Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

151–160 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#152

Earlier quoted context omitted.

How about the issue where Google’s devices were errantly recording everything due to a hardware issue - where the button override for the voice activation was stuck in the activated position. People who think that there’s no way that Google and Amazon could be recording everything need to realize that this is also not true. Most of these “limitations” are software enforced, and that software is updated constantly.

Over a year ago Google removed the part of the hardware that caused that bug on the Home mini: https://www.theverge.com/circuitbreaker/2017/10/11/16462572/...

And so something like that can never happen again? Regressions are a very real thing, both in hardware and software.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#153

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

These are software companies. These devices support OTA updates, including changing the activation word. It's trivial to change the activation word to empty or something innocuous. Ergo, there's no hardware limitation.

If your argument stems from "Google and Amazon would never do that," I do not trust any corporate entity to value my rights more than their ability to make a dollar.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#154
post #137

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

"Allow Google Maps to always access your location. Yes. Ask Me Later". Given the multiple precedents on the erosion of privacy path in the past 20 years, of which I quoted one example above, it's pretty obvious that they will turn "always on listening" in the future, using whatever dark patterns necessary to avoid a class action suit.

I am getting sick of yes, ask me later. Stop asking me completely

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#155
post #37
post #19

So doesn't Alexa already not record until you say the trigger word? If we don't trust that that is the case, then sure this device covers that, but it doesn't change the fact that they are still collecting data on every command you issue to the device.

That is correct! Google, Amazon, and Apple despite having vast resources don't have the ability/desire to pay for the bandwidth, storage, and processing needed to have 24/7 recording and analysis from every smart device, especially when you realize that includes cell phones. Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in…

Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in the same way

Actually, they are.

The majority of "ordinary" people I interact with believe Facebook is listening to their conversations 24/7. It's been brought up multiple times on HN.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#156
post #37
post #19

So doesn't Alexa already not record until you say the trigger word? If we don't trust that that is the case, then sure this device covers that, but it doesn't change the fact that they are still collecting data on every command you issue to the device.

That is correct! Google, Amazon, and Apple despite having vast resources don't have the ability/desire to pay for the bandwidth, storage, and processing needed to have 24/7 recording and analysis from every smart device, especially when you realize that includes cell phones. Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in…

Google Photos allows users unlimited storage when storing photos in their proprietary format. I see a 90-day buffer per user consuming roughly the same amount of storage.

Also disingenous to consider the smart speaker that works without cell reception in the same category. Those that require cell reception to work are just as circumspect as Alexa/Google.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#157
post #48

Earlier quoted context omitted.

Couldn't the device use voice-to-text and upload the text, possibly tagged with which voice profile said what? The same goes for phones, obviously.

That would either increase the cost of the device or degrade the performance of the speech-to-text. In the case of your phone, you'd get about an hour of battery life. Reasonably accurate speech recognition requires several orders of magnitude more computation than wake word detection.

That would either increase the cost of the device

On-chip speech-to-text has been around since the 80's. It's not expensive to implement, especially with modern manufacturing.

or degrade the performance of the speech-to-text

How accurate does it need to be? All the spy corporations need is a stream of keywords.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#158
Access to privacy equals business today. Therefore turning this "promise of privacy" project over to the business sector would be a contradiction in terms. Most of the world does not care that companies/governments have access to their privacy. Snowden is a good example of this principle. The few that do care would not be enough to sustain this "promise of privacy" business model. Therefore the responsibility is upon each individual to make their own Alias in order to protect their own privacy using this open source maker project. Great work to all those that worked on the Alias project!

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#159

Earlier quoted context omitted.

What, you think the rasberry pie is a internet connected listening device too? Why did you connect it to ethernet then?

He's not talking about a rasberry pi in general, he's talking about Project Alias, the device featured in this article, and the first step in the instructions is connecting the Pi to your Wifi so you can download the software. So yeah, this project turns the raspberry pi into an internet connected listening device.

Great point. What happened with good old physical connections via USB cables?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#160

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

> The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it.

Are you sure? I don't seem to remember too much backlash from this, which was pretty similar:

https://www.esquire.com/lifestyle/cars/a33654/apple-is-shari...

Or this more recent story:

https://www.digitaltrends.com/home/amazon-alexa-sends-record...

Post reply on HN