Live data from Hacker News

Amazon device recorded private conversation, sent it out to random contact

kiro7.com

531–540 of 734 posts

Re: Amazon device recorded private conversation, sent it out to random contact

#531

Earlier quoted context omitted.

Trust is proportional to access. I don’t trust any third party with an always-on microphone in my house, especially one that’s networked. Malice aside, I don’t trust their competence. Nor should anyone I think.

That’s fair, but again, a smartphone fits that description too and nobody is talking about how you’d have to be crazy to let one in your house. It seems to me that smartphones are significantly worse. You can unplug your smart speaker or kick it off your WiFi and be confident that it can no longer hear you. Smartphones have batteries and cellular data connections. Also they’re usually with you at all times, even when…

That’s fair, but again, a smartphone fits that description too and nobody is talking about how you’d have to be crazy to let one in your house.

A lot of people talk about it, they’re just laughed or shouted down. There’s also the argument that mobile phones undoubtedly offer a number of incredibly useful tools, not the least of which is a primary phone line. I think anyone would be hard pressed to argue for commensurate utility from Alexa or similar products.

Re: Amazon device recorded private conversation, sent it out to random contact

#532

What actually happened: Alexa misinterpreted some voice commands and activated a "call" skill. The people involved and local news got very excited and escalated this into a conspiracy story. Amazon takes customer privacy EXTREMELY seriously. There's no way a team would get the "ok" to build a skill that randomly records private conversations then sends them to a random contact. It also doesn't make any logical sense…

Sorry but there is no real reason to give Amazon the benefit of the doubt on anything related to data and privacy. You guys can feel free to roll your eyes and tell people they're overreacting all they want. I find it revealing. We get it, people are just holding it wrong. Okay.

Look- we all know that bugs will happen. The question is, what will you do in light of that? What bounds will you set up to prevent the system from acting in ways you want to disallow? How will you detect something is awry? I would say that really caring about people's privacy means doing this part seriously, not just a baseline lack of active malice.

Re: Amazon device recorded private conversation, sent it out to random contact

#533
post #327

Earlier quoted context omitted.

I remember the first voice command stuff on google. Buddy of mine was trying it out and I couldn't help myself but shout: "NEW TEXT MESSAGE TO JENNY! FUCK YOU! SEND!" Fortunately the phone was too slow to take it all (even if it had Jenny would have found it amusing, she was a cube or two away). But yeah first thing I thought of was that if it's listening how easy is it for it to mistake intent or someone else or etc…

Hahah so my favorite thing to do when people use Siri, Google voice, Alexa etc is shout "WHERE TO BUY COCAINE, SAN FRANCISCO" or "HOW TO JOIN ISIS" or "PLUTONIUM FOR SALE NEAR ME" The commands are usually recognized but turn up nonsensical results.

Why?

Re: Amazon device recorded private conversation, sent it out to random contact

#534
post #308

Earlier quoted context omitted.

This is eerily similar to the concept of a 'cookie' seen in the Black Mirror episode, White Christmas. (Spoiler Alert) A cookie is a device "that is inserted under the clients head by the brain and kept there for a week, giving it time to accurately replicate the individuals consciousness. It is then removed and installed in a larger, egg shaped device which can be connected to a computer or tablet (to automate their…

I want to say "that episode really freaked me out" but... That's true for almost every episode of Black Mirror.

I get freaked out every time someone on HN proposes a tech not too far removed from Black Mirror plots. Great show!

Re: Amazon device recorded private conversation, sent it out to random contact

#535

Earlier quoted context omitted.

If you're staying that still, you likely don't need room lights on. Why not just use an area/task light if you're performing a stationary task?

For people with glasses the reflections can be pretty bad. In addition I require bright cold-white neon light or I fall asleep. By the way, German workplace safety regulations require a certain minimum of light at a workplace.

OSHA also requires a minimum light level in the US but I believe it only pertains to hazardous working environments (like on a production floor in a manufacturing facility for example). Either that or the enforcement in white collar environments is so weak that literally no one cares to follow the law which is surprisingly common with reagrd to many workplace regulations.

Re: Amazon device recorded private conversation, sent it out to random contact

#536
Amazon's response, from Ars' article:

> Echo woke up due to a word in background conversation sounding like "Alexa." Then, the subsequent conversation was heard as a "send message" request. At which point, Alexa said out loud "To whom?" At which point, the background conversation was interpreted as a name in the customers contact list. Alexa then asked out loud, "[contact name], right?" Alexa then interpreted background conversation as "right." As unlikely as this string of events is, we are evaluating options to make this case even less likely.

https://arstechnica.com/gadgets/2018/05/amazon-confirms-that...

Re: Amazon device recorded private conversation, sent it out to random contact

#537
My Echo somehow woke up when we were in another room, then heard itself talking to itself, and called my friend in the middle of the night. You can see the log of what it said and how it heard the last word as the command: https://www.facebook.com/mike.deeks/posts/10215464075417775

It was both hilarious and infuriating. I immediately turned the calling feature off (you have to contact support btw) and later we switched to Google Home.

Re: Amazon device recorded private conversation, sent it out to random contact

#538

I have this idea of a system I would like to have in my house. It contains cameras in every room that are constantly watching where people are and relaying the coordinates to a central server. That server makes decisions on if lights should be on or if A/C should be running in that room. But I would never buy this system. I would have to make it myself. I am hopeful that open source software and hardware can produce…

There's a whole class of tech like this for me. An Alexa/Echo/etc, a fitness tracker with GPS and sleep monitoring, a maps program that learns my routine and integrates with a weather app, and so on. And ideally? All of it integrated. It actually sounds nice to say "I'm going home", and have Maps say "today that will take 35, should your oven start preheating when you're 20 minutes out?" IoT devices are overrated, bu…

>a maps program that learns my routine and integrates with a weather app

That sounds awesome until the company providing that service starts abusing their knowledge of their location. That abuse doesn't even have to necessarily be malicious in nature either. For example, Google Maps on Android started asking me to rate, review, and/or take photos of my present location if they deemed it a point of interest (certain restaurants, parks, etc). I never opted in to this feature and the only way to disable it that I've figured out is to literally disable all location services on the phone.

I really dislike the idea of Google storing a timestamped record of almost every place I've ever visited. Tt has to beconstantly phoning home in order to deliver the request to document my visit within a minute or two of my arrival and that constant reminder that Big Brother Google is tracking me at every moment is just disturbing on so many levels. Even if they aren't using that data right now, remember the "data is never destroyed" principle of the internet.

On a side note, I would have ditched Android if I didn't need it for work simply because use of the GPS radio is hidden behind the acceptance of enabling Google's Location system and all the invasions of privacy that entails.

Re: Amazon device recorded private conversation, sent it out to random contact

#539

Earlier quoted context omitted.

>What’s so bad about having a small processor run a recognition routine on all incoming audio, discarding everything that doesn’t match, and activating the device if it does? If that was the case, nothing. But we have enough evidence to believe it's not. While having the device listen, even though it's been explicitly configured not to, is a bit more of a stretch. >Are you just worried about accidental activation? Th…

What evidence do we have? I’m about 99.9% sure that this story is just accidental activation and bad reporting. If you’re concerned with malicious intent then I really don’t understand the difference. If the device maker is trustworthy then you’re fine either way. If they’re malicious then you’re screwed either way. A setting for “please don’t listen” isn’t going to make the slightest bit of difference if they’re mal…

It's a worse PR nightmare if discovered, so a bigger risk.

“Networked device with microphone records and uploads your voice” might create reactions such as: yeah, what did you expect, how else would it work?

“Networked device with microphone records and uploads your voice even when explicitly told not to” is a lot worse. Company X is lying to us!

Re: Amazon device recorded private conversation, sent it out to random contact

#540
post #349

Earlier quoted context omitted.

some kind of acoustic biometrics would be helpful here (ie respond only to account holder, or disable some actions for others) along with better heuristic recognition of directives thats not foolproof but much better than what we have now, and i think we are pretty close

I agree, it would probably not even be close to foolproof. I believe any implementation of security through acoustic biometrics would be vulnerable to replay attacks. Systems to reproduce acoustics with high fidelity are commonplace - You might be using the output component of such a system right now if you're listening to music. You could make the Assistant remember the exact fingerprints of all previous activation…

i meant biometrics merely as a UX improvement, ie, to help prevent the device from responding to the wrong thing "accidentally"

it may have a place in security as well but i can only see it as part of a much more holistic model

Post reply on HN