Live data from Hacker News

Police seek Amazon Echo data in murder case

engadget.com

141–150 of 229 posts

Re: Police seek Amazon Echo data in murder case

#141
post #76

Earlier quoted context omitted.

Should the police be able to enter any house with locks they can pick? I suppose that would educate people, too. edit: I misread the comment as, " without a warrant"! Ugh

I don't understand your rebuttal. Are you disputing that LE does not have the ability to request a wire tap from a judge with a warrant? Wouldn't you want the police be able to intervene when they hear or observe shouting or fighting through an open door or window? Are you suggesting that a network-attached microphone is not equivalent to an open window? ( https://en.wikipedia.org/wiki/Third-party_doctrine )

It's certainly not equivalent. "Third-party doctrine" is extremely bad law that ignores the notion of private relationship. The law even recognizes some notions of private conversations (with your lawyer, and with your doctor), but ignores others (with your cloud provider) because the law is older than the cloud and the government loves making power grabs.

Justice Sonia Sotomayor is right to challenge it. I fear that she is one of a narrow generation that is young enough to understand digital technology, and old enough to remember the right to privacy in personal effects.

Re: Police seek Amazon Echo data in murder case

#142

Earlier quoted context omitted.

It stops listening. No action required. You can check in the Alexa app what is recorded (I just did). You can also check what is sent out to Amazon (which is what I did when I got the first one, using wireshark). The hardware is listening all the time, for the wake word. Nothing is sent until a wakeword is received.

That's exactly what Amazon would like there users to think. How do you think he wake work is detected? It MUST be listening to some sort of ambient audio, wether that is recorded or kept in anyway, only Amazon would know.

Amazon doesn't use telepathy. You can inspect the network traffic on your router and the contents of its local storage.

Re: Police seek Amazon Echo data in murder case

#143
post #120

I would never put a closed source hot mic in my house. You can trust big brother all you want, but I'm going to stay clear.

Every smart phone ever can do this. You have no way to verify the mic isn't in use, you have no way to verify cellular data transmission is not taking place, and you have no way to know the modem is not doing a remote execution injection to change whatever aftermarket free software OS you have running on the device is doing.

So just because my phone is potentially not secure means I should just open up my home to all other sorts of intrusion/attacks?

Yes, phones generally can do that, but it doesn't mean we shouldn't be concerned about what the Echo is doing.

Re: Police seek Amazon Echo data in murder case

#144

Alexa listens only to the words after the wake word. What's more it doesn't capture more than 10-12s past the wake word. If you have a device you can check this yourself (Alexa, One Mississippi, Two Mississippi…). It's actually hard to get it to capture this much. Take a breath or pause to long and capture stops sooner. The request of the police is nutty and indicative of not understanding the technology. Unless the…

Sure, maybe they don't understand the technology, but why not just hand it over so they can determine for themselves that there's no data pertaining to the investigation. They're essentially obstructing justice. They're trying to act like the good guy, but they're really just being assholes. Of course there's the possibility that they have something to hide and are actually collecting more data than we all think they…

If Amazon handed out my data to third party, that would be being an asshole

Re: Police seek Amazon Echo data in murder case

#145

Earlier quoted context omitted.

Hypothetically, if I was tasked with recording everything, I'd just add an internal buffer and then ship chunks of that data along with the regular queries.

Indeed, yes, that'd be the way to do it. You could claim the post-wake-word data is recorded at a higher bit rate than it actually is, thereby accounting for the larger than necessary data-transfer. I won't be surprised if we find out this is happening. They'll probably call it a "bug", fix it in an OTA, but then accidentally regress 6 months later.

Something you should probably understand about Amazon is that their Leadership Principles are real, and customer obsession is their main focus.

A big part of customer obsession is not eroding the trust of customers by treating their privacy as extremely important. For example, I've never heard of an incident in the more than two decades that Amazon.com has been in business of them selling customer data to a 3rd party for marketing purposes or otherwise. They wouldn't do something that could erode customer trust, or would be anti-customer, because they are in business for the long haul. Customer trust can only be earned slowly, over time, but can evaporate instantly with one mistake.

I trust Amazon more than Google and others to protect my customer data, because they've frankly earned this trust over 20+ years.

Re: Police seek Amazon Echo data in murder case

#146
The part that listens for the "Alexa" word is analog not digital.

It cannot be updated remotely by firmware.

Crack open the device, test the analog component and confirm the signal only fires when you speak alexa and nothing else.

Having said all that, I wouldn't buy it. NSA is known to temper with devices behind the back of companies (no matter how trustworthy you think Amazon/Google/Apple are). Check what they did with Cisco equipment sold to foreigners. They intercepted the shipment, tempered with the device and no one was any wiser until the Snowden leaks. Cisco now ships via proxy to guarantee no tempering.

American businesses shouldn't fear globalization or chinese disregard for intellectual property; their own government is fucking them.

Re: Police seek Amazon Echo data in murder case

#147
post #120

Earlier quoted context omitted.

Every smart phone ever can do this. You have no way to verify the mic isn't in use, you have no way to verify cellular data transmission is not taking place, and you have no way to know the modem is not doing a remote execution injection to change whatever aftermarket free software OS you have running on the device is doing.

So just because my phone is potentially not secure means I should just open up my home to all other sorts of intrusion/attacks? Yes, phones generally can do that, but it doesn't mean we shouldn't be concerned about what the Echo is doing.

No, it means that you're sitting in your house without a roof, and saying "I would never forget to close my windows during a rainstorm." Never mind the rain is pouring through your roof.

You're seriously willing to carry smartphones, which have both microphones and cameras, and give no indication visible or otherwise, of when they are listening or recording or sending data, and run whatever dodgy code some asian device manufacturer wanted it to run, but you won't trust a device made by Amazon that people have run wireshark captures against and lights up with big blue LEDs whenever it is listening.

Reality called - it wants the tinfoil hat back.

Re: Police seek Amazon Echo data in murder case

#148

The device doesn't start listening when you say the wake word, the device is always listening . It's only the UX that responds when the presence of the wake word is detected. This means that the device is continuously monitoring the environment for the presence of the wake word we know about ("Alexa"). Can the device monitor for other words that trigger other UX sequences? Of course it can! Can Amazon deliver an OTA…

> In fact, I would be in favor of law enforcement having the ability to "tap" these network-attached microphone appliances with a warrant. Then, perhaps, people will begin to understand what they've really bought.

All your arguments apply equally to any smart phone. It's another network attached microphone. Are you in favor of it there too?

Re: Police seek Amazon Echo data in murder case

#149
post #120

I would never put a closed source hot mic in my house. You can trust big brother all you want, but I'm going to stay clear.

Every smart phone ever can do this. You have no way to verify the mic isn't in use, you have no way to verify cellular data transmission is not taking place, and you have no way to know the modem is not doing a remote execution injection to change whatever aftermarket free software OS you have running on the device is doing.

[deleted]
Post reply on HN