Live data from Hacker News

Vendors must start adding physical on/off switches to devices that can spy on us

larrysanger.org

21–30 of 200 posts

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#22
It's too bad there's not a company with enough funding and incentive to make equivalents that don't need to phone home. Ones that are competitive in price, functionality, etc.

The recent HN post about Mozilla's IOT offering was encouraging: https://news.ycombinator.com/item?id=19695595

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#23
post #21
post #15

Earlier quoted context omitted.

I was thinking more of Alexa type devices.

Where’s it been shown that Amazon Echos spy on you?

The purpose of a knife is to cut. You simply trust the wielder of it, perhaps more than you should.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#25
post #22

It's too bad there's not a company with enough funding and incentive to make equivalents that don't need to phone home. Ones that are competitive in price, functionality, etc. The recent HN post about Mozilla's IOT offering was encouraging: https://news.ycombinator.com/item?id=19695595

While that would be ideal, I don't personally mind the phoning home if it only happens after the wake word and if the cloud service greatly improves the response capabilities it might otherwise have. Yes, the word can be heard by mistake, but that's just the risk trade-off I make.

I think a physical off switch would be good. At the moment I just unplug my Alexa if I'm particularly concerned it might hear something sensitive.

I know many HN readers are far more privacy-conscious than I am, but that's just how I think about it. I personally consider cybercriminals and people who dislike me far greater privacy and security risks to me than tech giants or even the US government.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#26
post #16

Earlier quoted context omitted.

Hopefully this would easily be detected, and the brand damage from the resultant public shaming should be enough of a deterrent. But maybe it's really well hidden and eludes detection, or people just don't care and there is no brand damage, or maybe even there's no "real" brand to damage (OEM crapware).

What's the brand damage from the resultant public shaming of e.g. Google Nest Guard' 'hidden' microphone?

That's different. While still very bad, one is omission, and one is full-on deceit.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#27
To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would be a red flag (which the vendor could try to explain if it is a non-spy message like an unusual error code).

Cryptographically I believe it is possible to encrypt a message such that either the user's key or the vendor's key can decrypt, but I'm not 100% sure.

Re: Vendors must start adding physical on/off switches to devices that can spy on us

#30
post #27

To suggest an alternative, all devices capable of internet communication must allow their traffic to be decrypted by their owner (how that password gets set is up to the individual device). This would allow owners who care to set up a man in the middle and confirm that all outgoing (and maybe even incoming) traffic to the device is what they expect. Any outgoing message that is not decryptable or not expected would b…

Easier is to just let the user compile and reflash the firmware themselves.

But yeah you could give the user access to the devices private keys and certificate store.

Post reply on HN