Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

191–200 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#191

Earlier quoted context omitted.

I'm not sure how you would regress a button that physically doesn't exist anymore. Also, if you're that scared of future bugs that don't exist, then you should probably throw away your smart phone.

The entire top surface of the Google Home is a button (capacitive). Those kinds of sensors are just as susceptible to physical defects as mechanical buttons. As a side note, whataboutism adds nothing of value to this discussion about the Google Home and Amazon Echo.

And the capacitive button doesn't trigger the listening hardware. Splitting hairs over the hardware specifications isn't proof that the bug is still a problem.

Also, talking about your contradictory behavior with your smartphone isn't whataboutism, unless you want to avoid addressing your hypocrisy, because smart phones are susceptible to the same blanket fears you have with homes/alexa. To critique only the latter, and not the former (which you use daily), is not fair.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#192

Earlier quoted context omitted.

My personal experience is that simply typing my query into a search engine or pressing the spotify logo to start my music requires less effort or fuss than attempting to figure out how I'm supposed to word my desire for the benevolent overseer to do what I want. IE, using voice commands is a downgrade IMO. Voice commands are not directly discoverable, and there's a lot more magic boxes.

I control my lights by saying “all lights red” and “dim all lights to 20%” Compare this to the number of taps required to do so in the hue app

I recently found out about the iOS widget that the Hue app provides. It's basically a single swipe+tap for me now, even if my phone is locked.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#193
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

The point is establishing as much trust as you can with your devices. Only having external points of trust when absolutely necessary. This is generally a Good Thing, and something we should do by default, not as a reaction to some corporate leak.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#194

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen [...] Take note that Amazon Drop In [1] is a feature built around turning on the Echo mic remotely without a wake word. I don't think this feature could exist if there was a hardware limitation. [1] https://www.amazon.com/gp/help/customer/display.html?nodeId=...

But doesn't the device light up when that happens?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#195
post #38

Earlier quoted context omitted.

Do you have kids? I have three small ones, and they are just starting to desire technology. From my perspective, letting them control music (which they want, and I want them to have) is much better using a Google Home device than giving them access to my phone or tablet. If you don't have kids, you have no idea how loud and aggressively they will scream when they want something, and especially when these devices are…

An aggressive screaming kid needs a timeout at the very least, followed by a progressive loss of privileges (toys) until the tantrum subsides. A few cycles is enough to amend even the most recalcitrant. I'm shocked: Why does your two year old need to know Google as a brand? How or why is this valuable to you? Do you expect Google to exist forever? Its entire revenue model is built on ads. Companies with more robust r…

Are you sure that gets what you want? Our desires for my kids might be different. Sounds like you think kids should be punished until they learn who is the boss. I'm not sure you have read all the literature on the effectiveness of that strategy.

I never said I want my two year old to know the Google brand. She hears her older siblings saying it. It is just what is so with her. But guess what? I'm willing to wager my kids aren't the only ones who learned things from their siblings that their parents don't want them to know about, at least at that moment. My kids are not playing with Barbies and I'm pretty sure body image issues with girls are much worse than exposure to Daniel Tiger.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#196
post #116
post #72

Earlier quoted context omitted.

It's an open source project. There's no company to trust.

Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

Users without skills can still hire a developer of their choice to do the verification, if they're really paranoid.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#197
post #64

Earlier quoted context omitted.

I like to be able to play music, ask simple questions, etc. without pulling out my phone. I don't understand why those aren't "legitimate" use cases. Maybe you don't like the tradeoff you're making in using such a device, but if I'm fine with it, how are my uses cases not legitimate?

Yeah, I got one for Christmas a couple of years ago; thought it would be really gimmicky, but I find it's actually quite a lot nicer to use than my phone or other devices for the following: * Turning on/off lights * Changing the thermostat set temp * Asking about the weather forecast * Add items to a shopping list * Playing music If you can't imagine a voice interface being appreciably better than a phone interface f…

It's also worth noting that you don't always have to do it with voice either. If I'm on the couch with my phone, I might use it to update my shopping list, whereas if I'm in the kitchen cooking, I'll use voice. Similarly, if I just want random music, I will say "play music", but if I want a specific album, I might use my phone, especially if it has a complicated name that I don't remember.

Obviously not every action is easier or more optimal by voice, but having the option is great.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#198

Earlier quoted context omitted.

> Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen [...] Take note that Amazon Drop In [1] is a feature built around turning on the Echo mic remotely without a wake word. I don't think this feature could exist if there was a hardware limitation. [1] https://www.amazon.com/gp/help/customer/display.html?nodeId=...

But doesn't the device light up when that happens?

I was just offering a counter to the hardware limitation claim. It's possible the device makes itself known during use, I haven't used this feature yet.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#199
post #73

Earlier quoted context omitted.

If they (the smart assistant makers) would promote the fact that their devices only go online after the trigger word is detected that would go far is assuaging people's fear of the always-on microphone

They have. The reality is that conspiracy theorists aren't interested in learning how things actually work, which is why they're conspiracy theorists. In reality your phone is a significantly bigger threat to privacy both in terms of normal day to day monitoring (e.g. location tracking) and even listening in (a closed source baseband that can communicate on a platform you cannot even monitor).

Most people don't learn how things work, they learn to believe in authority telling them how things work.

Conspiracy theorists have less faith in authority figures, which is why they're conspiracy theorists.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#200
post #37

Earlier quoted context omitted.

That is correct! Google, Amazon, and Apple despite having vast resources don't have the ability/desire to pay for the bandwidth, storage, and processing needed to have 24/7 recording and analysis from every smart device, especially when you realize that includes cell phones. Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in…

Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in the same way Actually, they are. The majority of "ordinary" people I interact with believe Facebook is listening to their conversations 24/7. It's been brought up multiple times on HN.

>The majority of "ordinary" people I interact with believe Facebook is listening to their conversations 24/7. It's been brought up multiple times on HN.

I see this a bunch when people say, they talked about an item with someone then google showed them an ad. Sure, perhaps all that data is being processed, but more likely, it's predictive and they know who in your social circle knows about this item. Your friend read a story about it, searched for it on amazon.

People are still in this mode where they don't realize how much info leaks without capturing any conversation, and how good prediction is/can be at this point. So the only explanation is that we're being spied on all the time because I don't think people can wrap their minds around prediction models that are this good.

There are stories from 10 years ago of advertising agencies knowing that someone is pregnant before they did and ten years later, the general public assumes they have to have the original thought first so FAAMG knows what to sell them.

Post reply on HN