Earlier quoted context omitted.
So, you’d tell your chain smoking friend to quit smoking every time he lit a cigarette? At some point, I would think he would say it’s none of your business.
Peer pressure is the main reason I quit smoking. So yes-- if not every time, then at least regularly and consistently. When technology starts to look like a recreational drug, treat it like a recreational drug.
Project Alias hacks Amazon Echo and Google Home to protect privacy
161–170 of 301 posts
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#162So doesn't Alexa already not record until you say the trigger word? If we don't trust that that is the case, then sure this device covers that, but it doesn't change the fact that they are still collecting data on every command you issue to the device.
https://www.telegraph.co.uk/technology/2018/08/14/hackers-fi...
https://www.wired.com/2017/05/hundreds-apps-can-listen-beaco...
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#163You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…
Do you have kids? I have three small ones, and they are just starting to desire technology. From my perspective, letting them control music (which they want, and I want them to have) is much better using a Google Home device than giving them access to my phone or tablet. If you don't have kids, you have no idea how loud and aggressively they will scream when they want something, and especially when these devices are…
I'm shocked: Why does your two year old need to know Google as a brand? How or why is this valuable to you? Do you expect Google to exist forever? Its entire revenue model is built on ads. Companies with more robust revenue streams have gone bankrupt in shorter timeframes.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#164Earlier quoted context omitted.
> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.
> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…
This is a very technically naive interpretation of their hardware/software solution.
If the wake word were hard-coded into silicon then perhaps I would be charitable about your misunderstanding(s) - but of course it is not. The wake word is user-definable and can be changed to arbitrary sounds at any time.
Whatever hardware limitation(s) may exist are trivially worked around with software, which can be updated over the top of you at any time.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#165Earlier quoted context omitted.
> Packet sniffing and hardware inspection both instantly disprove... I'm under the impression that packet sniffing is useless with end-to-end encryption, but I could be wrong. I.e., you can tell that something is being sent, but you can't know what.
The theory is that we can still estimate how much data goes over the network. So if it were sending all audio to the cloud, we'd see. It does however not exclude other information, like sending keyword flags, or storing audio fragments to send along with other messages later on.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#166Earlier quoted context omitted.
> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…
> Packet sniffing and hardware inspection both instantly disprove... I'm under the impression that packet sniffing is useless with end-to-end encryption, but I could be wrong. I.e., you can tell that something is being sent, but you can't know what.
If they can't see all of the traffic, but just know where the traffic is going, then I don't think they did their homework.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#167Earlier quoted context omitted.
> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.
> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…
Take note that Amazon Drop In [1] is a feature built around turning on the Echo mic remotely without a wake word. I don't think this feature could exist if there was a hardware limitation.
[1] https://www.amazon.com/gp/help/customer/display.html?nodeId=...
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#168Earlier quoted context omitted.
Over a year ago Google removed the part of the hardware that caused that bug on the Home mini: https://www.theverge.com/circuitbreaker/2017/10/11/16462572/...
And so something like that can never happen again? Regressions are a very real thing, both in hardware and software.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#169Earlier quoted context omitted.
> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.
Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…
1) whistleblowing unlikely because any employee that steps out of line can and will be destroyed 2) any media fuss will blow over in a few days 3) promotions and bonuses require outsize risks
I think everyone has a point in their career when they realise large tech companies are unaccountable before the law. Mine was watching the MERS database running roughshod over American property ownership laws.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#170You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…
Your smartphone is also always listening. What's the difference?
In the iOS ecosystem, Siri can be set up to only listen in response to a button-press (don't remember which is default), and the watch only listens on wrist-raise. Those at least creates some physical barrier to passive listening, even if it requires a certain degree of trust in the devices.