Live data from Hacker News

Amazon device recorded private conversation, sent it out to random contact

kiro7.com

391–400 of 734 posts

Re: Amazon device recorded private conversation, sent it out to random contact

#391
post #290

Earlier quoted context omitted.

Your solution is simple. However, it doesn't allow for as much modification as the original poster's idea. With his idea it could be modified in so many ways to add functionality because it wouldn't be limited by the technology. The solution you supplied will eventually be limited by the technology if the original poster wants to add other functions.

There may be a market for something between a standard one-bit low-rez motion sensor and a full color TV camera. Maybe a 16x16 pixel IR sensor with a fisheye lens and a puny CPU that reports an approximate number of people in the area, for HVAC and lighting control, and security.

Reporting an approximate number of people is not a trivial task, even with a real camera. Depending on what exactly you mean with "approximate", of course.

Re: Amazon device recorded private conversation, sent it out to random contact

#392
post #297

I am oversimplifying here but: * install device that is designed to listen to speech in the house * the device is connected to internet * the device is capable of contacting other internet peers/services/hosts * the device knows a bit about its owner's internet presence such as contacts * the device is equipped with simple conversational user interface based on fuzzy human speech-command detection These basically bou…

> "I felt invaded," she said. "A total privacy invasion. Immediately I said, 'I'm never plugging that device in again, because I can't trust it.'"

Let this lady's reaction be a lesson to all of those who say "people don't care about privacy." She wired her home with Alexa devices, and yet when she found out how her privacy could practically be invaded through such devices, she seems like couldn't get rid of them fast enough.

People care deeply about their privacy. They just don't understand the true implications of even a device that's supposed to "listen to you" and the possibilities of what someone else could do to their internet-connected devices.

This is why governments must intervene with laws such as GDPR or even much stronger ones in the future to protect people's privacy, because the companies themselves have no incentive to "self-regulate" other than a negligible amount.

The only problem is some governments will not intervene unless enough people go through similar situations such as this lady. In the US even that may not help much because the vast majority of politicians care most about continuing to receive (however modest) donations (also called bribe money elsewhere) from the industry.

Re: Amazon device recorded private conversation, sent it out to random contact

#394

Earlier quoted context omitted.

From what I gather, if you need fine-grained location information in a building, you can do this without cameras and just a handful of strategically placed wireless access points. Less likely to be seen as creepy and such systems already exist. If you just need 'is a person in this room' or 'how many people are in this room' levels of data, solutions to this problem have existed for decades. No need to over complicat…

This assumes you don't leave your phone in the charger as you wander around your house.

It doesn't. There are methods that do not require a person to be carrying a WiFi-enabled device for location tracking.

Re: Amazon device recorded private conversation, sent it out to random contact

#395

What actually happened: Alexa misinterpreted some voice commands and activated a "call" skill. The people involved and local news got very excited and escalated this into a conspiracy story. Amazon takes customer privacy EXTREMELY seriously. There's no way a team would get the "ok" to build a skill that randomly records private conversations then sends them to a random contact. It also doesn't make any logical sense…

What is this alleged 'conspiracy' story? An Amazon device recorded a private conversation and transmitted it to someone else, and it did so without the user's knowledge or intent. That actually happened. How it happened is only relevant to the engineers who build and maintain the thing. I, on the other hand, could not care less how it happened, and the fact that it did happen is reason enough never to buy one of thos…

>How it happened is only relevant to the engineers who build and maintain the thing. I, on the other hand, could not care less how it happened

I'm sorry, this is just stupid. If you cannot see the distinction between a feature that was intended to spontaneously record audio, and a bug caused by faulty voice-processing, then that's on you. The distinction is pretty critical

Re: Amazon device recorded private conversation, sent it out to random contact

#396
post #335

Earlier quoted context omitted.

That's the main problem with motion activated office lights tbf, especially when you're doing software development for example - not enough motion to keep them on.

Eh, it encourages me to get up and have a stretch periodically.

That doesn't work in a toilet stall.

Re: Amazon device recorded private conversation, sent it out to random contact

#397
post #201

Earlier quoted context omitted.

> I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. Do you have an Apple or Google device near you right now? Does it have a microphone, battery power, and a connection to the internet? What about your roommate? Do you ever have sensitive conversations near these devices? Of course I'm not suggesting you should abandon such technology. I'm just wondering why you draw the line…

This is actually a pretty interesting question about threat models. A lot of "it can listen" fears are inconsistent with "I carry a smartphone", but I do think there's a meaningful distinction. My expectation isn't secrecy , but it is privacy . I carry a smartphone, but I keep voice-command activation turned off. I'm sure it could be activated remotely, but I expect that would require a targeted effort. I assume that…

So how is an Echo different from your smartphone? It feels like you've failed to quantify that.

It's much easier to turn off voice-command activation on the Echo than your smartphone. The Echo is not constantly recording.

> I assume that Google isn't constantly recording everything in the vicinity of all Android phones

AHAHAHAHAHAHA, see for example: https://www.google.com/maps/timeline The vast majority of Android users I've met unknowingly had this enabled. It doesn't record your conversations, but it still records far more than an Echo.

Why would remotely enabling recording on your Android phone be more difficult than on an Echo?

Re: Amazon device recorded private conversation, sent it out to random contact

#398
post #349

Earlier quoted context omitted.

some kind of acoustic biometrics would be helpful here (ie respond only to account holder, or disable some actions for others) along with better heuristic recognition of directives thats not foolproof but much better than what we have now, and i think we are pretty close

Agreed, but I think vocal biometrics is a significantly more difficult problem to solve when even the best speech recognition still has issues like this. Phonetics is hard. Especially with ambient noise, echo and such. I had a conversation with one of the speech engineers when I worked at a speech recognition company and the level of detailed problems to solve was impressive. Totally made sense after talking about it…

And once you've managed to achieve perfect biometrics your next task is to prevent replay attacks.

An alternative, "wireless" approach to near-perfect security would be to invent-plement some kind of vocal, human-executable GPG/TLS.

Re: Amazon device recorded private conversation, sent it out to random contact

#399

Earlier quoted context omitted.

Yes. Assume that all data uploaded to the cloud will eventually be compromised. That is the only safe assumption. Not even the most responsible companies (e.g. Google) can hold out 100% of the time in the face of determined assault by government. Some of that data is going to leak to three-letter agencies, or similar. Somewhat less responsible companies (e.g. Amazon) will leak data more often, to a wider range of thr…

That seems like an extreme perspective. Kind of like the tech version of abstinence only sex ed. Sure, it's the only 100% safe way, but it's not useful for most people. It doesn't weigh the benefits against the potential cons, or even take into consideration the actually likelihood of data being leaked.

The alternative perspective you're presenting sounds to me utterly cavalier about the prospect of ruining people's lives. It's like Equifax's attitude towards identity theft: it doesn't affect their profitability, so why care?

It's because such blithe dismissal of the damage caused by data gathering is so prevalent in the industry that the likelihood of devastating compromise is so high and the costs borne by the populace are spiraling upwards.

Some data should never be collected. Some data should never even be uploaded.

Re: Amazon device recorded private conversation, sent it out to random contact

#400

"My husband and I would joke and say I'd bet these devices are listening to what we're saying," Think about this statement for a sec. Of course is listening to you. It has to listen to you because it needs to be able to respond to "Alexa". So yes, this is always listening. Now, once you come to terms with that, do you feel comfortable having a technology with access to the internet, location, habits, account, contact…

The problem with this logic is that it applies to phones, tablets, and laptops as well. There isn't much additional risk from having an Echo or a Google Home if you already keep a smartphone within 10 feet of you at all times, which most of the people who are buying these devices do.

Why is that a problem?
Post reply on HN