Live data from Hacker News

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

threatpost.com

11–20 of 424 posts

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#11
post #4

Does Amazon keep the raw recordings for GDPR compliance reasons? It seems to me keeping them just creates liability? (Yes data analysis for targeting and such would be valuable, but those can be done with, say transcripts instead of the raw recordings)

The actual recordings are the most valuable data for modeling purposes so I actually assume they try to store it to improve the system

Doesn't using live data for testing create GDPR issues?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#14
post #6

> "Using these files, it was fairly easy to identify the person involved and his female companion; weather queries, first names, and even someone’s last name enabled us to quickly zero in on his circle of friends,” according to the report. “Public data from Facebook and Twitter rounded out the picture.” Please keep in mind the next time you or a friend says "well, what do I care if Amazon knows when I ask to turn the…

Speaking of phones, aren't most people's smartphones already "an always on microphone in their homes"?

On the vast majority of devices it is not always on.

It is not a nitpick. Accidentally recording or even intentionally recording is many orders of magnitude simpler when the device is supposed to always be listening.

The fact that a single employee even could make the mistake mentioned in the articles is one example of why. Eventhough it also really does hint that the backend isn't up to par at amazon.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#15

This is just facebook all over again. Why can't people see trouble-tech? I never used facebook and won't ever use an alexa, nor whatever google's thing is.

I don’t know why this is getting downvoted. I feel the same way. Amazon and Google have yet to demonstrate to me that they value my privacy enough to take necessary steps to protect it. They, like Facebook, know most people foolishly don’t care enough to hold these companies feet to the fire on it.

At the risk of stating the obvious; Facebook has more than demonstrated the opposite.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#16
post #6

> "Using these files, it was fairly easy to identify the person involved and his female companion; weather queries, first names, and even someone’s last name enabled us to quickly zero in on his circle of friends,” according to the report. “Public data from Facebook and Twitter rounded out the picture.” Please keep in mind the next time you or a friend says "well, what do I care if Amazon knows when I ask to turn the…

Speaking of phones, aren't most people's smartphones already "an always on microphone in their homes"?

It's an always on microphone (as opposed to an always on device) if hacked or if Google/Apple change something fundamental, but only then. Echo/Dot have an always on microphone by design.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#17
I am baffled by how many people have no problems adding always listening and recording Google and Facebook devices to their living rooms.

Some are considered tech people who should know stuff like this could happen, but they just don't care or don't think it will happen to them.

Somewhere there is an ex-Stasi officer who is thinking "I wish we were that good and had people fooled to voluntarily install listening devices and didn't have to tap phone lines and crawl around basements and rooftops".

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#19
post #4

Earlier quoted context omitted.

The actual recordings are the most valuable data for modeling purposes so I actually assume they try to store it to improve the system

that makes sense. though I wonder if for training purposes they can simply remove the user identifier. (like anonymizing them for instance)

Nothing in the article suggests they were linked to any kind of user identifier, all we know is that each recording is linked to the transcription alexa made of it (which makes sense, training and log wise).

The user were easy to identify because if I listen to the last twenty queries you made to alexa between what you ask, what other people say in the background, what you talk about and what noise is in the background that gives me a lot of information; that's exactly how they were able to identify some of the users from their recordings.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#20
post #4

Does Amazon keep the raw recordings for GDPR compliance reasons? It seems to me keeping them just creates liability? (Yes data analysis for targeting and such would be valuable, but those can be done with, say transcripts instead of the raw recordings)

The actual recordings are the most valuable data for modeling purposes so I actually assume they try to store it to improve the system

I'd imagine that a competent company would keep access to user audio recordings tightly locked down, either because they actually care about privacy or because they care about the bad PR of recordings getting leaked.

But if the GDPR requires them to send the recordings to users upon request, they need to have a way to do that -- either by exposing a service on the web, or by providing access to customer service employees to handle the request. Not sure how I feel about that.

Post reply on HN