Live data from Hacker News

Amazon device recorded private conversation, sent it out to random contact

kiro7.com

201–210 of 734 posts

Re: Amazon device recorded private conversation, sent it out to random contact

#201

I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. I have a microphone and I've been intending to get one of the open source solutions working and just tie it in to mpd, weather and a few other things. But all the processing should really be done on your own device, by hardware you own, software that's open and that you configure, and not send up to someone else's computer (ak…

> I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device.

Do you have an Apple or Google device near you right now? Does it have a microphone, battery power, and a connection to the internet? What about your roommate? Do you ever have sensitive conversations near these devices?

Of course I'm not suggesting you should abandon such technology. I'm just wondering why you draw the line at "Alex/Google/Apple assistant device"

Re: Amazon device recorded private conversation, sent it out to random contact

#203
post #21
post #13

Earlier quoted context omitted.

> This devices should by law always have a big LED on when recording And the LED should be forbidden by law from being software-controlled. They should also have a physical inline toggle switch to disconnect the microphone(s) entirely, whose state is easy to visually confirm.

I wonder how would you even do that? It's not a tape recorder, where someone has to physically press a button, there are no moving parts, thus it must be software controlled.

I guess, in this case 'electricity' would be a the moving part. Just have a closable contact on the mic's power attached to an external switch.

Re: Amazon device recorded private conversation, sent it out to random contact

#204

What actually happened: Alexa misinterpreted some voice commands and activated a "call" skill. The people involved and local news got very excited and escalated this into a conspiracy story. Amazon takes customer privacy EXTREMELY seriously. There's no way a team would get the "ok" to build a skill that randomly records private conversations then sends them to a random contact. It also doesn't make any logical sense…

Having a UI that gives the customer no audio confirmation that it got a command to record and send a message is a serious UI failure. This isn't a small thing here. If a bug like this makes it though, how can I trust that device.

I don't think the article is indicating what you say. The report says it's a bug, but it does bother me why Amazon won't comment on the specifics. This should be patched immediately with a full retrospective explaining what happened.

Re: Amazon device recorded private conversation, sent it out to random contact

#205
post #13

Earlier quoted context omitted.

> This devices should by law always have a big LED on when recording And the LED should be forbidden by law from being software-controlled. They should also have a physical inline toggle switch to disconnect the microphone(s) entirely, whose state is easy to visually confirm.

We dont need laws for these things. If a consumer installs an internet connected microphone in their home, they should expect this.

We have laws for all sorts of things to protect users from their own ignorance. You can't expect every consumer to be 100% aware of the dangers of things they don't fully understand.

Re: Amazon device recorded private conversation, sent it out to random contact

#206

What actually happened: Alexa misinterpreted some voice commands and activated a "call" skill. The people involved and local news got very excited and escalated this into a conspiracy story. Amazon takes customer privacy EXTREMELY seriously. There's no way a team would get the "ok" to build a skill that randomly records private conversations then sends them to a random contact. It also doesn't make any logical sense…

> There's no way a team would get the "ok" to build a skill that randomly records private conversations then sends them to a random contact.

And then builds exactly that...

Re: Amazon device recorded private conversation, sent it out to random contact

#207
post #167

Earlier quoted context omitted.

They should feel more comfortable than an equivalent system built by a company that is looking to profit off of your data - and additionally, you can give the guest stronger guarantees that when you say that the system is "off", it actually is.

The chance that a random implementer has a security vulnerability is much higher than that Jeff Bezos is listening to me watch TV. A private system is more vulnerable to target attack and an Amazon system is more vulnerable to mass surveillance.

You are on the right track, but I don't think you are quite right. Amazon like systems are more vulnerable to mass surveillance.

Your vulnerability isn't a targeted attack: you are not valuable enough to be worth the effort to figure out your system. As an attacker on your system I'd have to figure out how to break in, and then how to use the hardware you have. You are more valuable as part of a botnet - attacks that already exist. (if you are a politician then maybe, but that person is also vulnerable to a targeted attack on their amazon system - probably more so because the target is easier to figure out).

Re: Amazon device recorded private conversation, sent it out to random contact

#208

Earlier quoted context omitted.

Not sure about Android phones with "Ok Google" but on iOS, all of Siri's voice processing is on the device. As opposed to Amazon Alexa which sends the data to the cloud for processing.

Siri does speech recognition on Apple’s servers, but commands are performed on the device. The server doesn’t know who you are.

Is there an independent audit that can prove that?

Re: Amazon device recorded private conversation, sent it out to random contact

#209

What actually happened: Alexa misinterpreted some voice commands and activated a "call" skill. The people involved and local news got very excited and escalated this into a conspiracy story. Amazon takes customer privacy EXTREMELY seriously. There's no way a team would get the "ok" to build a skill that randomly records private conversations then sends them to a random contact. It also doesn't make any logical sense…

Is your best guess at why this might impact someone's trust in Amazon products really that people would think it was an intentional design choice? (Seems kind of straw-man-y.) If not, then you should generally address the part that will matter to people -- not whether this was on purpose, but what issues caused it and how will they be fixed.

Re: Amazon device recorded private conversation, sent it out to random contact

#210

I have this idea of a system I would like to have in my house. It contains cameras in every room that are constantly watching where people are and relaying the coordinates to a central server. That server makes decisions on if lights should be on or if A/C should be running in that room. But I would never buy this system. I would have to make it myself. I am hopeful that open source software and hardware can produce…

There's a whole class of tech like this for me. An Alexa/Echo/etc, a fitness tracker with GPS and sleep monitoring, a maps program that learns my routine and integrates with a weather app, and so on.

And ideally? All of it integrated. It actually sounds nice to say "I'm going home", and have Maps say "today that will take 35, should your oven start preheating when you're 20 minutes out?" IoT devices are overrated, but I can absolutely imagine a critical mass of integrated tools being very useful.

But I'm not even slightly willing to do that. It's too much information and too much risk surface. I'd pay a hefty premium to get local-data-only versions of these products, but no one is offering that, and it doesn't look like they're going to start.

Post reply on HN