That's a good point. You would also need to leave your headphones plugged in while not playing sounds (I don't, but others might I suppose). Headphones also make a really crappy mic -- try it out by plugging them into a microphone jack (essentially what this malware emulates) and recording yourself: you'll need to hold them inches from your mouth to be intelligible.
This is an interesting idea and something that the driver software should be more vigilant about, but it's definitely not something that would lead me to conclude the headline.
> Headphones also make a really crappy mic -- try it out by plugging them into a microphone jack (essentially what this malware emulates) and recording yourself: you'll need to hold them inches from your mouth to be intelligible.
The article itself claims two orders of magnitude better reach:
> In their tests, the researchers tried the audio hack with a pair of Sennheiser headphones. They found that they could record from as far as 20 feet away—and even compress the resulting recording and send it over the internet, as a hacker would—and still distinguish the words spoken by a male voice.
One attack vector doesn't need to cover everyone. Developing many attack vectors as possible gives you the greatest chance that one of them will work against a particular target.
As an example, lets say that a particular organization has taken a number of standard precautions to prevent audio from being recorded surreptitiously. They've banned cell phones and chosen computers without internal mics. The ability to record sound via the output jack would be huge.
Besides, I bet beats would work just fine. The reason Sennheiser's worked so well is probably because they have a large speaker, whereas a ear bud has a pretty small speaker. A speaker being used to pick up audio is basically a dynamic mic, which are not very sensitive for a given size. So I'd expect something like Beats, or the cheapo AKGs I have connected to my audio jack right now to work quite well.
This is an interesting idea and something that the driver software should be more vigilant about, but it's definitely not something that would lead me to conclude the headline.