Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

201–210 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#201

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

Do you (or anyone else with the same claim) have a citation for this?

I've spent some time reverse-engineering the echo microphone board, and while there is an interlock that prevents recording while the red mute button is lit (just the light under the button, not the ring), I didn't see anything that would prevent recording while the ring light was off.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#202

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

I'm probably biased because I lived my early childhood behind the Iron Curtain but I can't for the life of me understand why someone would buy these. The cost-benefit is just not there.

Huh. I came to the opposite conclusion - growing up in Eastern Europe, "they're always listening" is the default position for me, so one more listening device is no big deal.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#203
post #160

Earlier quoted context omitted.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

> The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. Are you sure? I don't seem to remember too much backlash from this, which was pretty similar: https://www.esquire.com/lifestyle/cars/a33654/apple-is-shari... Or this more recent story: https://www.digitaltrends.com/home/amazon-alexa-sends-record...

The first article isn't anything nefarious.

> However, Apple's practice of sharing Siri data with third parties [to provide and improve Siri, Dictation, and dictation functionality] is perfectly legal and outlined in Apple's iOS Software License Agreement, which Siri users are required to accept.

I mentioned using the voice data to market "without permission." That's my rationale. All of these scary location tracking this, retargeting that methods are always buried in a privacy policy somewhere. But when you start doing it on the DL, that's when you get in trouble. So the cons greatly outweigh the pros for any sane company.

And of course the second article is an isolated case of human error. Nothing to do with violating privacy for profit.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#204

Earlier quoted context omitted.

They are.

How so? Ultimately the mic is always on and listening for its keywords - if you look at the teardown of the Alexa on iFixIt, I don't even see any device other than the main CPU that would be capable of performing keyword recognition. Meaning the main CPU would have to be the thing then controlling the lights after the keywords are recognized... The Google Home at least has a separate board with a microcontroller on i…

Not a hardware guy, but couldn’t you tie the LEDs to whatever bus that connects the mic and the main CPU?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#205

Earlier quoted context omitted.

Peer pressure is the main reason I quit smoking. So yes-- if not every time, then at least regularly and consistently. When technology starts to look like a recreational drug, treat it like a recreational drug.

Why is this downvoted? Peer pressure is by and large the best way to curb thoughts and actions that are harmful to individuals and society. The current echo chamber on the net filled with alternative/radical theories is the outcome of insufficient peer pressure. Nutbars always existed in real-life too, society was just better at keeping them from doing too much harm.

Those of us who are nutbars hate society for forcing us to conform. Given that a lot of us are more tech-savvy than society, we love that we tend to be able to work around its restrictions.

Also, obligatory http://www.paulgraham.com/say.html

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#206

Earlier quoted context omitted.

And so something like that can never happen again? Regressions are a very real thing, both in hardware and software.

I'm not sure how you would regress a button that physically doesn't exist anymore. Also, if you're that scared of future bugs that don't exist, then you should probably throw away your smart phone.

I think the point is that bugs exist and will continue to exist: whether it's the same bug, a different one, mal-intent, negligence, or anything else. Sure, this one device won't solve every single problem out there, but should we not solve anything just because we can't solve everything?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#207
post #188
post #72

Earlier quoted context omitted.

It's an open source project. There's no company to trust.

Do you think being an open source project makes it more secure somehow? It doesn't.

This is code you can inspect running on hardware that you own and control. It's trivial to ensure it's secure at that point. Unlike when it belongs to a company.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#208
post #195

Earlier quoted context omitted.

An aggressive screaming kid needs a timeout at the very least, followed by a progressive loss of privileges (toys) until the tantrum subsides. A few cycles is enough to amend even the most recalcitrant. I'm shocked: Why does your two year old need to know Google as a brand? How or why is this valuable to you? Do you expect Google to exist forever? Its entire revenue model is built on ads. Companies with more robust r…

Are you sure that gets what you want? Our desires for my kids might be different. Sounds like you think kids should be punished until they learn who is the boss. I'm not sure you have read all the literature on the effectiveness of that strategy. I never said I want my two year old to know the Google brand. She hears her older siblings saying it. It is just what is so with her. But guess what? I'm willing to wager my…

Sorry, my apologies. I misread your post read to mean that you were happy/excited to have your kid understand Google as a brand (i.e. valuable).

As for parenting, we may just agree to disagree. I concur with your assessment that siblings will definitely teach more than parents. That's to be expected. We just would never reward bad behaviour with acquiescence. But to each his own. Our seven-year old has wide latitude when it comes to choices and actions, but he also realizes that the consequences of those actions are not in his control. We gave him his own iPad at the age of 3 and access to his own real spending money in Grade 1. He gets to decide what to spend it on. At the same time, we've made it clear to him that poor impulse control and bad behaviour will never get him what he wants. He negotiates everything, including daily bedtime or routine tasks, and we're perfectly fine with that. It seems to align well with his personality, and builds some valuable life skills.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#209

Earlier quoted context omitted.

I'm not sure how you would regress a button that physically doesn't exist anymore. Also, if you're that scared of future bugs that don't exist, then you should probably throw away your smart phone.

I think the point is that bugs exist and will continue to exist: whether it's the same bug, a different one, mal-intent, negligence, or anything else. Sure, this one device won't solve every single problem out there, but should we not solve anything just because we can't solve everything?

Right, and my point is that bugs will exist for all devices, not just these. Applying the logic, "bugs could happen" to just these devices isn't rational because it applies to all all devices, especially smart phones. We shouldn't ditch devices because of future potential for bugs that don't exist yet.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#210

Earlier quoted context omitted.

What, you think the rasberry pie is a internet connected listening device too? Why did you connect it to ethernet then?

He's not talking about a rasberry pi in general, he's talking about Project Alias, the device featured in this article, and the first step in the instructions is connecting the Pi to your Wifi so you can download the software. So yeah, this project turns the raspberry pi into an internet connected listening device.

Also says in the same instructable that once the device is trained that there's no need to have the device connected anymore. It also doesn't need to be connected to the internet - you just need to be able to get to it via a browser with a microphone - I was able to train the device with no connection to the internet.
Post reply on HN