Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

231–240 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#231
post #37
post #19

So doesn't Alexa already not record until you say the trigger word? If we don't trust that that is the case, then sure this device covers that, but it doesn't change the fact that they are still collecting data on every command you issue to the device.

That is correct! Google, Amazon, and Apple despite having vast resources don't have the ability/desire to pay for the bandwidth, storage, and processing needed to have 24/7 recording and analysis from every smart device, especially when you realize that includes cell phones. Also it is ironic because all modern cellphones have the whole smart speaker thing built into them but people aren't freaking out about that in…

My experience with pocket dialing and speakerphone calls leads me to believe my phone is a much less capable listening device. Many people still have phones where constant listening would supposedly drain the battery.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#232
post #67
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

It doesn't have to connect to the internet to do what it does. The scenario you seem to be suggesting is that the Project Alias developers would be conspiring with Google by compromising Project Alias to NOT disrupt Google's listening and then Google would be listening in on you using their network access. This by definition does not double the area of risk.

If you can be confident that Project Alias does not have network access, then the worst possible scenario, even if the developers are literally Satan, is that Google Home would be doing exactly what it does without Project Alias attached.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#233

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

Not that this helps anyone sleep easier, but imagine in today's age... a whistleblower -- perhaps one of the thousands of software devs working on one of these -- leaked proof that these devices are recording everything to re-market and profit, without permission... The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it. It wouldn't just take an insane and stupid CEO to do that,…

> The resulting backlash and legal ramifications would be so huge it just wouldn't be worth it.

Everything can be explained away with "we discovered a bug that might cause your unit to record you constantly, but it's fixed now. Won't happen again, sorry!"

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#234

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

Those two separate control boards didn't stop my Amazon dot from acually recording ambient noise and uploading it to Amazon's systems. I know this because of the audio history they themselves provide! You can literally go back and play back all the audio recorded, and a great deal of it did not include questions. Further, there was also a report of being able to trigger audio recording without either activating the L…

You are making an enormous amount of assumptions based on a semantic argument.

Echo devices only begin recording if they think they hear the wake word. Obviously this is less than straight-forward, hence the recordings that didn't follow the wake word (just examples of an Alexa device incorrectly thinking it heard it).

To suggest that a serial root console is a point of attack for an Echo device is bordering on insanity. You'd need a breakout board connected via the USB interface (not port, mind you) in order for this work-around to be effective. So yes, if a hacker had physical access to your device, time enough to solder on a breakout board, said third-party could record a variety of things.

But then, it's a whole hell of a lot easier to just install a mic in someones house and get the same effect, now wouldn't it?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#235

Earlier quoted context omitted.

Why is this downvoted? Peer pressure is by and large the best way to curb thoughts and actions that are harmful to individuals and society. The current echo chamber on the net filled with alternative/radical theories is the outcome of insufficient peer pressure. Nutbars always existed in real-life too, society was just better at keeping them from doing too much harm.

Those of us who are nutbars hate society for forcing us to conform. Given that a lot of us are more tech-savvy than society, we love that we tend to be able to work around its restrictions. Also, obligatory http://www.paulgraham.com/say.html

I think it's dangerous to conflate freedom of speech with moral relativism. Freedom to speak does not suddenly make morally wrong actions right. Ex: murder, slavery, forcible confinement, poor treatment of women and children, and so on.

I realize we are quibbling the definition of "nutbar", but my line is drawn at the extreme end, not the moderate end. It's one thing to advocate Haskell as the perfect language for building an OS (crazy talk, but I support it) and quite another to advocate violent uprising against minorities in society (a la StormFront). I hope we can agree that there's a distinction at play here.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#236
post #96

I call it Misplaced Distrust. Every cellphone in the world has a microphone that could be listening all the time and sending data anywhere. So does most every computer. It's a better threat vector by 1000x, more stealthy, easier to conceal traffic. But all anyone ever talks about is a device designed to listen to you talk because hey, so obvious, big brother MUST be listening in there!

Cell phones have batteries, so it would be even less practical for phones to be "phoning home" a stream of what's going on around it at all times than a "smart speaker".

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#237
post #54

Earlier quoted context omitted.

If you don't trust these devices, you probably wouldn't trust your phone either.

And I have a feeling many people who make a privacy case against Echo/Home forget that their phone does the same thing.

My phone is in my pocket, which signficantly degrades the audio quality of any recordings. Same reason I have a cover over my laptop camera, but not over my phone camera.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#238

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Seriously, a lot of people on HN need to do their damn homework about these devices before declaring them to be something they have been proven not to be.

Based on what? Marketing copy? Eyeballing iFixit teardowns?

> but that would be caught pretty quick because the device would be "lit up" constantly (another _hardware_ thing)

Totally not buying it, unless you can show me the traces and discrete components that force power through the LED when signal from the microphone is allowed to reach the uC. If it's done in software, I'm not trusting it.

If you're making an argument of "trust the vendor because economics", you have to recognize how weak it is.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#239
post #204

Earlier quoted context omitted.

How so? Ultimately the mic is always on and listening for its keywords - if you look at the teardown of the Alexa on iFixIt, I don't even see any device other than the main CPU that would be capable of performing keyword recognition. Meaning the main CPU would have to be the thing then controlling the lights after the keywords are recognized... The Google Home at least has a separate board with a microcontroller on i…

Not a hardware guy, but couldn’t you tie the LEDs to whatever bus that connects the mic and the main CPU?

Yes, I don't mean to say it's impossible - just that you'd need an entirely isolated system to detect when data was flowing over that link which is physically connected in all cases and cannot be updated. I don't believe we see that in either the Alexa or Google Home, but I'd be happy to be mistaken if anyone's done a more in depth teardown of these systems.

And all of this is hinged on hoping you notice LEDs firing in the corner while you're having a conversation. Perhaps a more noticeable method should be used in cases like this. A forced "beep"/tone or something from an isolated circuit hardwired to the speakers.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#240
This thread has gotten long, so here's a summary:

- There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a switch and recording everything is warrants serious concern - These two groups will not agree, and that's fine :)

Post reply on HN