Live data from Hacker News

Ask HN: Private Alternatives to Alexa?

news.ycombinator.com

161–166 of 166 posts

Re: Ask HN: Private Alternatives to Alexa?

#161

Earlier quoted context omitted.

> There are types of hashes that aren’t for finding exact matches. My thesis in school way back when was building something for image near-duplicate detection using a sort of hash made out of the image features detected. The output of a neural net run on an image is also a sort of hash in a (maybe) semantically meaningful vector space. And then you can look for similar or nearby vectors. This isn’t just useful for fi…

Boy, there's a number of misconceptions here. I was considering not responding, but you're so wrong here that I just can't walk away and let you continue to spread this kind of blatantly wrong handwaving. > If for every one billion people(hypothetically of course) that are caught with child abuse images, one innocent person is asked to unlock their phone to prove that it's a false positive to a court, I think that's…

>You're pulling this hypothetical figure out of thin air, it may as well be one in a hundred or one in a trillion.

I agree, but it’s just as had waving when I say maybe it’s low chance that there are false positives, as it is when you’re freaking out at it being a hypothetically high number of false positives.

> That's not the problem here. If people want to continue to store photos of child exploitation on their iPhone, they can do it with the flip of a switch. Once you disable iCloud, Apple stops client-side scanning altogether.

If it’s so much under the users control why do you care or feel like this is an invasion of privacy then? I’ll say I feel like it’s still useful because criminals make dumb mistakes that incriminate themselves all the time — and this is a fine balance between being overly invasive and catching some people that store abuse images.

> Oh, like they already[0] do[1]? iMessage has been wiretapped since 2013, it's an open secret at this point that Apple is deep in bed with domestic intelligence agencies. Denying this is just refusing to acknowledge a truth that has reared it's ugly head again and again and again.

Yes, everyone knows this stuff, but just because it’s happening does not mean it can be used to incriminate someone in court unless there is justified prior suspicion which a judge issues a warrant for. That’s where the transparency is, at the court level.

> Countries like China…

This is a silly example, it makes me sad to say, but people in China are going to have their personal freedoms violated in very harsh ways regardless of Apple operating there of not. Unfortunately that’s the reality of living under totalitarianism — I don’t know why you’d even bring this up when I am clearly stating that what really protects people is living in a free democratic country with a well functioning court system.

> If they actually cared about those things, they'd divert some of the national budget to addressing those issues. Instead, they take that money and invest it in surveillance. Billions of dollars get poured into black budgets every year, with margins that constantly expand. The NSA regularly backdoors encryption standards, the FBI regularly designs exploits and incorporates them into US infrastructure.

I don’t wholly disagree, but I don’t see the connection with the original point. Also, you’re talking about governments as a monolith, which is a mistake. Any government is made of may departments and people, when you say ‘if they actually cared’, who’s the ‘they’? I think it’s really silly to say no-one in any part of the FBI cares about stoping child abuse for example. Sure I get that the CIA does not care, but that’s just not their job either.

> If any of our surveillance programs want to backdoor an iPhone or introduce vulnerabilities into iPhones, Apple has no recourse.

Maybe, maybe not. What is your hypothetical scenario for this? Can you explain how you think they’d do this where Apple has no recourse? Also who is the ‘they’? When you just say ‘they’ in a handwaving general way you sound conspiratorial. Are you saying they’d do it and apple could not detect it? Or that they’d coerce apple and apple would have no legal way to stop them?

> A much more appealing effort is to keep tabs on everything you do, everywhere you go and everyone you talk to. That way, if you become a legitimate threat to the state they can zero you before you cause any real damage. Make no mistake, every government is only out to save their own skin. You may disagree with it, or find it silly, but that's realpolitik for you.

This is where we depart the most. I’m European, In my opinion, America, with its two party non proportional system is a very poor example of democracy that is quite susceptible it corruption because of it’s concentration of powers. Just because you guys don’t live in a well functioning democracy does not mean that’s the case for the whole world — you’re projecting a bit here. I guess we agree in our mistrust of the US. Hopefully you guys don’t slid more on that totalitarian scale even more I guess.

> There is no way that we're living in a world where our government lacks the competence or resources to effectively monitor us at every corner.

I guess you don’t know about off grid log cabins that have no cell signal ;-)

> Apple is given a black-box list of irreversible image signatures that the government themselves consider harmful, and there is literally zero transparency that goes into this process. We have quite literally no idea how any of this works,

I think this is the point you’re wrong here, if there is a false positive I believe even in the US that you’ll be able to simply exhibit the source image that caused the false positive in court, if it even gets that far, which I think probably not, and prove innocence. The hash match is not the proof that you have child abuse images — it just starts a process of review. I think in practice it’ll start a process where a manual review will happen where someone will look at your source image and say, oh yeah, that’s clearly a false positive, and then it’s done. I’m sure we’ll know more where the first people get cause with this mechanism because it will still have to be prosecuted in a public court and at that time we won’t have to speculate so much.

Re: Ask HN: Private Alternatives to Alexa?

#162
post #68

Earlier quoted context omitted.

Yeah, they absolutely were not scanning photos and anyone with basic knowledge of how hashing works should know that. I was really disappointed with some of the reactions a saw coming from this community, which totally lacked any nuance or acknowledgment of how serious the issue of child abuse is.

They are Not scanning the photos But if there is a positive scan of the hash of a photo then the photo will be send to a human to check. Now with a certain error rate it is sure that humans working at apple will see privat photos that don’t have child pornography in them .

Three positive matches to known child pornography.

The chance of that happening in the real world is astronomically small.

Re: Ask HN: Private Alternatives to Alexa?

#163

Earlier quoted context omitted.

Honestly, I find it amazing that so many people let these things into their homes. The price you pay for such little actual utility isn't worth it. I won't use voice recognition on a single device. Not only do I not trust Google/Amazon, I don't trust that I wouldn't accidentally say something that triggers it to phone a person I'm talking about, or order something expensive in the internet. Home Assistant on my phone…

Does anyone's employer have rules about having company meetings (at home) with such devices nearby? Seems potentially risky.

We configured endpoint detection tools (ie Very Popular Endpoint Product) to scan local networks for these devices based on open ports and mac addresses. It is fairly straightforward to fingerprint them. Not foolproof (wifi isolation and other network segmentation), but low hanging fruit.

Re: Ask HN: Private Alternatives to Alexa?

#164
post #111

If you use Home Assistant and want something that is easy to setup, there is Home Intent: https://homeintent.io It uses Rhasspy under the covers, and automatically imports lights, switches, fans, etc and sets up sentences and intents for you. After initial setup, it can be used without an active internet connection. All you need is some container knowledge, an extra Pi, and a good speakerphone (like a Jabra Speak 410…

Wow, this is exactly what I'm looking for, thanks so much for developing it. I'm going to give it a shot over the holidays, have a pretty big home assistant install I'd love to control via voice. I'd primarily like to be able to turn on/off a few specific switches, set a few specific scenes and ideally play a few playlists (squeezebox integrated with home assistant). Would creating scripts in HA and then calling them…

I have considered integrating Home Assistant scripts at some point, so people could trigger whatever they wanted in HA. I'll get it added to the issue tracker and try to work on it for a future release!

As far as multiple instances, I've been working on satellite images. So you could have on base on a pi 3/4 (or potentially even a server) and then use some pi 0's connected to mics placed wherever else.

So stay tuned!

Re: Ask HN: Private Alternatives to Alexa?

#165
post #17

I’m also very interested in an answer. We use Alexa a lot, but this week I had to unplug every Alexa in the house because a distant family member had gained access to the family Amazon account and was trying to use the “drop in” feature to listen to our conversations. In the course of our investigation I found out that Alexa does not log privacy related events at all (there is no record of a drop in stored anywhere),…

Contact customer support about the deleting the profile, these things usually are taken very seriously, especially if it still is happening. If you don't hear anything back, call CS back and complain, shit will hit the fan then. I used to work in Alexa, and if we ignored a CS complaint like this, it would get escalated quickly and highly. Some of your assumptions about the back end are wrong too. As much as you hear bad news on how Amazon treats their employees, they really do care a lot about their customers.

Re: Ask HN: Private Alternatives to Alexa?

#166

Earlier quoted context omitted.

They are Not scanning the photos But if there is a positive scan of the hash of a photo then the photo will be send to a human to check. Now with a certain error rate it is sure that humans working at apple will see privat photos that don’t have child pornography in them .

What are we talking here, 1 in 1 billion. I just can’t care that much unless there’s real evidence that the error rate is really high.

I dont know the error rate of image recognition but it is certainly more than one in a million. More 1-10%. But i dont want to talk the idea of apple down. I am okey with them scanning THEIR servers for childporn. As long as the keep away from MY phone.
Post reply on HN