I feel creeped out by these home listening devices and I don't own one, but don't our phones already have this capability? You can turn "Ok Google" on on an android phone. I sometimes record audio, and the mic is incredibly good. Is there a substantial difference between our phones and these devices? EDIT: Just realized the substantial difference is that Google and Amazon own all of these things. They don't control a…
Amazon device recorded private conversation, sent it out to random contact
221–230 of 734 posts
Re: Amazon device recorded private conversation, sent it out to random contact
#222Earlier quoted context omitted.
> The device did not audibly advise that it was preparing to send the recording, something it’s programmed to do. Apparently it's not programmed to do that. Unless this was a hardware glitch or cosmic-ray event.
As developers, we use 'programmed' in that manner all the time, to mean what we were trying to get it to do rather than what it actually does.
Re: Amazon device recorded private conversation, sent it out to random contact
#223I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. I have a microphone and I've been intending to get one of the open source solutions working and just tie it in to mpd, weather and a few other things. But all the processing should really be done on your own device, by hardware you own, software that's open and that you configure, and not send up to someone else's computer (ak…
You would also need to leave if they have a smartphone of any kind...
Re: Amazon device recorded private conversation, sent it out to random contact
#224> But Danielle is hoping Amazon gives her a refund for her devices, which she said their representatives have been unwilling to do. Based on Amazon's admission and apologies, I'd think they'd be willing to give a lot more than just a refund. Seems like a huge liability for them.
Unless it’s expected behavior that malfunctioned. Antecdotally I’ve found a lot of companies support have almost no leeway for appeasement if the triggering behavior is considered “expected behavior” or a bug based off of it.
In terms of the big picture, this was dumb PR wise and this story should have never happened. For less than a $1000, Amazon could have stopped the story if the PR dept were more in sync with customer service
Re: Amazon device recorded private conversation, sent it out to random contact
#225Earlier quoted context omitted.
Lots of phone can be set to not listen all the time. iPhone for instance. Yes, it’s ultimately trust in the device maker, the compiler, the chip manufacturer, etc, and those can and have been verified to some extent. But that’s not the point. A phone can listen or not, where you have no doubt with the cylinder. It’s its raison d'etre.
OK, but you used the word “tapped.” A smart speaker isn’t supposed to be tapping you any more than a phone is. In both cases, they have to be doing something more than they’re supposed to.
And people know this. It’s not like they are being misled. It’s a conscious exchange of privacy for convinence. It’s just that, in my mind, you are getting very little for what you’re giving.
Re: Amazon device recorded private conversation, sent it out to random contact
#226Earlier quoted context omitted.
If this was intentional, then yes they shouldn't be able to deflect responsibility. However, if it was just a bug, I think it is a bit unfair to vilify either the company or the developers. Bugs happen, and hopefully they can learn what caused this and prevent this class of bugs in the future.
And this is where "software" diverges from "engineering". Bugs happen in architecture, aircraft, etc. too. the difference is that the actual engineers are paid to have a precautionary approach and spend significant resources to actively prevent bugs from making it into the final product. In contrast, software is often written to "ship first", be "agile", and "move fast and break things". Yet when it causes problems,…
Well, yes and no. Bugs, security, reliability, etc are all important things to consider, but they can't be the only focus. Security doesn't matter if the thing you are creating has no features; it would be the same as if it didn't exist at all.
Instead, we must manage risk; the risk of bugs, the risk of security vulnerabilities, etc. Nothing we do is risk free. Even walking across the bathroom floor has SOME risk; we might slip and fall. Does that mean we should just stay in bed all day to avoid any risk?
No, we measure risk by factoring the chance of the bad thing happening and the consequence of the bad thing happening. We then determine how much effort we should spend on that risk, since there are infinite risks and only a finite amount of effort we can expend.
If the consequence of a risk is death, then we should absolutely put a lot of effort into minimizing that risk. If the consequence of a risk is that a private conversation is sent to a contact, we should definitely put a lot of effort into minimizing that risk, but probably not quite as much as you would into something that has the consequence of death.
Even when the risk is death, however, we don't put infinite effort into avoiding it. We choose to cross the street, even when we know there is a risk of death when we do it. We drive cars that have chances of mechanical failures that could cause our death, but we don't bring the car to the shop every day to check for failures.
Things are not so black and white as to say "security is always the most important thing"
Re: Amazon device recorded private conversation, sent it out to random contact
#227Summary of vague technical details (which may be all we hear about this): > an Alexa engineer investigated ... they said 'our engineers went through your logs, and they saw exactly what you told us, they saw exactly what you said happened, and we're sorry.' He apologized like 15 times in a matter of 30 minutes and he said we really appreciate you bringing this to our attention, this is something we need to fix!" > th…
Re: Amazon device recorded private conversation, sent it out to random contact
#228I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. I have a microphone and I've been intending to get one of the open source solutions working and just tie it in to mpd, weather and a few other things. But all the processing should really be done on your own device, by hardware you own, software that's open and that you configure, and not send up to someone else's computer (ak…
> I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. Do you have an Apple or Google device near you right now? Does it have a microphone, battery power, and a connection to the internet? What about your roommate? Do you ever have sensitive conversations near these devices? Of course I'm not suggesting you should abandon such technology. I'm just wondering why you draw the line…
I carry a smartphone, but I keep voice-command activation turned off. I'm sure it could be activated remotely, but I expect that would require a targeted effort. I assume that Google isn't constantly recording everything in the vicinity of all Android phones - the news would probably get out, and honestly I'd see the battery impact pretty quickly.
As the saying goes, "Quantity has a quality all its own". My basic objection is to systems that are likely to store/upload all available data, with the attendant risks of leakage or commercialization I object to. Anything I say around my phone is potentially forfeit, but I don't think everything is.
Re: Amazon device recorded private conversation, sent it out to random contact
#229Earlier quoted context omitted.
How did we do it before? I can't even imagine. /s
Are you arguing that we should just stop creating anything new, since we clearly survived before without it? This comment could literally apply to ANY new thing.
Re: Amazon device recorded private conversation, sent it out to random contact
#230I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. I have a microphone and I've been intending to get one of the open source solutions working and just tie it in to mpd, weather and a few other things. But all the processing should really be done on your own device, by hardware you own, software that's open and that you configure, and not send up to someone else's computer (ak…
> I've told my roommate I'm moving out if he ever buys an Alex/Google/Apple assistant device. Do you have an Apple or Google device near you right now? Does it have a microphone, battery power, and a connection to the internet? What about your roommate? Do you ever have sensitive conversations near these devices? Of course I'm not suggesting you should abandon such technology. I'm just wondering why you draw the line…
There’s a big difference between:
- Devices which are by design always actively listening and sending real-time audio to computers you can’t control or even really trust, with unknown security properties, and consumer-appliance security life-cycles/support
- Devices that can be configured to do that, but which you have some control over (phones, laptops, etc.) and generally won’t, without some form of consent (even if via a dark pattern, e.g. LinkedIn on Android).