Live data from Hacker News

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

threatpost.com

171–180 of 424 posts

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#171
post #31

Earlier quoted context omitted.

Why are you baffled? They’re great little devices. I have two Amazon echoes. Now that I can use my Apple Music, they are used constantly. Voice-first devices are long overdue.

This is just my opinion, based on my experience and personality. Voice first running entirely on prem with no internet connectivity, sure I would go for that. Talking to the internet? No way. Not even if I had root on the device with the source code to the OS, firmware and applications.

> Talking to the internet? No way. Not even if I had root on the device with the source code to the OS, firmware and applications.

Can you explain how this is different from running your linux computer with a webcam attached?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#172
post #114

Earlier quoted context omitted.

>I am baffled by how many people have no problems adding always listening and recording Google and Facebook devices to their living rooms. I am baffled by people that think anyone cares about their conversation about Jeff at work or what Monica and Ross just did on the 75th viewing of an episode of friends, or that they talk to their stuffed rabbit named Bun that they've had since about a week after they were born ab…

I am baffled that people like yourself are not concerned in the least. I grew up in an Eastern Europe Communist State where this kind of personal surveillance was the norm. People went and wrote down all their interactions with others. You can see these documents now as the former secret police archives were published (what wasn't destroyed to protect the higher ups). It's amazing how the most innocuous remarks can b…

Because your phone, or computer, or tablet can record your voice and far worse.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#173
post #93

Earlier quoted context omitted.

Using a reward card and taking FB quizzes are active decisions. Being surreptitiously recorded is not.

Well, they made an active decision to buy a device specifically meant to record them and provide responses to said recording. It would be another thing to find out a phone records every conversation passively, but these devices are literally made for the purposes of recording you. That kind of sounds like a self inflicted wound if they actually cared about privacy. This is all said with the presumption that the devic…

OK, by your definition of "recording", a laptop contains several I/O devices that "record" my input, not just webcam and microphone, but keyboard as well. I guess I should just shrug at the revelation that it comes with a keylogger. Because hey, if I didn't want my written thoughts to be recorded, why did I buy a memory-enabled Internet-connected device to do actually that?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#174
post #77

Earlier quoted context omitted.

Which nobody can do. It is encrypted and unless the device accept invalid certs, they can queue up, compress, batch upload any data they want. They control the security, not the end-luser.

We know how much storage is on the device - we could tell thru network monitoring if they were actually doing this - there is just enough smarts in the device to only turn on the recordings when the wake word is spoken - thats not being said a malicious player wouldnt hack it, and insert their own code to listen all the time - but based on the evidence, I don't think amazon is that player.

[deleted]

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#175
post #94

Earlier quoted context omitted.

This is exactly why we are building the first 100% on-device and private-by-design open-source Voice AI at https://snips.ai (and we have cloud-matching performances: https://medium.com/snips-ai/snips-brings-cloud-level-spoken-... ) Disclaimer: I'm a co-founder We believe that people want more natural interaction and AI at home, but that it should never be at the cost of their privacy. You never know what a company, o…

Completely OT, but is the woman supposed to look that goofy/deformed? https://imgur.com/a/DFgvNMt

Clearly the illustrator determined her head should be placed on backwards.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#176
post #118

Earlier quoted context omitted.

“Amazon seems to actually care about privacy “ Not according to the NY Times this week. Amazon have been reading your private messages on Facebook. https://www.nytimes.com/2018/12/18/technology/facebook-priva...

You might want to read the article again. No part of it says that Amazon read private messages on Facebook.

Yeah, AFAIK it was login-with-facebook partners like Spotify. Were people ever able to login to Amazon with facebook?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#177
post #24
post #15

Earlier quoted context omitted.

I don’t know why this is getting downvoted. I feel the same way. Amazon and Google have yet to demonstrate to me that they value my privacy enough to take necessary steps to protect it. They, like Facebook, know most people foolishly don’t care enough to hold these companies feet to the fire on it. At the risk of stating the obvious; Facebook has more than demonstrated the opposite.

The only company I've seen take demonstrable action to protect their customer's privacy is Apple. Google, Facebook, Microsoft, Amazon have never given me a single reason to trust that they have my privacy concerns on their mind.

>The only company I've seen take demonstrable action to protect their customer's privacy is Apple.

The same Apple that gave the Chinese government access to all their Chinese user's iCloud data?

https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#178
post #96

Earlier quoted context omitted.

What evidence or steps would be sufficient for you?

Not parent, but I'll answer. 1) The implementation of the wake word recognition is implemented in hardware that cannot be updated remotely. 2) The device is unable to transmit information without lighting up a TX light. Implemented in unmodifiable hardware. 3) Voice recordings are processed and then deleted within one month. 4) The device is run by a company that doesn't make money through marketing or data analysis.

1 means it's impossible to offer better voice recognition accuracy or change the wake word, meaning they get pilloried by reviewers for offering a device that's strictly worse than the current gen, and they get pilloried by HN for contributing to tech waste.

1&2 get the company pilloried by HN the moment a vulnerability comes out.

3 is a requirement that doesn't actually solve any problems and ruins a legitimate need of ML - comparing performance against a known baseline.

4 is overbroad - most software companies make their money through data analysis of one form or another.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#179
I'm a generally happy Echo owner but am getting increasingly worried these mistakes are only going to ramp up, especially with the new Drop In feature, allowing users to enable the microphone on any Echo -- not limited to their own -- given the appropriate permissions are in place. (It's not clear if these are enforced at all on-device or simply cloud-based permissions.)

[1] https://www.amazon.com/gp/help/customer/display.html?nodeId=...

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#180

Earlier quoted context omitted.

Point 1: Keyword triggers and is actually said are miles apart, as shown by the Alexa creepy laugh episode. There is no practical way of knowing when Alexa has heard a keyword and recorded content around it. Not to mention the Google play incident where a poor wiring job made the devices think the "enable assistant" button was constantly being pressed. Point 2: My phone, an iPhone, offers a way to turn off the keywor…

> There is no practical way of knowing when Alexa has heard a keyword and recorded content around it. I know this isn't the kind of certainty you're looking for, but Google Home and Alexa both allow you to enable audio cues for when they start and stop recording. I find this helpful from an accessibility perspective, but the privacy-conscious may also appreciate the indicator.

They also have visual cues enabled by default. The light turns on when it is listening. You quickly get an idea of when it is recording and when it is not. And it rarely falsely triggers.
Post reply on HN