Live data from Hacker News

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

threatpost.com

191–200 of 424 posts

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#191
post #89

Is there a good non-internet connected device for turning on lights with your voice?

I built something just for fun a couple of weeks back. I used the Sphinx Open Source Speech Recognition Toolkit from CMU https://cmusphinx.github.io/ Look for the sphinxbase and pocketsphinx packages under Ubuntu. It'd be simple enough to hook this up to Philips Hue or whatever to do what you want. There are numerous Sphinx language bindings. I went for Ruby via Isabella https://github.com/chrisvfritz/isabella . I us…

This sounds very close to how I started out with a similar project, named Rhasspy: https://github.com/synesthesiam/rhasspy-hassio-addon

I ended up using a set of JSGF grammars (one per intent) to generate a statistical language model for use with pocketsphinx. Rhasspy also features a web-based interface for creating custom words -- I have a mapping from Sphinx phonemes to eSpeak phonemes so you can iterate over a pronunciation until it sounds right.

As you mentioned, the wake/hotword stuff with Sphinx isn't terribly robust. I've been Docker-izing Mycroft Precise (https://github.com/MycroftAI/mycroft-precise) to address this.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#192

Earlier quoted context omitted.

This is just my opinion, based on my experience and personality. Voice first running entirely on prem with no internet connectivity, sure I would go for that. Talking to the internet? No way. Not even if I had root on the device with the source code to the OS, firmware and applications.

> Talking to the internet? No way. Not even if I had root on the device with the source code to the OS, firmware and applications. Can you explain how this is different from running your linux computer with a webcam attached?

Do you really think the people who are concerned about Google Home/Alexa/etc don't also have their webcam covered with a sticker?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#193
post #120

Earlier quoted context omitted.

If we are playing the "you can't prove that" game, then you also can't prove that your $12 throw away phone isn't always recording, or that you new kitchen countertop doesn't have a recording device embedded in it, or that the maker of whatever device you are using to type that comment isn't breaking a plethora of laws to record everything you type or say or do around that device at any time.

It's reasonable to embed motive into these suspicions. My confidence in iPhone not listening to me is linked to the fact that Apple's ad network is a fraction of the size of Amazon's and Google's, and that to the best of our knowledge, it doesn't require extensive access to personal data to run effectively. Same with GE appliances and countertop makers. One of the most reliable ways for me to believe a company will n…

True but...

1- Apple might not be interested in listening to its users but I'm sure other businesses are. Apple users are loyal customers who can pay twice for a piece of technology and some of them will happily spend a night in line to be able to do that. Most advertisers would pay big money to Apple to know who those people are and what they want; that information is like gold.

2- unfortunately advertisers aren't the only entity potentially interested in spying people.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#194

I'm having trouble getting worked up about this one. Yeah a privacy breach happened, but it was only one person's data exposed, and only to one other person. The only reason it made the news is because people are already paranoid about voice assistants.

Was the data supposed to be stored in the first place according to the privacy policy/user consent? If not, it'd mean that Amazon stored highly sensitive data (audio recordings from people's bedrooms) illegally and in breach of user's trust.

Was there something in the article to suggest that it wasn't collected and stored in accordance with policy?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#195
post #104

I've never seen a demographic breakdown of HN, but I'm 37 years old. I'm definitely not the oldest guy here, but I see history repeat itself regularly. I remember when people used location tracking as a reason to not own a cell phone. I'm talking about flip phones, mind you, not even iPhones with GPS receivers. I recall the bulk of complaints in that vein died down around the time Google Maps for phones came out. If…

All it ever takes is the utility outweighing the risk for enough people to support a business.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#196
post #85

Is there a good non-internet connected device for turning on lights with your voice?

What is wrong with using a finger to turn the lights on and off?

Whats worse is that newer generations will not know what an analog switch is and how powerful and yet simple it is and how it just works in an instant when you want it to. When I was a kid I used to disassemble things and learn lots from the adventure because it was logical and intuitive (I also had to assemble it back or I'd get scolded at). Kids these days don't bother because the device of their choice captivates most of their attention and their control is limited.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#197

Earlier quoted context omitted.

>The only company I've seen take demonstrable action to protect their customer's privacy is Apple. The same Apple that gave the Chinese government access to all their Chinese user's iCloud data? https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...

This is false. iCloud data doesn't contain phone call contents or iMessage data contents. Yes they gave access to metadata, but this is China where privacy basically doesn't exist, not a western country.

Wrong - Apple moved all iCloud data, which includes text messages, email and other data stored in iCloud (according to Reuters) as well as the access keys. Apple even forced users to sign the updated TOS or drop service.

The Chinese government access is _not_ limited to metadata.

https://www.reuters.com/article/us-china-apple-icloud-insigh...

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#198
post #186
post #104

I've never seen a demographic breakdown of HN, but I'm 37 years old. I'm definitely not the oldest guy here, but I see history repeat itself regularly. I remember when people used location tracking as a reason to not own a cell phone. I'm talking about flip phones, mind you, not even iPhones with GPS receivers. I recall the bulk of complaints in that vein died down around the time Google Maps for phones came out. If…

I am in my 30s too, and I remember reading articles saying that DHS had hundreds of thousands of hours of wiretapped conversations they would never get to because they all needed to be manually reviewed. When the company selling a suspiciously cheap home speaker ('stocking stuffer') is the same company that boasts of having infinitely scalable computing ability and is the only cloud vendor that meets the Pentagon's p…

Just so I'm clear here, you're proposing a conspiracy theory where Amazon, the DHS, and The Pentagon are in collusion to collect and transcribe audio from Amazon Echos -- in such a way that none of the many people who have hacked and extensively reverse-engineered them would be able to tell?

I can't find any holes in that theory.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#200
post #19

Earlier quoted context omitted.

Nothing in the article suggests they were linked to any kind of user identifier, all we know is that each recording is linked to the transcription alexa made of it (which makes sense, training and log wise). The user were easy to identify because if I listen to the last twenty queries you made to alexa between what you ask, what other people say in the background, what you talk about and what noise is in the backgrou…

> Nothing in the article suggests they were linked to any kind of user identifier They were able to provide the customer a bundle of his recordings upon request so they must've maintained such a lookup mapping. Of course that led to the mix up reported here. But I'd argue it's safer if on Amazons side they simply can't fulfill such request themselves due to anonymization.

I suppose that does raise a question of where you draw the line on a company's obligation to anonymize information. Is disassociating a user ID from the data enough? What about data that makes the user identifiable through patterns?

If I say "Alexa, my name is Bob Jones and I have chlamydia," they're not really helping me out by just not associating that audio clip with my username.

Post reply on HN