Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

281–290 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#281

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#282

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen [...] Take note that Amazon Drop In [1] is a feature built around turning on the Echo mic remotely without a wake word. I don't think this feature could exist if there was a hardware limitation. [1] https://www.amazon.com/gp/help/customer/display.html?nodeId=...

Dropping in causes the Alexa to light up and play a tone, so not exactly stealthy.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#283

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

Good luck packet sniffing an encrypted text blob of your conversations the device is transcribing.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#284

Earlier quoted context omitted.

Those two separate control boards didn't stop my Amazon dot from acually recording ambient noise and uploading it to Amazon's systems. I know this because of the audio history they themselves provide! You can literally go back and play back all the audio recorded, and a great deal of it did not include questions. Further, there was also a report of being able to trigger audio recording without either activating the L…

You are making an enormous amount of assumptions based on a semantic argument. Echo devices only begin recording if they think they hear the wake word. Obviously this is less than straight-forward, hence the recordings that didn't follow the wake word (just examples of an Alexa device incorrectly thinking it heard it). To suggest that a serial root console is a point of attack for an Echo device is bordering on insan…

[deleted]

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#286
post #204

Earlier quoted context omitted.

Not a hardware guy, but couldn’t you tie the LEDs to whatever bus that connects the mic and the main CPU?

Yes, I don't mean to say it's impossible - just that you'd need an entirely isolated system to detect when data was flowing over that link which is physically connected in all cases and cannot be updated. I don't believe we see that in either the Alexa or Google Home, but I'd be happy to be mistaken if anyone's done a more in depth teardown of these systems. And all of this is hinged on hoping you notice LEDs firing…

As an alternate angle - Instead of trying to disable the light have it show the "I'm doing a software update" light pattern. I know I personally wouldn't give that a second glance

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#287
post #281

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?

It's like in school where there's an advantage/disadvantage question and I only know one thing: I wore the same thing as advantage and disadvantage.

The advantage of a stationary device is you don't have to charge it. It is always connected.

The disadvantage is you don't have to charge it. It is always connected so the engineers don't have to make trade offs they'd have to make on a battery operated phone.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#288
im confused, how are people arguing about if amazon echo or other smart devices record conversation without the wake up prompt?

-https://www.kiro7.com/news/local/woman-says-her-amazon-devic...

amazons statement is:

“Echo woke up due to a word in background conversation sounding like “Alexa.” Then, the subsequent conversation was heard as a “send message” request. At which point, Alexa said out loud “To whom?” At which point, the background conversation was interpreted as a name in the customers contact list. Alexa then asked out loud, “[contact name], right?” Alexa then interpreted background conversation as “right”. As unlikely as this string of events is, we are evaluating options to make this case even less likely.”

-https://www.theverge.com/2018/5/28/17402154/how-to-see-amazo...

amazon

"For these instances, Amazon claims that the devices were likely triggered by false positive commands."

in my mind, it's not a question of if the device is recording you, because that's exactly what it's made for. it's a question of, if the company or even worse, govt. want to use these devices for spying or info gathering.

we already know the NSA has back doors and exploits they explicitly decide to keep open so they can access devices for information gathering i.e spying.

-https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-...

so, i feel if you don't wish to open yourself up to the idea of a device spying on you, that's perfectly acceptable.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#289
post #225

Earlier quoted context omitted.

> Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead. I trust that amongst thousands of people with different incentives at least one will raise their voice if something is not right. At least more so than I trust a corporation with, in this case, the the wrong incentives to self-regulate to my expectations.

I've always wondered how much OS code gets audited or if everyone just assumes someone else will do it (bystander effect)

[deleted]

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#290

Earlier quoted context omitted.

I like to be able to play music, ask simple questions, etc. without pulling out my phone. I don't understand why those aren't "legitimate" use cases. Maybe you don't like the tradeoff you're making in using such a device, but if I'm fine with it, how are my uses cases not legitimate?

Apologies if this comes across as too "get off my lawn", but I come from a time when to look something up, you had to haul yourself to the library; open one of dozens of drawers filled with index cards; find the card your looking for, which directed you to a stack in the library; find the book on the stack; and finally find the page in the book by consulting an index. It's a lost art. Then, you would have to go to an…

I'm sort of on the boundary there. I didn't have a cell phone until I moved away from home for school. I had occasional access to dial up Internet as a kid, but I still remember plenty of afternoons spent at the library.
Post reply on HN