Live data from Hacker News

Why You Should Never Buy an Amazon Echo or Even Get Near One

nakedcapitalism.com

21–30 of 41 posts

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#21

I really hate articles like this, because on the one hand I'm a total privacy nut and believe that the passive of surveillance of modern society has a terrifying and terrible chilling effect that really could end civil society as we know it. But I am quadriplegic. This means that without these devices I would be unable to control my house the way I do, because of the moment I have about 4 Amazon echoes, Google home a…

I read the article expecting something new, but it just goes on interminably with objections that we all know about from the snowden era. Nothing is really specific to the voice data, its germane to every device connected to the internet.

So I too dislike articles like this, the title is misleading and the text was not compelling.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#22
post #9
post #4

Earlier quoted context omitted.

If I get that right, using your phone to spy on you is a targeted action that targets you if you are of interest (sidenote, it's funny how many people deny being of interest even if they could build you a rocket program if you kidnapped and motivated them). A home assistant on the other hand is always on, listening and profiling its vicinity. So there is a large difference, not if you're under attack but rather if yo…

I don't see much of a difference here. Both are devices that listen to their surroundings. Both can be used to target the devices owner (if they are near their device) or to profile the devices vicinity. The only difference I see is that the phone location changes more often and that the owner is probably more likely to be near it. I guess people are just more aware of the fact that home assistants listen to everythi…

> Both are devices that listen to their surroundings.

That's the key, though - Echo/Home are listening passively, by design. Your phone is listening actively, but can be activated remotely to listen passively if you are the target of surveillance by a state actor.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#23

I really hate articles like this, because on the one hand I'm a total privacy nut and believe that the passive of surveillance of modern society has a terrifying and terrible chilling effect that really could end civil society as we know it. But I am quadriplegic. This means that without these devices I would be unable to control my house the way I do, because of the moment I have about 4 Amazon echoes, Google home a…

I read the article expecting something new, but it just goes on interminably with objections that we all know about from the snowden era. Nothing is really specific to the voice data, its germane to every device connected to the internet. So I too dislike articles like this, the title is misleading and the text was not compelling.

While I agree with the sentiment that it doesn't tell us anything we don't already know from the Snowden era, I really do think we have to keep banging on about the Snowden revelations. They (The revelations) really do need to stick in the public consciousness, not just in the consciousness of the hive on HN. Because honestly, the only substantive privacy changes I've seen in the UK are terrible ones and that scares the crap out of me.

But I have absolutely no idea how to convey the simple idea to people that are not in the tech world that "if it's connected to the Internet, don't consider it private", which I'd love to be proved wrong about but I really don't think I am.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#24

The Echo was able to pick a voice out of a crowd engaged in conversation. That means it is capable of singling out individual voice. That means it has been identifying individual voices, tagging the as “Unidentified voice 1″, Unidentified voice 2” and so on. It has already associated the voices of its owners, and if they have set up profiles for other family members, for them as well, so it knows who goes with those…

It's not just over-stating it, it's demonstrably wrong. All you need to disprove it is to ask someone else's Echo to answer a question. What I presume it's actually doing is responding to the keyword, Alexa in this case, and somehow correlating the rest of the question to the voice that said the keyword. I don't happen to know what criteria it uses to do that but it's clearly doing that or something a lot like it. Th…

That's basically exactly what happens, except without the voice correlation part. Alexa should be easily tripped up by multi-speaker babble: speaker A says the trigger, speaker B starts a command, speaker A interrupts, and Alexa hears A+B+A.

It's certainly how _i_ solved the problem when I wrote a SR system ...

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#26
post #18

Earlier quoted context omitted.

Strong encryption is a thing. EDIT: Another thing that just came to my mind. Even when you analyze network traffic and observe that traffic only occurs during your queries (i.e. in the seconds after the hotword is uttered), that doesn't mean that the Echo won't use the opportunity to send some previously-recorded audio to the server together with the current recording. In the same way that clever hackers disguise the…

Yes but we could could look at the amount of of data transmitted in total. Audio compression is well understood, and can infer within an range of usable quality, if any excess voice or other data is sent over the network.

Assuming its sending it as audio, and not as transcribed text which is both smaller and also much more compressible.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#27
post #6

Surely it's possible to sniff what's being sent back to Amazon's servers? If Amazon are lying and they are storing/analysing everything the Echo hears, surely this would be easy to prove?

It is possible to see all traffic it sends, and possibly even fake certificate authorities (depends on how resilient the Alexa is to this tampering) and trick the Alexa into giving you the data it sends encrypted using a key that you control.

However, this line of reasoning can be refuted all the way down to being impossible to prove/disprove. For example, there is reasonably an audio processing chip in Alexa that does always-on keyword listening, and it's possible it could track breadcrumbs over time (e.g., voice fingerprints, triggering keywords like "bomb", etc). This data can then be interlaced with innocuous data, for example inside an access token (opaque blob used to identify on whose behalf the Alexa is making requests). That would make it virtually impossible to find even if you had full access to the network traffic.

Anyway, when it comes to these things I like to take an Occam's razor approach. There's a great number of things a company can do to spy on you, but most likely when it comes to mass surveillance it's easier to tap into more obvious sources of data like your browsing history from the ISP, your phone line, Facebook/Google tracking data. In fact, I'd be more scared of say Facebook's and Google's voice assistants than Amazon or Apple because the latter two don't depend as much on consumer identity as a business.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#28
post #18

Earlier quoted context omitted.

Yes but we could could look at the amount of of data transmitted in total. Audio compression is well understood, and can infer within an range of usable quality, if any excess voice or other data is sent over the network.

Assuming its sending it as audio, and not as transcribed text which is both smaller and also much more compressible.

ASR is a hugely complex process that is handled by ML algorithms on Amazon's servers. The echo simply does not have the hardware to handle this on it's own.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#29
post #9

Earlier quoted context omitted.

I don't see much of a difference here. Both are devices that listen to their surroundings. Both can be used to target the devices owner (if they are near their device) or to profile the devices vicinity. The only difference I see is that the phone location changes more often and that the owner is probably more likely to be near it. I guess people are just more aware of the fact that home assistants listen to everythi…

> Both are devices that listen to their surroundings. That's the key, though - Echo/Home are listening passively, by design. Your phone is listening actively, but can be activated remotely to listen passively if you are the target of surveillance by a state actor.

>but can be activated remotely to listen passively if you are the target of surveillance by a state actor.

As it gets cheaper and easier to retain and analyze the output of the former the bar for the latter decreases.

I really don't want to get flagged for the "random" searches and audits every time in interact with a government service in 2020 just because the way I talk checks the proper subset of boxes for some AI to set the "probably doesn't like us" bool on my row to true.

Re: Why You Should Never Buy an Amazon Echo or Even Get Near One

#30
A lot of handwaving but little substance.

This sort of presentation makes for nice kindling but unfortunately not much more. In the end, your voice is unfortunately 'public'.

There is no difference between this and muttering too loudly. If someone hears you asking the voices in your head to quiet down, you would not think to blame them for violating your privacy by listening.

Eventually we will all have to re-assess what we accept businesses, government, and private parties knowing and doing with what we say. It is also a reminder that what we do (our body motions) will be up next for recording and analysis as motion, cameras, and facial recognition become more prevalent (iphone X).

Post reply on HN