Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

241–250 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#241
post #73

Earlier quoted context omitted.

If they (the smart assistant makers) would promote the fact that their devices only go online after the trigger word is detected that would go far is assuaging people's fear of the always-on microphone

They have. The reality is that conspiracy theorists aren't interested in learning how things actually work, which is why they're conspiracy theorists. In reality your phone is a significantly bigger threat to privacy both in terms of normal day to day monitoring (e.g. location tracking) and even listening in (a closed source baseband that can communicate on a platform you cannot even monitor).

If that was the case, my Pi-hole would not be blocking thousands of outgoing network requests from my Echo and Google Home.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#242
post #8

I love this idea. I've wanted to do something similar for a long time, but I was thinking about building a home assistant where the always-on mic was a complete separate board that only listened for wake words and had no internet access. The main mic would only be powered on when the smaller board woke it up. Alias achieves the same thing in a much simpler way to where I might actually consider buying a home assistan…

How is this different than an actual echo device as it sits now? You're still relying on a piece of software to make the wake-word assessment and hand off the audio to the cloud. Now you're just adding more hardware parts to fail. If your argument is that you trust your software more than Amazon's, then you shouldn't need anything more than a single microphone anyways because why would you surveil yourself?

> ... you shouldn't need anything more than a single microphone anyways because why would you surveil yourself?

For the same reason nginx usually runs as a separate user: people make mistakes and security vulnerabilities happen. Security in depth is a good thing.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#243
post #232
post #67

Earlier quoted context omitted.

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

It doesn't have to connect to the internet to do what it does. The scenario you seem to be suggesting is that the Project Alias developers would be conspiring with Google by compromising Project Alias to NOT disrupt Google's listening and then Google would be listening in on you using their network access. This by definition does not double the area of risk. If you can be confident that Project Alias does not have ne…

I say to Project Alias "Call my friend Chris".

Project Alias whispers to my Amazon Echo "Call Secret Project Alias Man in the Middle"

Project Alias requires no network connection to do nefarious things.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#244

Earlier quoted context omitted.

Those two separate control boards didn't stop my Amazon dot from acually recording ambient noise and uploading it to Amazon's systems. I know this because of the audio history they themselves provide! You can literally go back and play back all the audio recorded, and a great deal of it did not include questions. Further, there was also a report of being able to trigger audio recording without either activating the L…

You are making an enormous amount of assumptions based on a semantic argument. Echo devices only begin recording if they think they hear the wake word. Obviously this is less than straight-forward, hence the recordings that didn't follow the wake word (just examples of an Alexa device incorrectly thinking it heard it). To suggest that a serial root console is a point of attack for an Echo device is bordering on insan…

> To suggest that a serial root console is a point of attack for an Echo device is bordering on insanity.

That was not what he said. He argues that Amazon/Google could remotely use a similar exploit (without direct access to the hardware) to start recording without lighting up the LED.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#245
post #138

Earlier quoted context omitted.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

I just kinda doubt this. How much backlash was there when it came out that the NSA was recording the full content of every cell phone call in the Bahamas? Edit: codename SOMALGET, subproject of MYSTIC. https://en.wikipedia.org/wiki/MYSTIC_(surveillance_program)#... http://www.documentcloud.org/documents/1164088-somalget.html

Why would there be? The Bahamas is not inside the United States and thus is part of the NSA's mission of monitoring foreign communications.

Spy agencies spy. It's their job description.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#246
post #104

Earlier quoted context omitted.

From a non-privacy perspective this adds the feature of being able to customize your wake word, which besides being a nice feature on its own also counters Google and Amazon's desire to inject their brands deeper into our psyche by making us say them out loud. From a privacy perspective, having user control of the wake word prevents Google and Amazon from adding future wake words that could be abused for other ways t…

Google might get the bright idea to track TV ads by listening for audio in the ads Considering that some TVs have this built-in, I'd be surprised if Google wasn't already doing the same. It's why my "smart" TV isn't allowed to connect to my wifi network. (There was a previous HN article about it, I believe the brand was Samsung.)

I think it was the Facebook app, it listened to ambient background to determine music and TV shows. The user had to opt in or at least approve permissions.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#247
post #96

I call it Misplaced Distrust. Every cellphone in the world has a microphone that could be listening all the time and sending data anywhere. So does most every computer. It's a better threat vector by 1000x, more stealthy, easier to conceal traffic. But all anyone ever talks about is a device designed to listen to you talk because hey, so obvious, big brother MUST be listening in there!

Cell phones have batteries, so it would be even less practical for phones to be "phoning home" a stream of what's going on around it at all times than a "smart speaker".

And metered data. I would be very aware if my phone was eating my data plan via constantly recording audio. Even a measly 12kbps audio stream adds up to nearly 4GB/mo if recording 24hrs/day.

Non-techie users would absolutely notice that their data and battery is being used up in the background pretty quickly. Further, the cell networks simply could not support that kind of usage from every single subscriber at the same time.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#248

Earlier quoted context omitted.

Your smartphone is also always listening. What's the difference?

For one, Amazon doesn't make smartphones, and I trust them the least. In the iOS ecosystem, Siri can be set up to only listen in response to a button-press (don't remember which is default), and the watch only listens on wrist-raise. Those at least creates some physical barrier to passive listening, even if it requires a certain degree of trust in the devices.

> In the iOS ecosystem, Siri can be set up to only listen in response to a button-press

Sure, that's assuming you trust Apple (if you don't, then you might imagine that those settings don't actually do what they say they do). If you trust them, then you're fine. If you're in Google's ecosystem, and you trust Google, then you're fine. Ditto for Amazon. But the point here is that people don't trust these entities.

And then somehow target a smart home speaker, while simultaneously carrying around an always-on, always-connected, geo-located, potential listening device in their pocket, all day long.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#249

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

Nice summary. For those who believe that one of these companies might (intentionally or accidentally) "flip the switch", would a project like this really do that much to persuade you that the device had now become safe for use? Or would you simply avoid knowingly purchasing any such devices? (In that sense I'm struggling to understand the true customer for a neat hack like this.)

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#250
post #187

Earlier quoted context omitted.

If your kids are screaming loudly and aggressively about things they want, you have a problem that technology will not solve.

No. You just have kids. The rest of what you said is incidental.

I have two kids, 9 and 11, and neither of them are screaming and yelling about what music to play. If they want to listen to music, they know to go to the rumpus room and pick out a vinyl.
Post reply on HN