Live data from Hacker News

Google employees are listening to Google Home conversations

translate.google.com

261–270 of 463 posts

Re: Google employees are listening to Google Home conversations

#261

I think the responses to this can be broken down into a 2x2 matrix: level of concern vs. understanding of technology. 1) Don't understand ML; not concerned - "I have nothing to hide." 2) Don't understand ML; concerned - "I bought this device and now people are spying on me!" 3) Understand ML; not concerned - "Of course, Google needs to label its training data." 4) Understand ML; concerned - "How can we train models/c…

The meta-issue in the United States is that once your data is accessible to a third party, you have no sovereignty over it, and abuse by private actors is "agreed to" by click-wrap and access by government actors is a simple subpoena.

The law needs to catch up. Sharing should require specific informed consent and legislation needs to establish a scope where data stored as a "tenant" on a third party server is given 4th amendment protection.

Re: Google employees are listening to Google Home conversations

#262
post #2

This falls into the category of: I bugged my house... NOW MY HOUSE IS BUGGED! Not to dismiss the value of the news here, it is important for folks to know, but the overall situation is both concerning, and amusing.

I'm not sure why it's unreasonable for customers to have assumed this is like every other product: they developed it with employees and voluteers before shipping. After all, the voice recognition in my Prius doesn't send recordings of my "call mom and dad mobile" back to Toyota and it certainly doesn't send random snippets of conversations my wife and I have to low paid contractors around the world.

> After all, the voice recognition in my Prius doesn't send recordings of my "call mom and dad mobile" back to Toyota and it certainly doesn't send random snippets of conversations my wife and I have to low paid contractors around the world.

How do you know? Is it not internet-connected?

Re: Google employees are listening to Google Home conversations

#263

Earlier quoted context omitted.

It's not wrong for humans to label training data. It's wrong to let humans listen to voice recordings that users believed would be between them and a computer. The solutions are obvious: sell the things with a big sticker that says, "don't say anything private in earshot," revert to old fashioned research methods where you pay people to participate in your studies and get their permission, or ask people for permissio…

> ask people for permission to send in mis-heard commands Note that you also want the "correctly" heard commands, because some of them will have been incorrect. It's frustrating when an assistant gives the "I don't know how to do that", but it's even more frustrating to get "OK, doing (the wrong thing)". Also, another alternative: provide an actual bug reporting channel. "Hey Google, report that as a bug" "Would you…

To be fair the system already has something like that. If you complain to the Home it'll ask if you want to provide feedback and give you a few seconds to verbally explain what went wrong.

I'm not sure if humans will then review that feedback of if it goes through a speech to text algorithm first but the mechanism for feedback is there.

Re: Google employees are listening to Google Home conversations

#264
post #222
post #202

Earlier quoted context omitted.

Because you can check. Open it up, see what it does. Use Wireshark to inspect traffic. More importantly, anyone can check, and many people have. Imagine the scoop that "the mute switch does nothing" would be for a tech journalist.

Here is a Google Home teardown: https://www.ifixit.com/Teardown/Google+Home+Teardown/72684 You will note that the mute button is not a physical switch that cuts the signal from the microphone, but a soft button. It will probably do what it claims most of the time, but if Google for whatever reason wanted to secretly unmute it remotely, I have no doubt they could. Wireshark? Sure, but what am I even looking for? They…

> if Google for whatever reason wanted to secretly unmute it remotely, I have no doubt they could.

Many things can happen in a hypothetical future, what does that have to do with today's reality?

Re: Google employees are listening to Google Home conversations

#265

Earlier quoted context omitted.

Is it feasibility, or just laziness? My car has a little blurb that explains that they collect data to use for training and gives me the choice to participate or not. Opting out doesn’t affect any functionality. Why can’t Google do the same thing?

Because Google's first allegiance is to the shareholders and data has value so it's not in their best interest to make it easy not to share your data.

The shareholder value theory is rubbish, because it has no predictive or descriptive powers for why one decision was made over another.

I can just as easily say that the best way to maximize shareholder value is to minimize public scandal, scrutiny, and potential for legislature.

Nearly every single decision, including contradictory ones, made by every single company, everywhere, can be retroactively justified to have been done in the name of shareholder value.

Re: Google employees are listening to Google Home conversations

#266

Earlier quoted context omitted.

"... I think there needs to be a massive breach or abuse of power from one of these organizations/services that has severe real world consequences for those that utilize/support them..." One of my greater fears is the knowledge that, should this happen, there's a nonzero chance that no one would care.

I suppose it hasn't had mass real world consequences for folks yet, but the Equifax breach pretty much proves this?

Yes, the Equifax breach is one of the reasons I included "severe" as a qualifier. It has been demonstrated that even fairly serious breaches will be ignored by the general public. It needs to be something that makes people genuinely fear for the safety of their finances, possessions, and/or health

Re: Google employees are listening to Google Home conversations

#267

Earlier quoted context omitted.

It sounds like you're hoping for this as evidence that you were right to be concerned; have you considered that you might be wrong? What if your coworkers are right, and the risk is actually extremely low? How would you determine that?

>It sounds like you're hoping for this as evidence that you were right to be concerned Not at all, if the constant security breaches and lack of response from consumers, regulators, companies, etc. isn't enough evidence for you that there is a serious problem then you fall into the group I'm describing

What constant security breaches? There are two major examples of security breaches I can think of that happened recently at amagoofaceoft: mis-stored passwords (fb/insta, and google for a short period earlier this year), and variants of the Cambridge analytics attacks, which steal public information but at scale. While those certainly aren't good, I wouldn't classify either as a security breach. The first was a loss of defense in depth, and the second, like I said, just got public info, but lots of it.

Are you saying that breaches at other companies mean we shouldn't trust the big ones to be secure? Like because Equifax has terrible security practice, google by definition must also have bad security? Or...what?

(I work at Google).

Re: Google employees are listening to Google Home conversations

#268

Earlier quoted context omitted.

>The fact that I do not get any feedback whatsoever when things go wrong leads me to have no faith that the problem will be resolved in any satisfactory manner. When combined with a complete lack of consumer/business interaction options in general (w.r.t. Google), it leads to some very dissatisfied consumers. I guess you can ask for your money back? Lets stay grounded in reality here, Google is paying money on your b…

> Lets stay grounded in reality here, Google is paying money on your behalf to improve your experience. Lets stay grounded in reality here, Google is not doing this for me or on my behalf . Google just invests a bit to take a bunch of very valuable user data and then monetizes it for far more than it took to obtain it. This relies on the fact that most users are unaware of how valuable their data is. As a business mo…

How do they monetize voice recognition data, other then by selling devices that use voice recognition, and trying to make them better for the user?

Re: Google employees are listening to Google Home conversations

#269
post #265

Earlier quoted context omitted.

Because Google's first allegiance is to the shareholders and data has value so it's not in their best interest to make it easy not to share your data.

The shareholder value theory is rubbish, because it has no predictive or descriptive powers for why one decision was made over another. I can just as easily say that the best way to maximize shareholder value is to minimize public scandal, scrutiny, and potential for legislature. Nearly every single decision, including contradictory ones, made by every single company, everywhere, can be retroactively justified to hav…

Right! All the companies doing it differently are also trying to satisfy their shareholders.

Re: Google employees are listening to Google Home conversations

#270

Earlier quoted context omitted.

>It sounds like you're hoping for this as evidence that you were right to be concerned Not at all, if the constant security breaches and lack of response from consumers, regulators, companies, etc. isn't enough evidence for you that there is a serious problem then you fall into the group I'm describing

What constant security breaches? There are two major examples of security breaches I can think of that happened recently at amagoofaceoft: mis-stored passwords (fb/insta, and google for a short period earlier this year), and variants of the Cambridge analytics attacks, which steal public information but at scale. While those certainly aren't good, I wouldn't classify either as a security breach. The first was a loss…

> Are you saying that breaches at other companies mean we shouldn't trust the big ones to be secure? Like because Equifax has terrible security practice, google by definition must also have bad security? Or...what?

Are you asserting that Google detects 100% of significant breaches, and promptly notifies the public of all of them?

My experience tells me that neither assertion is likely to be true.

Post reply on HN