• Home
  • News
  • Coins2Day 500
  • Tech
  • Finance
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
TechCybersecurity

Inaudible Soundwaves Expose a Spooky New Pathway for Hackers

By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
By
David Z. Morris
David Z. Morris
Down Arrow Button Icon
October 30, 2016, 1:47 PM ET

In a presentation scheduled for this week’s Black Hat conference in London, security researchers from University College London will outline how new marketing software that uses ultrasound signals could also expose millions of devices to malicious hacking.

The underlying technology in question is known as ultrasonic cross-device tracking, or uXDT. Cross-device tracking has been called a ‘holy grail’ for marketers, allowing them to, for instance, tell your phone when you’re watching a particular TV show, or share data about laptop web browsing to your tablet. A variety of startups and services, including Korea’s Soundlly and the rewards app Shopkick, are developing or using versions of the technology.

Get Data Sheet, Coins2Day ’s technology newsletter.

There are already well-documented concerns about uXDT that have little to do with hackers. In March, the Federal Trade Commission warned several developers using software called Silverpush that they risked violating privacy guidelines by failing to disclose that apps could monitor user’s TV viewing habits.

The UCL team says the lack of disclosure and opt-out options on widely-installed uXDT apps represents an even bigger threat, though. Such apps often actively listen for ultrasound signals, even when the app itself is closed, creating a new and relatively poorly-understood pathway for hacking.

The researchers have already found ways to mine cloaked IP addresses. Speaking to New Scientist, UCL team member Vasilios Mavroudis suggests that an app’s always-on microphone access could be leveraged to monitor conversations (and, if you’re not paranoid already, to decipher what you’re typing). The ‘beacons’ that transmit ultrasound data can also be spoofed to manipulate apps’ user data.

For more on cybersecurity, watch our video.

This isn’t the first time that soundwaves have been implicated in hacking. In 2013, a security consultant named Dragos Ruiu said he witnessed several “air-gapped” machines—those with no Internet, Bluetooth, or other exploitable network connection—nonetheless spread an apparent virus strain he dubbed “badBIOS.” Ruiu initially speculated the persistent infection was being spread between machines via ultrasound. Though researchers have since largely debunked that theory, and though ultrasound can’t carry large amounts of data, something similar seems technically feasible.

The risk of ultrasound is particularly concerning because it’s a candidate for use in communication between the growing mass of Internet of Things devices. There are, according to Mavroudis, currently no standards for securing ultrasound beacons and signals. With last week’s massive IoT botnet attack still fresh in our memory, the UCL researchers are hoping to encourage the development of such standards. In the meantime, they’re also introducing a patch for Android that will allow better user supervision of ultrasound access.

About the Author
By David Z. Morris
See full bioRight Arrow Button Icon
Rankings
  • 100 Best Companies
  • Coins2Day 500
  • Global 500
  • Coins2Day 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Leadership
  • Success
  • Tech
  • Asia
  • Europe
  • Environment
  • Coins2Day Crypto
  • Health
  • Retail
  • Lifestyle
  • Politics
  • Newsletters
  • Magazine
  • Features
  • Commentary
  • Mpw
  • CEO Initiative
  • Conferences
  • Personal Finance
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Coins2Day Brand Studio
  • Coins2Day Analytics
  • Coins2Day Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Coins2Day
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map

© 2025 Coins2Day Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Coins2Day Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.