Live data from Hacker News

Amazon device recorded private conversation, sent it out to random contact

kiro7.com

431–440 of 734 posts

Re: Amazon device recorded private conversation, sent it out to random contact

#431

Earlier quoted context omitted.

This is actually a pretty interesting question about threat models. A lot of "it can listen" fears are inconsistent with "I carry a smartphone", but I do think there's a meaningful distinction. My expectation isn't secrecy , but it is privacy . I carry a smartphone, but I keep voice-command activation turned off. I'm sure it could be activated remotely, but I expect that would require a targeted effort. I assume that…

So how is an Echo different from your smartphone? It feels like you've failed to quantify that. It's much easier to turn off voice-command activation on the Echo than your smartphone. The Echo is not constantly recording. > I assume that Google isn't constantly recording everything in the vicinity of all Android phones AHAHAHAHAHAHA, see for example: https://www.google.com/maps/timeline The vast majority of Android u…

> So how is an Echo different from your smartphone? It feels like you've failed to quantify that. > It's much easier to turn off voice-command activation on the Echo than your smartphone. The Echo is not constantly recording.

The difference is that a smartphone has the ability to constantly listen, but an Echo's primary use-case is to constantly listen. So if you're going to turn off voice-command activation on an Echo, there's much less reason to own an Echo in the first place than there is to own a smartphone with voice-command activation disabled.

Furthermore, an Echo is constantly plugged into essentially limitless power, while a phone is not. People in general are much more likely to notice excessive power consumption on their smartphone from the fact that their battery would drain more quickly than usual. Whereas, not many people are directly monitoring the power usage of their plugged-in Echo on a daily basis, so they'd be much less likely to notice if their Echo is suddenly using more power than usual (for example, by being remotely activated to listen constantly).

> AHAHAHAHAHAHA, see for example: https://www.google.com/maps/timeline The vast majority of Android users I've met unknowingly had this enabled. It doesn't record your conversations, but it still records far more than an Echo.

Granted, but there is no built-in voice command to send your timeline to one of your contacts.

> Why would remotely enabling recording on your Android phone be more difficult than on an Echo?

It's not that one is more difficult than the other, but rather that your risk grows with the number of possible attack vectors. If I already own a smartphone, then I may already be at risk, but adding an Echo to the mix increases my risk.

Two channels for remote listening will always be more risky than one. I don't think anyone is suggesting that you can replace your smartphone with an Echo, so the discussion about the risk of an Echo will always be within the context of _adding_ to the risk of having a smartphone. I don't think it's surprising when someone draws the line between the thing they currently rely on and the additional thing they can live without.

Re: Amazon device recorded private conversation, sent it out to random contact

#432

Earlier quoted context omitted.

I get what you are saying but I would say that Amazon does NOT take privacy extremely seriously or this couldn't have happened. Let me be clear that I'm not saying they don't care at all or they are conspiring with the NSA. What I mean by the above is that the "call" skill is much different than the "weather" skill. All Alexa has to do is have a confirmation prompt in the "call" skill and this wouldn't have happened.…

> I get what you are saying but I would say that Amazon does NOT take privacy extremely seriously or this couldn't have happened. Apple shared personal photos of myself onto the internet without my permission. I could not delete it without getting support to assist, and they could not provide me with a reason why this happened. Would you say that Apple does not take privacy seriously?

I would need you to explain how that happened.

The issue from the article is systemic. Everyone could easily accidentally be recorded and share that with random people

Re: Amazon device recorded private conversation, sent it out to random contact

#433

I have this idea of a system I would like to have in my house. It contains cameras in every room that are constantly watching where people are and relaying the coordinates to a central server. That server makes decisions on if lights should be on or if A/C should be running in that room. But I would never buy this system. I would have to make it myself. I am hopeful that open source software and hardware can produce…

And then the distro will be abandoned and be an open sore for hackers. IoT devices are a mass grave of abandoned Linux distros.

Re: Amazon device recorded private conversation, sent it out to random contact

#434
post #392
post #297

I am oversimplifying here but: * install device that is designed to listen to speech in the house * the device is connected to internet * the device is capable of contacting other internet peers/services/hosts * the device knows a bit about its owner's internet presence such as contacts * the device is equipped with simple conversational user interface based on fuzzy human speech-command detection These basically bou…

> "I felt invaded," she said. "A total privacy invasion. Immediately I said, 'I'm never plugging that device in again, because I can't trust it.'" Let this lady's reaction be a lesson to all of those who say "people don't care about privacy." She wired her home with Alexa devices, and yet when she found out how her privacy could practically be invaded through such devices, she seems like couldn't get rid of them fast…

> This is why governments must intervene with laws such as GDPR or even much stronger ones in the future to protect people's privacy, because the companies themselves have no incentive to "self-regulate" other than a negligible amount.

Market failure does not imply government solution. You're going to need a much stronger argument than "companies aren't doing a good enough job."

Amazon invaded her privacy, she realized it, and now she doesn't use the product. If you want others to do the same, start raising awareness yourself instead of enacting nanny state laws with other people's money.

Re: Amazon device recorded private conversation, sent it out to random contact

#435
post #15

Summary of vague technical details (which may be all we hear about this): > an Alexa engineer investigated ... they said 'our engineers went through your logs, and they saw exactly what you told us, they saw exactly what you said happened, and we're sorry.' He apologized like 15 times in a matter of 30 minutes and he said we really appreciate you bringing this to our attention, this is something we need to fix!" > th…

> The device did not audibly advise that it was preparing to send the recording, something it’s programmed to do. Apparently it's not programmed to do that. Unless this was a hardware glitch or cosmic-ray event.

cosmic ray - is that an exploit name or the secret government program that mandates Amazon provide this information on request?

Re: Amazon device recorded private conversation, sent it out to random contact

#437
post #335

Earlier quoted context omitted.

Eh, it encourages me to get up and have a stretch periodically.

That doesn't work in a toilet stall.

Our company has this in the toilets, when it goes dark you just wave your hands

Re: Amazon device recorded private conversation, sent it out to random contact

#438

I received one of these messages just a week ago. Alexa sent me a message of my friend and his girlfriend having a private conversation. I immediately texted him to ask if he intended to do that and he did not- so weird.

Do you have any proof of this online or can you provide more specific details? Not that I don't trust you but I don't trust anything I read on the internet without a minor amount of verification.

Re: Amazon device recorded private conversation, sent it out to random contact

#439
post #392
post #297

I am oversimplifying here but: * install device that is designed to listen to speech in the house * the device is connected to internet * the device is capable of contacting other internet peers/services/hosts * the device knows a bit about its owner's internet presence such as contacts * the device is equipped with simple conversational user interface based on fuzzy human speech-command detection These basically bou…

> "I felt invaded," she said. "A total privacy invasion. Immediately I said, 'I'm never plugging that device in again, because I can't trust it.'" Let this lady's reaction be a lesson to all of those who say "people don't care about privacy." She wired her home with Alexa devices, and yet when she found out how her privacy could practically be invaded through such devices, she seems like couldn't get rid of them fast…

> People care deeply about their privacy.

No, they don't. Do you really think if, before she made this purchase, someone explained to her all the things that could theoratically go wrong with this device, she would have chosen not to buy it?

She only cares now and acts like she doesn't share quite a bit of the blame because it actually affected her. I think it is highly likely she'll just switch to an Apple or Google equivalent instead of noticing the larger problem with these devices.

Re: Amazon device recorded private conversation, sent it out to random contact

#440
post #349

Earlier quoted context omitted.

Most phone now have some kind of lock screen, which makes it pretty difficult to get to the butt dialing stage. Will speech command recognition get to that stage? The main reason I won't have any of those products in my house is because of that. I'd much rather have a confirmation of some kind before the system takes action. "...random talking..." Assistant "I am recording" Me: "Stop recording"

some kind of acoustic biometrics would be helpful here (ie respond only to account holder, or disable some actions for others) along with better heuristic recognition of directives thats not foolproof but much better than what we have now, and i think we are pretty close

I agree, it would probably not even be close to foolproof.

I believe any implementation of security through acoustic biometrics would be vulnerable to replay attacks.

Systems to reproduce acoustics with high fidelity are commonplace - You might be using the output component of such a system right now if you're listening to music.

You could make the Assistant remember the exact fingerprints of all previous activation phrases and only trust you if it was original. This could be circumvented if you spoke the activation phrase at any point where your assistant could not hear you, for example to another Assistant of the same brand.

Post reply on HN