Live data from Hacker News

Google listening in to your room shows importance of privacy defense in depth

privateinternetaccess.com

61–70 of 124 posts

Re: Google listening in to your room shows importance of privacy defense in depth

#61
post #39

I want my desktop operating system to offer fairly fine-grained control of permissions I selectively grant to processes/applications. I would like the ability to easily revoke Chrome's ability to use my audio inputs, and then—if the use case comes up, such as a WebRTC conference—I can grant permission either on a one-time basis or until I revoke. This would be the operating system controlling the application's capabi…

An HIPS can do much of this on Windows. It takes some training though.

I use the free one that comes with Comodo Firewall, but I am unaware of any free, quality, stand alone alternatives.

Re: Google listening in to your room shows importance of privacy defense in depth

#62
post #32

How does he know Chrome is transmitting ALL conversations that it hears? His arguments aren't valid: "(Ok, so how does it know to start listening just before I’m about to say ‘Ok, Google?’)" This could easily be achieved offline. The same argument could be made for Siri, a wiretapping device which you carry with you all the time. In fact wiretapping your phone would be much more effective then wiretapping a computer…

Agreed - there is a lot of speculation here.

In the U.S., implementation of a wiretapping scheme like this would be a significant civil and criminal violation. Google is already under a FTC consent degree for privacy violations, which would make it doubly egregious. So I'll give Google the benefit of the doubt - and assume there are privacy-protective mechanisms designed in to the system.

In the age of ambient technology, where anything can be recorded, the onus is now on developers to create systems that internally suppress mass privacy violation. The "Privacy by Design" approach (disclosure, I have an evangelist of PbD) can provide solid guidance as to how to build privacy-protective mechanisms (e.g. data minimization, data scrubbing) into ambient technologies.

Re: Google listening in to your room shows importance of privacy defense in depth

#63
post #24

Earlier quoted context omitted.

A couple of hundred million dollars is a trivial write off for google. It should be a 5% of revenue.

Can we stop with the witch hunts and the desire to maim folks over minor infractions like this? Consider that you're one of the developers that wrote this feature. You try very hard to make sure your users privacy rights are respected. Normally your work is strong and you catch all of the corner cases, but this one you missed. You've fixed it upstream, but folks are demanding 5% of the company's bottom line because o…

> Consider that you're one of the developers that wrote this feature. You try very hard to make sure your users privacy rights are respected.

Surely a developer working for Google knows that user privacy is not a priority for the company?

Re: Google listening in to your room shows importance of privacy defense in depth

#65
post #8

I wonder if European Commission would be interested in adding this to their investigation, couple of hundred million dollars should be enough penalty for violating users privacy.

Downloading a binary blob is violating user privacy?

Re: Google listening in to your room shows importance of privacy defense in depth

#66
post #53

Earlier quoted context omitted.

Nope, I have no proof, and of course I'd be happy to learn that they aren't listening. I just hypothesize that they are based on my experience, but I've not tried to test it in any systematic way.

Listening all the time and sending the audio to Google would kill an smartphone in a moment. Apaty of the bandwith used

That's presuming it just doesn't cue up a text or audio[1] log on the device and upload it to Google the next time it's on wi-fi and plugged into a charger.

1. 4khz mono audio is sufficient for human voice recognition and tiny in terms of storage.

Re: Google listening in to your room shows importance of privacy defense in depth

#67

Earlier quoted context omitted.

NaCl Enabled Yes Microphone Yes Audio Capture Allowed Yes Current Language en-US Hotword Previous Language en-US Hotword Search Enabled No Always-on Hotword Search Enabled No Hotword Audio Logging Enabled No What now?

Go to chrome://settings/ Uncheck: Enable "Ok Google" to start a voice search.

FYI I'm running Chrome 43.0.x on OS X 10.10.3 and Enable "Ok Google" is disabled under chrome://settings. I don't remember ever enabling it, so this behavior is correct.

Re: Google listening in to your room shows importance of privacy defense in depth

#68
post #37

Wow, is there really no way to disable this? I guess I'm going back to Firefox.

Of course there is a way to disable this, it's in the settings with all the other settings.

Where? You can turn off voice-activated search, but that doesn't actually disable the extension.

Re: Google listening in to your room shows importance of privacy defense in depth

#69
post #34

Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I highly doubt that this is the case. Instead, the plug in knows how to recognize "OK Google" all by itself. Once activated, then it starts sending audio data. IF it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.

It's not about consistently being bugged though--I see two troubling implications to this; a) Government A decides target B has valuable communications, and uses this audio capture functionality as an attack vector (ie, a MiTM server modifies the chrome binary blob request slightly to a version where chunked audio is sent back to a control server). b) (more likely) This binary blob contains a voice recognition algori…

What sort of transparency would satisfy you in this case?

Re: Google listening in to your room shows importance of privacy defense in depth

#70
post #28

Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I highly doubt that this is the case. Instead, the plug in knows how to recognize "OK Google" all by itself. Once activated, then it starts sending audio data. IF it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.

It's probably not actively listening to all users. But if it has the capability, then it can be activated upon request by law enforcement or the NSA.

This happened 12 years ago when the FBI tried to eavesdrop on conversations taking place in a car with OnStar or a similar device. Agents wanted to remotely activate the car's microphone; I wrote about the case here: http://news.cnet.com/Court-to-FBI-No-spying-on-in-car-comput...

The 9th Circuit said "no," but the court's reasoning wasn't based on privacy concerns. The reasoning was that companies can only be forced to comply with wiretaps when the order would cause a "minimum of interference" (and the FBI's tap would have disabled the call-an-operator feature if there were an emergency, which exceeded the "minimum of interference" threshold).

This is not unique to Google, which has done a better job than just about any company I can think of at fighting off overly broad surveillance demands; see my post from two years ago for examples: https://news.ycombinator.com/item?id=5725899

Why could Apple, Microsoft, or Samsung not be compelled -- let's assume an actual court order exists -- to deliver a software update to a specific user that allows FBI agents remote access to that device microphone? Or AT&T? Or Verizon? We know from recent history that AT&T is hardly likely to put up a fight.

I wrote more about the outer limits of the Feds' surveillance authority here: http://www.cnet.com/news/how-the-u-s-forces-net-firms-to-coo... Excerpt: "Precedents were established a decade or so ago when the government obtained legal orders compelling companies to install custom eavesdropping hardware on their networks..." And earlier: "In 1977, the U.S. Supreme Court ruled that surveillance law is a "direct command to federal courts to compel, upon request, any assistance necessary to accomplish an electronic interception..."

In terms of a hierarchy of privacy protection, I trust technology > courts > Congress > DOJ oversight > FBI.

Post reply on HN