Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

111–120 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#111

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught pretty quick because the device would be "lit up" constantly (another _hardware_ thing)

From pure technical perspective, can the device not be programmed to be waked by wakewaord “the” with the light off?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#112
post #89

Earlier quoted context omitted.

I too grew up in the time of card catalogs. And I learned a lot from reading through the other encyclopedia entries as I flipped the pages looking for the page with the info. Yes, you're right, the voice interface is not the astronomical leap that the cellphone was. But why is that your cutoff line? My voice assistants offer a lot of benefit to me. Especially with kids, I don't always have a free hand to pull out the…

My personal experience is that simply typing my query into a search engine or pressing the spotify logo to start my music requires less effort or fuss than attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want. IE, using voice commands is a downgrade IMO. Voice commands are not directly discoverable, and there's a lot more magic boxes.

I control my lights by saying “all lights red” and “dim all lights to 20%”

Compare this to the number of taps required to do so in the hue app

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#113

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

How about the issue where Google’s devices were errantly recording everything due to a hardware issue - where the button override for the voice activation was stuck in the activated position. People who think that there’s no way that Google and Amazon could be recording everything need to realize that this is also not true. Most of these “limitations” are software enforced, and that software is updated constantly.

This is the main problem that I see. Sure, I tested the packets, sniffed them, made sure it wasn't recording, etc, but then they push an update the next day. I don't think it's practical to monitor these devices all the time, and I haven't been asked to opt-in to an Echo update.

I also don't necessarily assume mal-intent on the part of the companies, but that doesn't mean there won't _ever_ be that intent. Trusting that all of these assumptions hold over time is hard.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#114
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t)

Citation needed.

Or if you have reference firmware I can load, that would be awesome... What do you mean its closed firmware and controlled by Amazon/Google? You mean they can change it whenever they wish, and we have no say???

Long story short; you rented a spy device and you trust some random person online it isn't spying... Even though there are credible stories of these devices doing precisely that.

No, no, absolutely not, and hell no!

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#115
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Who cares. Whoever buys the hardware can do whatever they want with it. If someone feels better with this device on their Google / Alexa product let them do it. If the speech recognition is horrible I’m sure they’ll take it off.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#116
post #72
post #67

Earlier quoted context omitted.

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

It's an open source project. There's no company to trust.

Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#117

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

Those two separate control boards didn't stop my Amazon dot from acually recording ambient noise and uploading it to Amazon's systems. I know this because of the audio history they themselves provide! You can literally go back and play back all the audio recorded, and a great deal of it did not include questions. Further, there was also a report of being able to trigger audio recording without either activating the LED ring or using a wake word via a serial root console. While a third-party attacker is unlikely to use that method of access, nothing about the hardware actively prevents Amazon ftom triggering it that way. Likewise for Google.

And yes, I work on this stuff. Neither Google nor Amazon have the hardware limitations you suggest.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#118
post #89

Earlier quoted context omitted.

I too grew up in the time of card catalogs. And I learned a lot from reading through the other encyclopedia entries as I flipped the pages looking for the page with the info. Yes, you're right, the voice interface is not the astronomical leap that the cellphone was. But why is that your cutoff line? My voice assistants offer a lot of benefit to me. Especially with kids, I don't always have a free hand to pull out the…

My personal experience is that simply typing my query into a search engine or pressing the spotify logo to start my music requires less effort or fuss than attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want. IE, using voice commands is a downgrade IMO. Voice commands are not directly discoverable, and there's a lot more magic boxes.

> attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want

I have yet to find a use case for modern voice control that required more than a passing thought about how to word things. Even my technologically illiterate parents can use these devices with relative ease, especially compared to smart phone and desktop computer UIs. Have you actually tried out these devices or are you just assuming they're as bad as they were 20 years ago?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#119
post #38

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

Do you have kids? I have three small ones, and they are just starting to desire technology. From my perspective, letting them control music (which they want, and I want them to have) is much better using a Google Home device than giving them access to my phone or tablet. If you don't have kids, you have no idea how loud and aggressively they will scream when they want something, and especially when these devices are…

It's not a devil's bargain, you have lost the ability to bargain. It's a common theme with parents these days.

There is nothing magical about technology, it's just an application of age-old parenting principles. And there's nothing particularly harmful about technology either, there should be no grand battle: you define the limits and the children should stick to them and respect you as a parent. This is true for all things children want to do, from screaming and playing indoors to accessing communal devices to getting their own devices when you, as a parent determine they should.

Post reply on HN