This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…
Project Alias hacks Amazon Echo and Google Home to protect privacy
281–290 of 301 posts
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#282Earlier quoted context omitted.
> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…
> Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen [...] Take note that Amazon Drop In [1] is a feature built around turning on the Echo mic remotely without a wake word. I don't think this feature could exist if there was a hardware limitation. [1] https://www.amazon.com/gp/help/customer/display.html?nodeId=...
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#283Earlier quoted context omitted.
> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.
> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#284Earlier quoted context omitted.
Those two separate control boards didn't stop my Amazon dot from acually recording ambient noise and uploading it to Amazon's systems. I know this because of the audio history they themselves provide! You can literally go back and play back all the audio recorded, and a great deal of it did not include questions. Further, there was also a report of being able to trigger audio recording without either activating the L…
You are making an enormous amount of assumptions based on a semantic argument. Echo devices only begin recording if they think they hear the wake word. Obviously this is less than straight-forward, hence the recordings that didn't follow the wake word (just examples of an Alexa device incorrectly thinking it heard it). To suggest that a serial root console is a point of attack for an Echo device is bordering on insan…
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#285Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#286Earlier quoted context omitted.
Not a hardware guy, but couldn’t you tie the LEDs to whatever bus that connects the mic and the main CPU?
Yes, I don't mean to say it's impossible - just that you'd need an entirely isolated system to detect when data was flowing over that link which is physically connected in all cases and cannot be updated. I don't believe we see that in either the Alexa or Google Home, but I'd be happy to be mistaken if anyone's done a more in depth teardown of these systems. And all of this is hinged on hoping you notice LEDs firing…
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#287This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…
I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?
The advantage of a stationary device is you don't have to charge it. It is always connected.
The disadvantage is you don't have to charge it. It is always connected so the engineers don't have to make trade offs they'd have to make on a battery operated phone.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#288-https://www.kiro7.com/news/local/woman-says-her-amazon-devic...
amazons statement is:
“Echo woke up due to a word in background conversation sounding like “Alexa.” Then, the subsequent conversation was heard as a “send message” request. At which point, Alexa said out loud “To whom?” At which point, the background conversation was interpreted as a name in the customers contact list. Alexa then asked out loud, “[contact name], right?” Alexa then interpreted background conversation as “right”. As unlikely as this string of events is, we are evaluating options to make this case even less likely.”
-https://www.theverge.com/2018/5/28/17402154/how-to-see-amazo...
amazon
"For these instances, Amazon claims that the devices were likely triggered by false positive commands."
in my mind, it's not a question of if the device is recording you, because that's exactly what it's made for. it's a question of, if the company or even worse, govt. want to use these devices for spying or info gathering.
we already know the NSA has back doors and exploits they explicitly decide to keep open so they can access devices for information gathering i.e spying.
-https://www.wired.com/story/eternalblue-leaked-nsa-spy-tool-...
so, i feel if you don't wish to open yourself up to the idea of a device spying on you, that's perfectly acceptable.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#289Earlier quoted context omitted.
> Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead. I trust that amongst thousands of people with different incentives at least one will raise their voice if something is not right. At least more so than I trust a corporation with, in this case, the the wrong incentives to self-regulate to my expectations.
I've always wondered how much OS code gets audited or if everyone just assumes someone else will do it (bystander effect)
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#290Earlier quoted context omitted.
I like to be able to play music, ask simple questions, etc. without pulling out my phone. I don't understand why those aren't "legitimate" use cases. Maybe you don't like the tradeoff you're making in using such a device, but if I'm fine with it, how are my uses cases not legitimate?
Apologies if this comes across as too "get off my lawn", but I come from a time when to look something up, you had to haul yourself to the library; open one of dozens of drawers filled with index cards; find the card your looking for, which directed you to a stack in the library; find the book on the stack; and finally find the page in the book by consulting an index. It's a lost art. Then, you would have to go to an…