Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

181–190 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#181
post #73

Earlier quoted context omitted.

The processing for the wake word is handling on the firmware. If you point Wireshark (or another network monitor) at a Google Home or Alexa device you can see that there isn't significant network activity while idle.

If they (the smart assistant makers) would promote the fact that their devices only go online after the trigger word is detected that would go far is assuaging people's fear of the always-on microphone

Can they change the trigger word, eg if they get instructed via a national security letter?

Whilst offline, is it possible for the device to store audio?

Is all writable storage auditable by users?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#182
post #145

Earlier quoted context omitted.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

Surely somebody in the '90s said something similar with regard to location data, and yet your location is tracked 24/7 by adtech megacorps, and the thousands of tech/adops employees don't say a peep. The playbook has 3 easy steps: 1. Get people addicted to technology X. 2. Keep bugging people using technology X to surrender their privacy using classical dark patterns. 3. Profit! There is no need for whistleblowers. I…

That’s my big concern with this tech, training people to have always-on surveillance in their homes without a second thought. I realize that the typical and trite response by some involves throwing away my phone, but there are holes in that. First, it is trivially easy to control where your phone is, you can get burners, root your phone, and all of the other good things we know and love.

An Echo, or similar dross is a closed box controlled OTA, and networked. Even if someone had immense faith in company X, it would be unwise to ignore intelligence and law enforcement both foreign and domestic wanting access. You can’t root Alexa, it won’t even work without the cloud. It really does feel like training wheels for something entirely unpleasant, and all because people are so helpless in the face of dubious convenience and fashion.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#183
post #138

Earlier quoted context omitted.

I just kinda doubt this. How much backlash was there when it came out that the NSA was recording the full content of every cell phone call in the Bahamas? Edit: codename SOMALGET, subproject of MYSTIC. https://en.wikipedia.org/wiki/MYSTIC_(surveillance_program)#... http://www.documentcloud.org/documents/1164088-somalget.html

> was recording the full content of every cell phone call in the Bahamas? The what now?

I didn't realise this either but it looks pretty widely known: https://theintercept.com/2014/05/19/data-pirates-caribbean-n...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#184

Earlier quoted context omitted.

How about the issue where Google’s devices were errantly recording everything due to a hardware issue - where the button override for the voice activation was stuck in the activated position. People who think that there’s no way that Google and Amazon could be recording everything need to realize that this is also not true. Most of these “limitations” are software enforced, and that software is updated constantly.

This is the main problem that I see. Sure, I tested the packets, sniffed them, made sure it wasn't recording, etc, but then they push an update the next day. I don't think it's practical to monitor these devices all the time, and I haven't been asked to opt-in to an Echo update. I also don't necessarily assume mal-intent on the part of the companies, but that doesn't mean there won't _ever_ be that intent. Trusting t…

"Malintent" can be a hard bar to clear, but it's clear beyond a shadow of a doubt that these companies view these devices as mechanisms to push forward their own interests and desires, in addition to my own. I won't even necessarily call that morally wrong, or at least, that line is very fuzzy. But it does mean that viewing them with a certain amount of suspicion is just rational, not crazytalk.

(It's true of cell phones too, of course, and I am engaged in constant activity to ensure the phone works for me, and not any of the many corporations that want to make it work for them. Turning off notifications, uninstalling certain apps after they've gone bad, ensuring permissions aren't too wide open, uninstalling default-installed apps and disabling others... it's a constant battle made worthwhile only by the fact that in the end, I really have mostly mastered my phone and it is working for me. I don't have one of these audio assistants because it is far less clear to me how to do that. Modulo being spied on by intelligence agencies, anyhow, although at this point I'm not sure how one could even escape that.)

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#185

Earlier quoted context omitted.

And so something like that can never happen again? Regressions are a very real thing, both in hardware and software.

I'm not sure how you would regress a button that physically doesn't exist anymore. Also, if you're that scared of future bugs that don't exist, then you should probably throw away your smart phone.

The entire top surface of the Google Home is a button (capacitive). Those kinds of sensors are just as susceptible to physical defects as mechanical buttons.

As a side note, whataboutism adds nothing of value to this discussion about the Google Home and Amazon Echo.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#186

Earlier quoted context omitted.

My personal experience is that simply typing my query into a search engine or pressing the spotify logo to start my music requires less effort or fuss than attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want. IE, using voice commands is a downgrade IMO. Voice commands are not directly discoverable, and there's a lot more magic boxes.

I do find using voice commands a downgrade when it comes to interaction speed. I find it incredibly annoying to talk to alexa as it doesn't seem to match my dialog speed. Then, I find myself standing their waiting for it to shut up thinking, 'I could have done this faster myself' Also, an interaction I had last week: add x to my shopping list. ok, I will add x to my shopping list, anything else? . . . But I can't add…

I don't have an echo but there was a post on HN[0] not long ago that linked to an article[1] about how Alexa is able to add multiple items to your shopping list at once, and how it understands what is what. So in theory you shouldn't be running in to the problem you're describing. Not every time at least.

[0] https://news.ycombinator.com/item?id=18706651

[1] https://developer.amazon.com/blogs/alexa/post/36ca7d4c-cd98-...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#187
post #38

Earlier quoted context omitted.

Do you have kids? I have three small ones, and they are just starting to desire technology. From my perspective, letting them control music (which they want, and I want them to have) is much better using a Google Home device than giving them access to my phone or tablet. If you don't have kids, you have no idea how loud and aggressively they will scream when they want something, and especially when these devices are…

If your kids are screaming loudly and aggressively about things they want, you have a problem that technology will not solve.

No. You just have kids. The rest of what you said is incidental.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#188
post #72
post #67

Earlier quoted context omitted.

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

It's an open source project. There's no company to trust.

Do you think being an open source project makes it more secure somehow? It doesn't.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#189
post #179
post #116

Earlier quoted context omitted.

Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

Nothing is 100% guaranteed, but with an open source project, given enough users, its far less likely for someone to be able to bury nefarious stuff without many eyes looking at it and at least one person sounding an alert.

Yeah but really this isn't true. Popular open source that has tens of thousands of eyes on it still gets compromised all the time (see: npm). Even the Linux kernel has had rogue git commits injected into it.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#190
post #119
post #38

Earlier quoted context omitted.

Do you have kids? I have three small ones, and they are just starting to desire technology. From my perspective, letting them control music (which they want, and I want them to have) is much better using a Google Home device than giving them access to my phone or tablet. If you don't have kids, you have no idea how loud and aggressively they will scream when they want something, and especially when these devices are…

It's not a devil's bargain, you have lost the ability to bargain. It's a common theme with parents these days. There is nothing magical about technology, it's just an application of age-old parenting principles. And there's nothing particularly harmful about technology either, there should be no grand battle: you define the limits and the children should stick to them and respect you as a parent. This is true for all…

You are wrong. With kids, you are dealing with micro bargaining every moment. It's what kids do to learn.

Do you have kids, or did you read this somewhere?

What age old parenting techniques are you talking about? The ones older people reminisce about when they lament how bad young people are today? Do you have a source backing up the efficacy of those "proven" techniques?

Post reply on HN