Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

131–140 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#131

Earlier quoted context omitted.

How about the issue where Google’s devices were errantly recording everything due to a hardware issue - where the button override for the voice activation was stuck in the activated position. People who think that there’s no way that Google and Amazon could be recording everything need to realize that this is also not true. Most of these “limitations” are software enforced, and that software is updated constantly.

This is the main problem that I see. Sure, I tested the packets, sniffed them, made sure it wasn't recording, etc, but then they push an update the next day. I don't think it's practical to monitor these devices all the time, and I haven't been asked to opt-in to an Echo update. I also don't necessarily assume mal-intent on the part of the companies, but that doesn't mean there won't _ever_ be that intent. Trusting t…

> Trusting that all of these assumptions hold over time is hard.

This is the big point. You are not only trusting that the company as it is today is doing the right thing, but that the company will continue to do the right thing for so long as the device is in your house - and that they will do the right thing in perpetuity with your data (including if/when they sell the company down the road).

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#132
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission...

The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that, but also thousands of other tech/adops employees who'd have to be like, "yea this is a great idea."

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#133
post #89

Earlier quoted context omitted.

I too grew up in the time of card catalogs. And I learned a lot from reading through the other encyclopedia entries as I flipped the pages looking for the page with the info. Yes, you're right, the voice interface is not the astronomical leap that the cellphone was. But why is that your cutoff line? My voice assistants offer a lot of benefit to me. Especially with kids, I don't always have a free hand to pull out the…

My personal experience is that simply typing my query into a search engine or pressing the spotify logo to start my music requires less effort or fuss than attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want. IE, using voice commands is a downgrade IMO. Voice commands are not directly discoverable, and there's a lot more magic boxes.

I do find using voice commands a downgrade when it comes to interaction speed. I find it incredibly annoying to talk to alexa as it doesn't seem to match my dialog speed. Then, I find myself standing their waiting for it to shut up thinking, 'I could have done this faster myself'

Also, an interaction I had last week:

add x to my shopping list.

ok, I will add x to my shopping list, anything else?

. . .

But I can't add a list, add pears, apples, and oatmeal to my shopping list.

So If I have raw chicken on my hands and want to add shit to my list, it takes so god damn long that I want to punch the fucking thing.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#134

Earlier quoted context omitted.

How about the issue where Google’s devices were errantly recording everything due to a hardware issue - where the button override for the voice activation was stuck in the activated position. People who think that there’s no way that Google and Amazon could be recording everything need to realize that this is also not true. Most of these “limitations” are software enforced, and that software is updated constantly.

This is the main problem that I see. Sure, I tested the packets, sniffed them, made sure it wasn't recording, etc, but then they push an update the next day. I don't think it's practical to monitor these devices all the time, and I haven't been asked to opt-in to an Echo update. I also don't necessarily assume mal-intent on the part of the companies, but that doesn't mean there won't _ever_ be that intent. Trusting t…

> This is the main problem that I see. Sure, I tested the packets, sniffed them, made sure it wasn't recording, etc, but then they push an update the next day. I don't think it's practical to monitor these devices all the time, and I haven't been asked to opt-in to an Echo update.

This is a problem with forced updates in general (I'm also thinking of Windows, Chrome, Chrome extensions, etc. here) that security experts seem completely blind to.

That said, note that even if the software didn't update, it doesn't mean it would have to send bad packets when you're actually observing. It could randomly start doing that once in a while after a few months.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#135

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

Your smartphone is also always listening. What's the difference?

I don't use a smartphone

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#136
post #95

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

My dad just had some major health issues, and has a much harder time getting around the house. He finds these things pretty useful to save him some trips around the house.

That is a good point, I had not considered that use case.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#137
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

"Allow Google Maps to always access your location. Yes. Ask Me Later".

Given the multiple precedents on the erosion of privacy path in the past 20 years, of which I quoted one example above, it's pretty obvious that they will turn "always on listening" in the future, using whatever dark patterns necessary to avoid a class action suit.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#138

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

I just kinda doubt this. How much backlash was there when it came out that the NSA was recording the full content of every cell phone call in the Bahamas?

Edit: codename SOMALGET, subproject of MYSTIC. https://en.wikipedia.org/wiki/MYSTIC_(surveillance_program)#...

http://www.documentcloud.org/documents/1164088-somalget.html

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#139
post #138

Earlier quoted context omitted.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

I just kinda doubt this. How much backlash was there when it came out that the NSA was recording the full content of every cell phone call in the Bahamas? Edit: codename SOMALGET, subproject of MYSTIC. https://en.wikipedia.org/wiki/MYSTIC_(surveillance_program)#... http://www.documentcloud.org/documents/1164088-somalget.html

> was recording the full content of every cell phone call in the Bahamas?

The what now?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#140
post #30

Earlier quoted context omitted.

Involves more trust. This has the elegance of not needing to trust the megacorps any more than you care to.

How does this involve more trust? With either Alias, or an homebrew solution you're sending the query portion ("How many teaspoons are in a tablespoon?") to the megacorp?

Whoops didn't see this part, yeah you're right!

>hardware device (eg Raspberry Pi) that listens for a wake up then sends to the API?

Post reply on HN