
it away hello everyone thank you for coming and joining us today so today we going to talk about easier voice private so how many of us haven't used any voice assistant devices like anything in our phone watch or any digital device or gadgets is there anyone who don't know what is voice assistant devices anyone no so we all know what is voice assistant devices are so before I start who am I so I'm a security operation analyst working in LD automotives limited and I have done my masters in cyber defense and information assurance from Cranfield University then I upill my cyber knowledge with caps lock and before that I used to work in Telecom operator and vendor for for
almost over 5 years so why I said about voice assistant device why this topic so we are living in a digital era where we are being introduced with lots and lots of digital gadgets or devices incor incorporating voice then AI machine learning and so many so yeah we are using Voice Assistant devices quite a lot not only in our personal life but also in professional life as well so they are almost everywhere helping us securing securing our home entertain us and also for Disabilities so first let's say hi to my friend Alexa she was with me when I was doing my graduation over here in UK thousands miles away from my family and friends hybrid classes being all alone
in the home and yes it was very sometimes very boring and she was the per she was the device not the person sorry so she was the device who used to entertain me sing for me sometimes play very weird songs as well very weird answers and but she used to entertain me a lot so yeah and from there when I was doing my graduation and I have to submit my desertation I was started thinking what sort of topic I should pick up for my desertation and I was thinking something that is related to human so that I know about the human Centric vision and also like something which is we commonly use and have cyber threats so that time as I
used to spend a lot of time with Alexa so I started thinking about the benefits of using it so yes there are many benefits first it's efficiency so we can set alarms very easily reminders which is very good then it also help us to Smart our home so we have different control devices which we can operate by this device just saying our voice commands are saying turn on turn off and lock it down and so many then it can also be helpful for accessibility so those people who don't have like or have any issues with Mobility they can use this kind of device put some voice commands and you like utilize a lot of benefits from their and do their daily
jobs as well as these devices are also used to enhance our security in terms of our home security and so on so on so as these devices has a lot of benefits obviously we started I started thinking what are the concern as I was a student from the security or cyber defense so I started thinking what kind of vulnerabilities are there or what kind of concerns using these devices when I am using it or someone is using it so first of course the sensitive information so these devices hold a lot of information of ours when we are commanding any voice command or turning the devices on by saying Alexa or Siri so they started listening to us and they
hold those data in their servers so yes that's a sensitive information sometimes LED also being our privacy issue so when we are using our delivering sensitive information we also sometimes giving them the access to our privacy they listen to our con like confidential conversation with our partners Maybe then these devices also used a lot to spread malwares there are incidents which I came across like that are very handy tool because this is an iot device as well which is a lot times used for spreading malwest and as like any other cyber TR as it also has Financial loss aspects as well if you not intentional but share your bank credentials and it was listening it can
be stored those information in the device and that can be used afterwards and when you are using those device or hearing about incidents you might not trust those device anymore or would not like to use them which may come for the manufacturers lacking Trust on them and they might lose their business so when I came across all the concerns I started thinking what are the threats are so first misinterpreting wake words that happened with me a lot for example in Bangla that's my mother language we used to say stairs CD and whenever I'm talking with my parents or something and if I come across CD saying them are you going upstairs with the city and my city turns on and say I'm
listening which I definitely don't want so yes so this how it turned up and sometimes unintentionally these devices got turn up as well from maybe you are watching a television ad or something where this devices names or similar words not only like Siri Alexa but other wake up words that is set for the device is heard they got triggered and turn on as I already say bot neck attack it can be used for that as well and also sharing personal data against potential Advantage so when we are sharing them they can be used afterwards and of course there are lack of policies still in the those devices so though they have gdpr Incorporated but still that is not sufficient enough
then again the last one the very on that one aquisticsoul
so we cannot hear them but they can be used to trigger or turn on those devices and that also happen in many times such as just dolphin attack surfing attack and many others so then my research model came up so I started first thinking the iot knowledge so those people do people have what knowledge like about those devices if they do then do they aware of the threats they possess or issues they have and if they do are they are concerned when they have the knowledge of those devices are they concerned about the security and privacy if they know about the device have knowledge and have awareness as well still they do process any concern and if they do have everything
knowledge awareness and also have the concern about their security and privacy do they uh show that in their attitude so are they are aware about the different attacks going on those devices but they are still not showing like in their activity that they are trying to be secure so our findings was we had sorry I forgot to mention about it we had 123 participants in our research conducted online not only in UK but also in other countries so we try to accumulate developed countries underdeveloped countries and developing countries people there were different age group from 16 to 4 4 44 because we try to reach more Elder people I guess they don't trust on the online service so
they didn't participate that much so we couldn't have 60 or above people so there are from different backgrounds they are from PhD professionals and Business technical background they are different people so when we analyze the data we found out like those variable like age or their country those are not actually influencing the awareness on themselves even if they have knowledge or aware of the the incidents they are not influencing the in their attitude and also the attitude sometimes having the Privacy concern and knowledge are not demonstrating in their daily activities so we found there is a gap app still if they have knowledge if they have aware and if they have concern while using those devices there is a gap
so in physical security or like real life security we can see the thread sometimes uh someone is coming inside the door so we have to lock the door but in virtual reality we sometimes don't see like the new one that I mentioned earlier those audios we cannot hear them so we don't know when our MCH is triggered on and thus those we are not sometimes like secure ourselves as a result we are expressing our security and privacy concern but we are not protecting ourself in our Behavior it's not coming out in Virtual realm so which cause a security Paradox or security and privacy Paradox like people are try showing that they are concerned but they
are not acting on it so now why we need this awareness now when those devices are already in the market over decades because we are being introduced with many other new gadgets or systems such as CH GPD co-pilot or meta Quest so so those devices are being introduced to us and we are also trying to use them we are very excited to use them like we used to have in during Alexa young people most Young Generation they are really willing to use this Google Glasses and everything why they want to do use that because it's sometimes a Hy which we also try to understand in our research so this is same for these all other platforms
what what are the similarities and why we need the awareness now because these all platforms also have privacy concern these can be accessed unauthorized they also possess some vulnerabilities so yes they can be used for malware attack fishing attack and others they also have fraud or impersonation so which is like cloning your voice maybe manipulating your vision then they also have some ethical issues they might be used for surveillance such as like if I'm not mistaken and if you go back when the chat it introduced there were like debates is it safe to use is it not safe to use how long it's going to hold our data and so and so so people were in doubt and there was lack
of information same for other platforms as well and though we know about them like there should be some policies and information we all say we agree to all the terms and condition we never read out them so yes there is a lack of like Sur like when there are surveillance use this like platforms for surveillance we don't actually think before using them we just say yes we agree all terms and condition do whatever you want we don't know want to know that but we want to use them and of course when we are using them we are being dependent on those devices for because the these all are automated device so it makes our life easier and
who don't want our life to be easier in this chaotic busy lives so imp implications for practice as we already come to know why we need the awareness why concern is matters so we have to make sure the people are protected and people can vary among one other so you cannot make sure every people is protected by the devices but you have to make sure the policies are there which can protect them as much as possible so manufacturers obviously have to consider human Centric perspectives also when you are using them you also as a user have to understand how you can securely use those devices awareness definitely matters when you have aware or awareness campaign people at least get to know
about those threats and they will somehow somewhat get out like show in their behavior like at least protecting themselves so the key takeways we are advancing into modern era we are advancing 5G 6G and what not what's not coming up so we have to understand that users need to know about those devices which is coming in the market so we have to make sure the knowledge is spread out the awareness have been created so that those are meeting the concerns the users have and when we are sharing the or using the awareness campaign we have to make sure like those are not creating security Paradox they know about or they are aware of the incidents or safety
measures they have to also incorporate in their daily life it's not just we know this let's go now we start us using it don't worry about how it's going to happen and as I said before policy makers have to understand the user Centric perspectives as well and those we can at least minimize the threats thank you for joining us today and this is my contact details if you have any questions afterwards or want to connect LinkedIn barcode is here it's not faked or spoofed or anything you can use that safely thank
you any questions anything yeah yeah I just wanted to ask someone who's looking to research into security vulnerabilities and I guess analyze what they're actually doing what sort of courses should you recommend so for those like iots is still like there are many devices are coming up right so I think it's better to start with literature review try to understand like what documents are already there what researches are already being conducted that will help you to advance thinking like these are already have been done so what we can come up with some other solution which can be helpful for like after 5 years maybe so you have to think a bit ahead but to know that you have to
know what is on the market or what is on the research field already so I would advise to start from literature review and analyze the market so any good books that you recomend I would say go for journals rather than books yes books are already in the market or helpful but they took time to get published and everything so you should like look for that's what my personal view like for updated like journals or updated documents so that you are not lacking behind when you are doing your research if that makes sense yeah okay thank you thank you very much everybody thank you