Live data from Hacker News

Google listening in to your room shows importance of privacy defense in depth

privateinternetaccess.com

111–120 of 124 posts

Re: Google listening in to your room shows importance of privacy defense in depth

#111
post #34

Earlier quoted context omitted.

It's not about consistently being bugged though--I see two troubling implications to this; a) Government A decides target B has valuable communications, and uses this audio capture functionality as an attack vector (ie, a MiTM server modifies the chrome binary blob request slightly to a version where chunked audio is sent back to a control server). b) (more likely) This binary blob contains a voice recognition algori…

This is true of any auto-updating software, including your operating system and all evergreen browsers. The problem with this blog post is that the author gets in a tizzy about what could happen, not what is actually happening. What could happen has not been affected by the recent Chromium screw-up, nor is it specific to Chromium.

Except Chromium as a framework is in an interesting position... and I think the threat is not even in how this could be used with malicious intent, but rather how easy it allows for indiscriminate passive logging on a grand scale.

Chrome is a very widely-distributed piece of trusted, self-updating software. It's also (for most users) directly connected to your google account--which is in many ways an intimate mirror to your identity.

You're absolutely right that this issue is not unique to Chrome, and can (and does) arise in any piece of software from native OSes & apps to 3rd party binaries.

I also think Chrome specifically warrants added concern for its ubiquity and de-facto link to your identity.

Anyone can use these techniques to target an individual, network, or system, but Chrome is one of the most widely distributed pieces of software designed with analytics in mind, from a company known for designing algorithms to improve contextual awareness.

What that means is, it's uniquely trivial to add in a few vectors of phonemes to recognize certain words/phrases, flip on an analytics pixel, and instantly have 100's of millions of devices running chrome associate their linked google accounts with this word/phrase.

Re: Google listening in to your room shows importance of privacy defense in depth

#112

Earlier quoted context omitted.

Physical switches are the most common point of mechanical failure. It translates to real-world lost revenue in terms of returns and repairs to include them at all. ... but yes, they should still be included. ;)

There's a light for the camera, they should just add one for the microphone.

While acceptable for most paranoid users, the indicator light isn't as secure as a physical switch. For some devices (most notably 2007/2008 era MacBooks) the controller can be manipulated to enable the camera without giving any visual indication via the light.

Re: Google listening in to your room shows importance of privacy defense in depth

#113

Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I highly doubt that this is the case. Instead, the plug in knows how to recognize "OK Google" all by itself. Once activated, then it starts sending audio data. IF it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.

More importantly, the plugin does not even run unless you opt in to hotwording (by checking the check box in settings). The open source Chromium code makes sure of this. So you do not need to take our word for it.

Please see my statement here for details: https://code.google.com/p/chromium/issues/detail?id=500922#c...

Furthermore, you are right that if you turn on the "Ok Google" setting, the plugin will start listening to your microphone, but will not send audio to Google servers unless it hears an "Ok Google".

Re: Google listening in to your room shows importance of privacy defense in depth

#115
post #64

Note that all android phones have that issue. Also all windows phones and soon windows 10. Oh and smart tvs. it is a real problem though

> all android phones have that issue Citation needed. "Ok Google" functionality is an expressly required opt-in. I had to go out of my way to turn it on.

google phones (nexuses) pretty much turn it on as u hit next next next on install thats actually pretty similar the chrome tvs also warn you usually - but nontech ppl dont notice. next next.

Re: Google listening in to your room shows importance of privacy defense in depth

#116
post #115

Earlier quoted context omitted.

> all android phones have that issue Citation needed. "Ok Google" functionality is an expressly required opt-in. I had to go out of my way to turn it on.

google phones (nexuses) pretty much turn it on as u hit next next next on install thats actually pretty similar the chrome tvs also warn you usually - but nontech ppl dont notice. next next.

No, search recognition is not in the initial setup

Re: Google listening in to your room shows importance of privacy defense in depth

#118
post #41
post #26

Earlier quoted context omitted.

It appears that we're stuck in a tradeoff regarding software: Libre, high quality, and user friendly. Pick two.

Firefox is open, high quality and user friendly.

I'm not sure I agree any more.

The other day, on OS X, I happened to start a new copy of Firefox in an account that had parental controls enabled (such as Guest user by default). It was a real eye-opener.

Parental controls alerts anytime an https connection is initiated. Basically it was impossible to keep Firefox from immediately initiating quite a number of these. I frantically tried to uncheck all the relevant preferences I could (e.g. "Block reported web forgeries").

I failed. Firefox still insisted on phoning home (maybe I missed something?). Also, it was hard to even make progress. The parental controls popup takes focus and demands an administrator's approval to proceed. By the time I could dismiss the popup, Firefox tried to phone home again and a new popup appeared.

Sheesh.

Here are just some of the sites that Firefox immediately accesses:

   self-repair.mozilla.org
   snippets.cdn.mozilla.net
   search.yahoo.com
   location.services.mozilla.com
   www.mozilla.org
   tiles.services.mozilla.com
   safebrowsing.google.com
   aus4.mozilla.org
What I'm saying is that microphone access is just a very small portion of what's happening. Basically all these browsers are shipping vast amounts of our intimate browsing details to "the cloud".

Re: Google listening in to your room shows importance of privacy defense in depth

#119
post #63

Earlier quoted context omitted.

> Consider that you're one of the developers that wrote this feature. You try very hard to make sure your users privacy rights are respected. Surely a developer working for Google knows that user privacy is not a priority for the company?

After working there for eight years, I can confirm the contrary of this statement. Google cares very much about user privacy -- the engineers doing the work even more so. The quote from one of their SREs swearing about the Snowden revelations was drop dead true, and engineers there have been working /very/ hard to fix issues like this. Google does not operate like Apple -- there are many hands at the tiller, and the…

Google cares very much about user privacy

Google cares very much about other actors violating user privacy. Not quite the same amount of "caring" if the violations are being done by Google itself.

Re: Google listening in to your room shows importance of privacy defense in depth

#120

Earlier quoted context omitted.

Go to chrome://settings/ Uncheck: Enable "Ok Google" to start a voice search.

So I have Chrome installed (although I don't use it as my primary) and I checked... NaCl Enabled Yes Microphone Yes Audio Capture Allowed Yes In Settings my 'Ok Google' is (and was) unchecked. What gives?

"Hotword Search Enabled" is the one you are interested in.
Post reply on HN