Live data from Hacker News

Google listening in to your room shows importance of privacy defense in depth

privateinternetaccess.com

31–40 of 124 posts

Re: Google listening in to your room shows importance of privacy defense in depth

#31

Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I highly doubt that this is the case. Instead, the plug in knows how to recognize "OK Google" all by itself. Once activated, then it starts sending audio data. IF it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.

I just tried the feature out on my windows pc with chrome, and chrome only reacts to ok google when you have a new, empty tab, or the google search page open and active as the main tab. Additionally i checked with procmon what network activity chrome was making, and while it starts sending stuff AFTER "ok google" is activated, it doesn't send any between me saying it and chrome confirming it.

The theory that it's a small local plugin is also affirmed by the fact that my cellphone can do "ok google" without any sort of network, and is sometimes tricked into activating by audiobooks that make noises completely unlike "ok google".

Re: Google listening in to your room shows importance of privacy defense in depth

#32
How does he know Chrome is transmitting ALL conversations that it hears? His arguments aren't valid:

"(Ok, so how does it know to start listening just before I’m about to say ‘Ok, Google?’)"

This could easily be achieved offline.

The same argument could be made for Siri, a wiretapping device which you carry with you all the time. In fact wiretapping your phone would be much more effective then wiretapping a computer browser application.

Before making such accusations he should present some solid data, like network traffic from an idle chrome application during conversations (with and without saying "Okay Google"). If an idle chrome application was always transmitting data to google, he would have a solid argument.

Re: Google listening in to your room shows importance of privacy defense in depth

#33
Not surprised. I was a die-hard android user, but I kept having stuff like this happen to me, over and over again: http://www.reddit.com/r/technology/comments/2kwbl2/im_convin...

It also happens to my android-using friends. I've become convinced that Android phones are listening all the time so that they can figure out what we're about to search for and what to advertise to us.

Given that this has been my (admittedly anecdotal) experience with Android, I wouldn't be surprised at all if Google was trying to take this type of thing to the desktop with Chrome.

I love Google and have historically just not cared about my privacy as far as they're concerned, but I'm getting more creeped out as this kind of stuff becomes more pervasive.

Re: Google listening in to your room shows importance of privacy defense in depth

#34

Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I highly doubt that this is the case. Instead, the plug in knows how to recognize "OK Google" all by itself. Once activated, then it starts sending audio data. IF it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.

It's not about consistently being bugged though--I see two troubling implications to this;

a) Government A decides target B has valuable communications, and uses this audio capture functionality as an attack vector (ie, a MiTM server modifies the chrome binary blob request slightly to a version where chunked audio is sent back to a control server).

b) (more likely) This binary blob contains a voice recognition algorithm, which can of course detect the phrase "ok, google." Imagine they wanted to detect other phrases, like "drugs" or "travel." Small modifications could easily allow an arbitrary list of "hot" terms to be targeted. Then no audio is even sent back from the user's computer--a small flag in your google account is simply set attaching your profile to "high risk" terms overheard, and databased, where it could later be queried by law enforcement.

It's troubling because there's no transparency, and if you spend a little time brainstorming about the ways this could be used maliciously (most likely by a nation-state) there are many possibilities...

Re: Google listening in to your room shows importance of privacy defense in depth

#35
post #28

Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I highly doubt that this is the case. Instead, the plug in knows how to recognize "OK Google" all by itself. Once activated, then it starts sending audio data. IF it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.

It's probably not actively listening to all users. But if it has the capability, then it can be activated upon request by law enforcement or the NSA.

Any computer with a microphone (almost all!) has this capability.

Re: Google listening in to your room shows importance of privacy defense in depth

#36
post #24
post #8

I wonder if European Commission would be interested in adding this to their investigation, couple of hundred million dollars should be enough penalty for violating users privacy.

A couple of hundred million dollars is a trivial write off for google. It should be a 5% of revenue.

Can we stop with the witch hunts and the desire to maim folks over minor infractions like this?

Consider that you're one of the developers that wrote this feature. You try very hard to make sure your users privacy rights are respected. Normally your work is strong and you catch all of the corner cases, but this one you missed. You've fixed it upstream, but folks are demanding 5% of the company's bottom line because of a mistake /you/ made. The code isn't even used unless the user ticks a box to turn it on in the first place, which is even verifiable with a cursory use of system monitoring tools like fuser, lsof, etc.

You've been marked as costing a company a major stake of their income. You'll likely never live that down.

If you don't like the company's behavior, /don't use the software/. Simple, clean, and effective in large numbers -- more so than regulation action. Chromium is an open source first browser, we as a community actually have a hand in its development. If you don't like this, fix it.

Re: Google listening in to your room shows importance of privacy defense in depth

#38
post #32

How does he know Chrome is transmitting ALL conversations that it hears? His arguments aren't valid: "(Ok, so how does it know to start listening just before I’m about to say ‘Ok, Google?’)" This could easily be achieved offline. The same argument could be made for Siri, a wiretapping device which you carry with you all the time. In fact wiretapping your phone would be much more effective then wiretapping a computer…

listening doesn't necessarily mean recording and recording doesn't necessarily mean sending

Re: Google listening in to your room shows importance of privacy defense in depth

#39
I want my desktop operating system to offer fairly fine-grained control of permissions I selectively grant to processes/applications. I would like the ability to easily revoke Chrome's ability to use my audio inputs, and then—if the use case comes up, such as a WebRTC conference—I can grant permission either on a one-time basis or until I revoke. This would be the operating system controlling the application's capability.

I'm guessing a rough approximation is possible on some operating systems. Given the sprawling management infrastructure in Windows, I wouldn't be surprised if it has some "policy" framework in place that allows devices to be declared off-limits at a process granularity. The missing piece, then, is a viable user interface on top of that.

I'm not asking for something akin to the simplified permissions model of mainstream sandboxed mobile operating systems. Not set-and-forget; and certainly not all-or-nothing ("accept these required permissions or don't install the app.") Rather, something quite a bit finer grained and with the necessary infrastructure to have the OS prompt for privileged access if the application wants something I've disallowed, in a manner akin to Windows UAC prompts for admin credentials.

Imagine starting Chrome one day to have your operating system prompt you, "Chrome would like access to audio input 1 (microphone). Allow for now, permanently, or deny?"

Re: Google listening in to your room shows importance of privacy defense in depth

#40
post #35
post #28

Earlier quoted context omitted.

It's probably not actively listening to all users. But if it has the capability, then it can be activated upon request by law enforcement or the NSA.

Any computer with a microphone (almost all!) has this capability.

In theory, that's only true if the user has given permission for some remotely-accessible application to activate it. In practice, the NSA almost certainly has ways to accomplish it, but that doesn't mean we should make it trivial.
Post reply on HN