Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

171–180 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#171

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> the device would be "lit up" constantly (another _hardware_ thing) Unless the mic and lights are somehow wired together (they aren't), then this is really just more software which can be trivially updated away.

They are.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#172
post #159

Earlier quoted context omitted.

He's not talking about a rasberry pi in general, he's talking about Project Alias, the device featured in this article, and the first step in the instructions is connecting the Pi to your Wifi so you can download the software. So yeah, this project turns the raspberry pi into an internet connected listening device.

Great point. What happened with good old physical connections via USB cables?

It's probably the same reason that people started installing listening devices in their homes in the first place -- convenience. Few people want to walk around and plug in a cable to update/reconfigure their devices.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#173

Earlier quoted context omitted.

Your smartphone is also always listening. What's the difference?

I don't use a smartphone

I don't know why GP specified "smartphone", there's nothing special about the new phones. A nokia 3310 could spy on you all the same.

In fact, the nokia 3310 would probably be even less secure than modern phones.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#174
post #37

Earlier quoted context omitted.

That is correct! Google, Amazon, and Apple despite having vast resources don't have the ability/desire to pay for the bandwidth, storage, and processing needed to have 24/7 recording and analysis from every smart device, especially when you realize that includes cell phones. Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in…

Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in the same way Actually, they are. The majority of "ordinary" people I interact with believe Facebook is listening to their conversations 24/7. It's been brought up multiple times on HN.

>The majority of "ordinary" people I interact with believe Facebook is listening to their conversations 24/7.

Which is to their point because this is more an example of dunning-krugers with technology than anything else. Those "ordinary" people are data dumb, and project their own explanations onto data joining, which in this case they can only explain as 24/7 microphone recording.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#175

Earlier quoted context omitted.

> the device would be "lit up" constantly (another _hardware_ thing) Unless the mic and lights are somehow wired together (they aren't), then this is really just more software which can be trivially updated away.

They are.

How so? Ultimately the mic is always on and listening for its keywords - if you look at the teardown of the Alexa on iFixIt, I don't even see any device other than the main CPU that would be capable of performing keyword recognition. Meaning the main CPU would have to be the thing then controlling the lights after the keywords are recognized...

The Google Home at least has a separate board with a microcontroller on it which could be used for keyword recognition, but I'm pretty sure they allow that to be updated for the sake of improving keyword recognition and there's no reason that an update couldn't disable the LEDs in the listen state as far as I can see.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#177
post #91
post #57

Earlier quoted context omitted.

This is similar to the issue of people being scared of radiation from cell towers but somehow not freaking out that they have a transmitter in their pocket that uses the same range of frequencies but at vastly higher power (due to the proximity).

Like the people that attack smart electric meters while they talk on their cell phone

Cell phones don't leak precise power signals that identify exactly what a home user is doing. Smart Electric meters are absolutely part of the surveillance capitalism equation. Power Analysis is a leaky side channel.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#178
post #89

Earlier quoted context omitted.

I too grew up in the time of card catalogs. And I learned a lot from reading through the other encyclopedia entries as I flipped the pages looking for the page with the info. Yes, you're right, the voice interface is not the astronomical leap that the cellphone was. But why is that your cutoff line? My voice assistants offer a lot of benefit to me. Especially with kids, I don't always have a free hand to pull out the…

My personal experience is that simply typing my query into a search engine or pressing the spotify logo to start my music requires less effort or fuss than attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want. IE, using voice commands is a downgrade IMO. Voice commands are not directly discoverable, and there's a lot more magic boxes.

"hey Google, play some music"

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#179
post #116
post #72

Earlier quoted context omitted.

It's an open source project. There's no company to trust.

Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

Nothing is 100% guaranteed, but with an open source project, given enough users, its far less likely for someone to be able to bury nefarious stuff without many eyes looking at it and at least one person sounding an alert.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#180
post #81
post #76

Earlier quoted context omitted.

Whenever I find a stray Alexa or Google home at a friend's place I ask it how to import cocaine or where I can buy uranium. So far nothing's happened...

Nice friend! Do you search porn on their 'stray' computer while you're at it?

We do indeed throw horse porn into eachothers' search history. I sense your sarcasm - perhaps my friends and I have a different group culture than yours do?
Post reply on HN