voice activation.

6. Review and delete the voice history

The commands given to a voice assistant can be recorded in the user’s account. These recordings notably make it possible to review previous requests or to improve the device’s understanding.

However, few users think to check what is actually kept.

By reviewing the history, it is sometimes possible to discover accidental activations, excerpts of conversations or commands you did not remember making.

Get into the habit of regularly checking:

  • the recorded commands
  • the involuntary activations
  • the devices that have used the account
  • how long the recordings are kept
  • the permissions allowing the provider to analyze the voice excerpts

Depending on the service used, you may be able to manually delete the recordings, schedule their automatic deletion or ask the assistant to erase them by voice command.

Choose the shortest retention period that matches your needs.

7. Update the device regularly

Like a computer or a phone, a voice assistant runs on software that must be updated.

These updates can fix bugs, improve features and resolve security vulnerabilities. A device that no longer receives updates can become more vulnerable over time.

In most cases, voice assistants install their updates automatically. It nonetheless remains important to check that:

  • the device is still supported by its manufacturer
  • automatic updates are enabled
  • the associated mobile application is up to date
  • the connected objects controlled by the assistant are also updated

If a device is too old and no longer receives patches, it may be preferable to replace it or disconnect it from the network.

Here then are our seven recommendations for using a voice assistant more securely:

  1. Check the settings enabled by default.
  2. Limit connections with your other devices.
  3. Secure the account associated with the voice assistant.
  4. Manage purchases and sensitive commands.
  5. Control the microphone and the context of use.
  6. Review and delete the voice history regularly.
  7. Keep the device and its applications up to date.

Voice assistants can simplify many tasks, but their use relies on a constant exchange of data between the device, the user’s account and the provider’s services.

The goal is not necessarily to eliminate them from our daily lives, but to use them consciously. A few minutes devoted to settings, permissions and account security can considerably reduce the risks.

A connected device should never have more access than it truly needs.

WHO ARE WE?

Our mission is to train companies to adopt better online practices, to push back fraudsters and hackers, and to prevent so many years of effort from evaporating in a single click!

When we think about cybersecurity, we think about technologies and infrastructures. Why do we forget that the user plays a role in 90% of attacks and scams? We specialize in corporate cybersecurity training and fraud prevention.

For more information, visit our Training section.

Subscribe to our newsletter

Receive one email per month to improve your cybersecurity practices

subscribe

Rest assured that the data you share with us remains confidential.