Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

141–150 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#141
post #67

Earlier quoted context omitted.

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

What, you think the rasberry pie is a internet connected listening device too? Why did you connect it to ethernet then?

He's not talking about a rasberry pi in general, he's talking about Project Alias, the device featured in this article, and the first step in the instructions is connecting the Pi to your Wifi so you can download the software.

So yeah, this project turns the raspberry pi into an internet connected listening device.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#142

Earlier quoted context omitted.

Your smartphone is also always listening. What's the difference?

I don't use a smartphone

Do you see legitimate uses for smartphones?

The way I see it is if you already own a smartphone then echo or home don't really add additional exposure.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#143

I'm much less interested in gating audio recording (which I have reasonable confidence in the device itself doing) and much more interested in being able to use a device like this without turning on all of the various histories. Google Assistant refuses to do most of its interesting functions (other than trivial things like setting an alarm) without turning on search history, location history, voice history, and vari…

> which I have reasonable confidence in the device itself doing A few horror stories related to Alex hint that it might not be doing a very good job. The grammar/syntax it uses to wake is much more complex than what Alias is proposing as a safe alternative. The most blatant example would be the Portland, OR couple that found the Alexa device making phone calls to people as they had a discussion near it.

I don't know about Alexa but Google Home always repeats back to me in a loud and clear (and slow :( ) voice what it's about to do when I issue a command. I have a hard time believing you wouldn't notice the device making a call. Even if you failed to notice what the device was doing, the likelihood of this type of mistake vs. the likelihood of a pocket dial seems relatively slim.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#144
post #104
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

From a non-privacy perspective this adds the feature of being able to customize your wake word, which besides being a nice feature on its own also counters Google and Amazon's desire to inject their brands deeper into our psyche by making us say them out loud. From a privacy perspective, having user control of the wake word prevents Google and Amazon from adding future wake words that could be abused for other ways t…

Google might get the bright idea to track TV ads by listening for audio in the ads

Considering that some TVs have this built-in, I'd be surprised if Google wasn't already doing the same. It's why my "smart" TV isn't allowed to connect to my wifi network.

(There was a previous HN article about it, I believe the brand was Samsung.)

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#145

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

Surely somebody in the '90s said something similar with regard to location data, and yet your location is tracked 24/7 by adtech megacorps, and the thousands of tech/adops employees don't say a peep. The playbook has 3 easy steps:

1. Get people addicted to technology X.

2. Keep bugging people using technology X to surrender their privacy using classical dark patterns.

3. Profit!

There is no need for whistleblowers. It's all done in the open. You have already willingly surrendered your communications, your 24/7 location, your knowledge searches, your financial transactions, your media interests and your genetic material. Why not surrender the privacy of your home as well? Yes/AskMeLater.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#146
post #99
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Also, it would make no business sense to always be listening. A lot of people think that just because Alexa and Google Assistant are free to use, it means that these services are virtually free for the companies as well, but that's not the case. There is no way Amazon or Google would waste millions of dollars running the state of the art speech recognition algorithms on your house's background noise.

There is no way Amazon or Google would waste millions of dollars running the state of the art speech recognition algorithms on your house's background noise.

Unless they wanted to listen for a dog barking, then add "pet food buyer" to your profile data.

There are a lot of very easy use cases for monitoring background noise.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#148

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

How about the issue where Google’s devices were errantly recording everything due to a hardware issue - where the button override for the voice activation was stuck in the activated position. People who think that there’s no way that Google and Amazon could be recording everything need to realize that this is also not true. Most of these “limitations” are software enforced, and that software is updated constantly.

Over a year ago Google removed the part of the hardware that caused that bug on the Home mini: https://www.theverge.com/circuitbreaker/2017/10/11/16462572/...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#149
post #54

Earlier quoted context omitted.

If you don't trust these devices, you probably wouldn't trust your phone either.

And I have a feeling many people who make a privacy case against Echo/Home forget that their phone does the same thing.

In addition to knowing where you are, and potentially what sites you visit, who you communicate with, etc.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#150

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

I'm reminded of the Volkswagen diesel emissions scandal, where VW were doing something illegal and were whistle-blown by a developer, costing them billions of USD in fines and massive damage to their brand.

Just because something is ultra high risk, stupid, illegal and abuses consumers isn't apparently enough of a reason for large corporates not to do it.

Post reply on HN