Sign up for our daily briefing

Make your busy days simpler with Axios AM/PM. Catch up on what's new and why it matters in just 5 minutes.

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Catch up on coronavirus stories and special reports, curated by Mike Allen everyday

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Denver news in your inbox

Catch up on the most important stories affecting your hometown with Axios Denver

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Des Moines news in your inbox

Catch up on the most important stories affecting your hometown with Axios Des Moines

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Minneapolis-St. Paul news in your inbox

Catch up on the most important stories affecting your hometown with Axios Twin Cities

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Tampa Bay news in your inbox

Catch up on the most important stories affecting your hometown with Axios Tampa Bay

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Charlotte news in your inbox

Catch up on the most important stories affecting your hometown with Axios Charlotte

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

Please enter a valid email.

Please enter a valid email.

Subscription failed
Thank you for subscribing!

A new Moen Alexa-enabled shower displayed at the CES conference in January. Photo: Mandel Ngan/AFP via Getty Images

Researchers at the security firm CheckMarx discovered a security flaw in Amazon's Alexa voice enabled digital personal assistant that could have been used to eavesdrop and transcribe any ambient conversation.

But, there are caveats: The flaw requires a user to not only install, but also run a malicious app on Alexa, and not notice Alexa's trademark blue light never turns off. Amazon has now released a patch, meaning it is not an issue for up-to-date Alexa systems.

The details: Alexa lets users install new processes, known as skills. If a criminal developed a skill with some malicious code, CheckMarx discovered some ways to circumvent Amazon's system designed to prevent eavesdropping.

  • Alexa requires apps to periodically alert users it is still listening. But CheckMarx found a way to avoid that safeguard, known as "reprompt." Developers are allowed to set the reprompt message, including a message with no text.
  • Alexa only makes it difficult to transcribe text without specifying the number of words it records. CheckMarx dodged this by telling it to listen for one word sentences, two word sentences and so on and so forth all the way up to needlessly long strings of words.

Go deeper

Texas AG sues Biden administration over deportation freeze

Texas Attorney General Ken Paxton speaks to members of the media in 2016. Photo: Alex Wong/Getty Images

Texas Attorney General Ken Paxton is suing the Biden administration in federal district court over its 100-day freeze on deporting unauthorized immigrants, and he's asking for a temporary restraining order.

Between the lines: The freeze went into effect Friday, temporarily halting most immigration enforcement in the U.S. In the lawsuit, Paxton claims the move "violates the U.S. Constitution, federal immigration and administrative law, and a contractual agreement between Texas" and the Department of Homeland Security.

Dan Primack, author of Pro Rata
1 hour ago - Podcasts

Carbon Health's CEO on unsticking the vaccine bottleneck

President Biden has said that getting Americans vaccinated for COVID-19 is his administration’s top priority given an initial rollout plagued by organizational, logistical and technical glitches.

Axios Re:Cap digs into the bottlenecks and how to unclog them with Carbon Health chief executive Eren Bali, whose company recently began helping to manage vaccinations in Los Angeles.