Live data from Hacker News

Amazon device recorded private conversation, sent it out to random contact

kiro7.com

341–350 of 734 posts

Re: Amazon device recorded private conversation, sent it out to random contact

#341
post #327
post #297

I am oversimplifying here but: * install device that is designed to listen to speech in the house * the device is connected to internet * the device is capable of contacting other internet peers/services/hosts * the device knows a bit about its owner's internet presence such as contacts * the device is equipped with simple conversational user interface based on fuzzy human speech-command detection These basically bou…

I remember the first voice command stuff on google. Buddy of mine was trying it out and I couldn't help myself but shout: "NEW TEXT MESSAGE TO JENNY! FUCK YOU! SEND!" Fortunately the phone was too slow to take it all (even if it had Jenny would have found it amusing, she was a cube or two away). But yeah first thing I thought of was that if it's listening how easy is it for it to mistake intent or someone else or etc…

My friend installed IBM OS/2 WARP beta when it came out, it too was voice controlled. We would shout into his room, "select all, delete" or "format c" or other childish fun commands.

Re: Amazon device recorded private conversation, sent it out to random contact

#342
post #13

This devices should by law always have a big LED on when recording, you would have the option to set it's brightness though. Also why could it send data out without any confirmation from the user.

> This devices should by law always have a big LED on when recording And the LED should be forbidden by law from being software-controlled. They should also have a physical inline toggle switch to disconnect the microphone(s) entirely, whose state is easy to visually confirm.

> They should also have a physical inline toggle switch to disconnect the microphone(s) entirely, whose state is easy to visually confirm.

It has that. They call it the power cable.

If you disconnect the microphone, an echo is pretty useless.

Re: Amazon device recorded private conversation, sent it out to random contact

#343

Earlier quoted context omitted.

The Personal Cloud is what we should be building for ourselves. Servers running in your closet at your house.

Any idiot who breaks into your home would be well positioned to steal your server along with all of your memories and use them for ransom/blackmail/etc.

As opposed to any idiot who breaks into your IoT provider's server?

An encrypted hard disk with the key on a USB stick would be enough, just keep the key somewhere separate and you'll only have to plug it in when there's a power outage.

Re: Amazon device recorded private conversation, sent it out to random contact

#344
post #47

Earlier quoted context omitted.

Which means the light is always on. The device must be listening or the wake word won't work.

There are usually 2 stages, a local processor that can only detect the wake word, and then once that hears the wakeword it begins streaming data to the internet.

I’m aware. The microphone is always on in order for stage 1 to work.

Re: Amazon device recorded private conversation, sent it out to random contact

#345

Earlier quoted context omitted.

One reason you might want a server is to have more expressive power than "if someone literally enters the room, turn on the lights". You might want to turn on the lights and run the AC a little before you predict people will arrive, for example.

> One reason you might want a server is to have more expressive power than "if someone literally enters the room, turn on the lights". You might want to turn on the lights and run the AC a little before you predict people will arrive, for example. Maybe, but that seems like a lot of work for little gain. You probably don't actually have that much control over the AC in your rooms unless you have zoned heating and a l…

> Maybe, but that seems like a lot of work for little gain.

That's how I feel about Alexa.

Re: Amazon device recorded private conversation, sent it out to random contact

#346
I am seeing comments saying, Alexa misinterpreted some voice commands and activated a "call" skill. This sounds like a good excuse but does absolve Amazon of responsibility. If their voice and command recognition is broken they should add second step verifications like "Are you sure you want to call X" or "Okay, I am calling 'X' in 10s" or something similar. Crazy to imagine Amazon is shipping this device with capability of video calling people and buying stuff online without having fully testing and thinking about all scenarios.

If there is even a slightest possibility that Alexa/Siri/Google/Cortana is going to misinterpret commands (with privacy implications) then they should do two step verification of some sort.

Re: Amazon device recorded private conversation, sent it out to random contact

#347
post #308

I have this idea of a system I would like to have in my house. It contains cameras in every room that are constantly watching where people are and relaying the coordinates to a central server. That server makes decisions on if lights should be on or if A/C should be running in that room. But I would never buy this system. I would have to make it myself. I am hopeful that open source software and hardware can produce…

This is eerily similar to the concept of a 'cookie' seen in the Black Mirror episode, White Christmas. (Spoiler Alert) A cookie is a device "that is inserted under the clients head by the brain and kept there for a week, giving it time to accurately replicate the individuals consciousness. It is then removed and installed in a larger, egg shaped device which can be connected to a computer or tablet (to automate their…

I want to say "that episode really freaked me out" but... That's true for almost every episode of Black Mirror.

Re: Amazon device recorded private conversation, sent it out to random contact

#348

Earlier quoted context omitted.

> I'm just wondering why you draw the line at "Alex/Google/Apple assistant device" There’s a big difference between: - Devices which are by design always actively listening and sending real-time audio to computers you can’t control or even really trust, with unknown security properties, and consumer-appliance security life-cycles/support - Devices that can be configured to do that, but which you have some control ove…

To be fair, Apple’s homepod doesn’t send any data until it’s activated with the wake word. Amazon and google products send a ton of data back constantly.

Where have you read that Amazon and Google send a ton of data back? I've heard that none of these devices send anything back until they're activated by a specific phrase.

Re: Amazon device recorded private conversation, sent it out to random contact

#349

Earlier quoted context omitted.

If you replace "fuzzy human speech-command detection" with "buttons which can accidentally be pressed" - how is this different from butt-dialing?

Most phone now have some kind of lock screen, which makes it pretty difficult to get to the butt dialing stage. Will speech command recognition get to that stage? The main reason I won't have any of those products in my house is because of that. I'd much rather have a confirmation of some kind before the system takes action. "...random talking..." Assistant "I am recording" Me: "Stop recording"

some kind of acoustic biometrics would be helpful here (ie respond only to account holder, or disable some actions for others) along with better heuristic recognition of directives

thats not foolproof but much better than what we have now, and i think we are pretty close

Post reply on HN