Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

221–230 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#221
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> It’s very unlikely because Amazon and Google pay for false positives, so they have a strong incentive to develop really good trigger word detection.

There's a feature in my Pixel to show what song is playing --like in the real world-- on the lock screen. A kind of always-on Shazam.

They don't mind paying for always on.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#222
post #221
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> It’s very unlikely because Amazon and Google pay for false positives, so they have a strong incentive to develop really good trigger word detection. There's a feature in my Pixel to show what song is playing --like in the real world-- on the lock screen. A kind of always-on Shazam. They don't mind paying for always on.

That's fully on-device though, it keeps a database of the top songs fingerprints and doesn't use the network to recognize songs

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#223
post #221
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> It’s very unlikely because Amazon and Google pay for false positives, so they have a strong incentive to develop really good trigger word detection. There's a feature in my Pixel to show what song is playing --like in the real world-- on the lock screen. A kind of always-on Shazam. They don't mind paying for always on.

"Now Playing" is an offline feature

https://venturebeat.com/2017/10/19/how-googles-pixel-2-now-p...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#224
post #221
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> It’s very unlikely because Amazon and Google pay for false positives, so they have a strong incentive to develop really good trigger word detection. There's a feature in my Pixel to show what song is playing --like in the real world-- on the lock screen. A kind of always-on Shazam. They don't mind paying for always on.

[deleted]

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#225
post #116
post #72

Earlier quoted context omitted.

It's an open source project. There's no company to trust.

Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

> Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

I trust that amongst thousands of people with different incentives at least one will raise their voice if something is not right. At least more so than I trust a corporation with, in this case, the the wrong incentives to self-regulate to my expectations.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#226
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Who cares. Whoever buys the hardware can do whatever they want with it. If someone feels better with this device on their Google / Alexa product let them do it. If the speech recognition is horrible I’m sure they’ll take it off.

+1 to who cares.

> If the speech recognition is horrible I’m sure they’ll take it off.

This is interesting and cool, cause it sounds to me like they only detect for the keyword to "unlock" the Google home, so in theory they don't even need speech recognition. In most cases, they could just do with telling if a sound you make seems to match the sound you defined to be their name ¯\_(ツ)_/¯

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#227
post #189
post #179

Earlier quoted context omitted.

Nothing is 100% guaranteed, but with an open source project, given enough users, its far less likely for someone to be able to bury nefarious stuff without many eyes looking at it and at least one person sounding an alert.

Yeah but really this isn't true. Popular open source that has tens of thousands of eyes on it still gets compromised all the time (see: npm). Even the Linux kernel has had rogue git commits injected into it.

> the Linux kernel has had rogue git commits injected into it

What? Who "injected" what and when?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#228
post #221

Earlier quoted context omitted.

> It’s very unlikely because Amazon and Google pay for false positives, so they have a strong incentive to develop really good trigger word detection. There's a feature in my Pixel to show what song is playing --like in the real world-- on the lock screen. A kind of always-on Shazam. They don't mind paying for always on.

"Now Playing" is an offline feature https://venturebeat.com/2017/10/19/how-googles-pixel-2-now-p...

Go figure, I stand corrected.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#229

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Because it's a literal hardware limitation.

Unless there is a separate out of band board with a relay I can hear or see (meaning, code alone can't enable something), then it really isn't a hardware limitation. The security controls and operations are in the code. The code can change or may already have silent monitoring capabilities. Nobody on HN could really answer whether or not this is the case. All we can do is speculate. If someone were required to put lawful monitoring code in place, they would not be allowed to discuss it here. The best anyone could do is decompile the code or get the source code for the firmware. Even then, there could be non-volital space that allows for updates.

Case in point, there have been malware packages that could enable your microphone and camera on the laptop without turning on the LED. This varied with camera model. Some power the LED when the camera has power. Microphones don't always activate an LED. There are a myriad of articles you can find providing examples of malware that can listen to cell phone microphones, laptop microphones without activating the LED.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#230

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

I get that you believe this, and I even understand you repeating it to other people on the Internet. What I don't get is that your tone indicates that you are offended people don't believe what you believe... which also just happens to have been incorrect in the past and many others seem to think is provably possible in the future.
Post reply on HN