Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

91–100 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#91
post #57
post #37

Earlier quoted context omitted.

That is correct! Google, Amazon, and Apple despite having vast resources don't have the ability/desire to pay for the bandwidth, storage, and processing needed to have 24/7 recording and analysis from every smart device, especially when you realize that includes cell phones. Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in…

This is similar to the issue of people being scared of radiation from cell towers but somehow not freaking out that they have a transmitter in their pocket that uses the same range of frequencies but at vastly higher power (due to the proximity).

Like the people that attack smart electric meters while they talk on their cell phone

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#92

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

There's a widespread sentiment that current evidence of compliance to "doing right by users" should be viewed with circumspection. And it's fair to say Google's past behaviour raises doubts about the level of trust users should extend them.

What is a conspiracy theory about today's hardware, I have no trouble imagining is a planned or at least considered future iteration of their "service".

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#93
post #73

Earlier quoted context omitted.

The processing for the wake word is handling on the firmware. If you point Wireshark (or another network monitor) at a Google Home or Alexa device you can see that there isn't significant network activity while idle.

If they (the smart assistant makers) would promote the fact that their devices only go online after the trigger word is detected that would go far is assuaging people's fear of the always-on microphone

They have.

The reality is that conspiracy theorists aren't interested in learning how things actually work, which is why they're conspiracy theorists.

In reality your phone is a significantly bigger threat to privacy both in terms of normal day to day monitoring (e.g. location tracking) and even listening in (a closed source baseband that can communicate on a platform you cannot even monitor).

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#94
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

The sentiment this is countering is not "Google and Amazon _are_ recording 24/7/365". It is countering "Amazon and Google _would_ record 24/7/365 if they could get away with it socially".

Arguing that the technology doesn't do this does not address the underlying root perception that Amazon and Google are not to be trusted.

Google built its entire business on harvesting _all_ data on the web and building an infrastructure to process it efficiently. Purchasing Nest made clear that to us that they now wish to harvest data from the home. If they were able, socially and politically, to harvest _all_ data from the home, their history indicates that they would do so with all possible speed.

Having a device you built yourself that learns locally and is under your control prevents Amazon and Google from changing their mind about what level of recording is acceptable without your informed opt-in consent at the time of the change. Both providers reserve the right to update their privacy policies without notification or consent, including granting themselves to increase data collection.

TLDR: This device is the physical expression of mistrust of Amazon and Google. Their greed for your metadata is well-documented, and their policies let them increase data collection in your home at any time without your consent. Such increases would be prevented by this device.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#95

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

My dad just had some major health issues, and has a much harder time getting around the house. He finds these things pretty useful to save him some trips around the house.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#96
I call it Misplaced Distrust.

Every cellphone in the world has a microphone that could be listening all the time and sending data anywhere. So does most every computer. It's a better threat vector by 1000x, more stealthy, easier to conceal traffic. But all anyone ever talks about is a device designed to listen to you talk because hey, so obvious, big brother MUST be listening in there!

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#97

Of course now I need to trust the Alias device. That might very well be a good tradeoff, but there's still something always listening.

Except now you can audit the software and not connect it to the network at all.

Good point if I set up the Pi myself, but it's unclear if this will apply to the device if it gets produced commercially.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#98
post #80

Earlier quoted context omitted.

Some may see smart devices as part of a greater cultural movement, in which corporations entice individuals to trade privacy for convenience Someone who thinks these things are a gimmick, and a harmful gimmick at that, is right to express an opinion about the value these devices add. The same way I'd encourage a friend to quit chain smoking tobacco cigarettes, and not visit his house with my family if it were full of…

So, you’d tell your chain smoking friend to quit smoking every time he lit a cigarette? At some point, I would think he would say it’s none of your business.

Peer pressure is the main reason I quit smoking. So yes-- if not every time, then at least regularly and consistently. When technology starts to look like a recreational drug, treat it like a recreational drug.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#99
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Also, it would make no business sense to always be listening. A lot of people think that just because Alexa and Google Assistant are free to use, it means that these services are virtually free for the companies as well, but that's not the case. There is no way Amazon or Google would waste millions of dollars running the state of the art speech recognition algorithms on your house's background noise.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#100

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Packet sniffing and hardware inspection both instantly disprove...

I'm under the impression that packet sniffing is useless with end-to-end encryption, but I could be wrong. I.e., you can tell that something is being sent, but you can't know what.

Post reply on HN