Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

251–260 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#251

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Packet sniffing and hardware inspection both instantly disprove... I'm under the impression that packet sniffing is useless with end-to-end encryption, but I could be wrong. I.e., you can tell that something is being sent, but you can't know what.

You own the client. You can do anything to it. There is no way for encryption on the client to prevent you from inspecting the content.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#252
post #87
post #16

Earlier quoted context omitted.

I'm wondering this too. Like hey, let's install some under developed AI from some unknown company with unknown security policies on top of a device with access to hordes of personal data and the ability to make transactions online. No hacker will EVER think to use it as an attack vector /s

I didn't look into Alias deeply, but does it even have network access at all? I don't see a reason it would have to.

It needs it for setup (so you can set up the wake word using your phone), but then after that it can be disconnected.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#253

This may be an interesting addition to some home assistant developed using https://www.home-assistant.io/ That is, use Google Home/Alexa/Apple Home for their speech recognition abilities while ensuring it doesn't eavesdrop and works with any other smart device that you have (e.g. there is no way to directly control Nest using Apple Home).

There's really no need for that. Google at least has a speech recognition API that you could send audio to directly; no need to use a Google Home as a middleman if that's all you want.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#254

I bet Echo and Home could be reprogrammed by Amazon/Google to listen all the time, learn what the Alias trigger word is, and speak/replay that word for the Alias shell whenever they feel like.

That's not how this works. Alias plays white noise into the Home/Echo speaker so it can't hear what's going on, unless you first speak the Alias' wake word, which causes it to activate the Home/Echo and allow speech through.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#255
post #225
post #116

Earlier quoted context omitted.

Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead.

> Users without the skills to verify the code isn't nefarious have to trust good samaritan developers instead. I trust that amongst thousands of people with different incentives at least one will raise their voice if something is not right. At least more so than I trust a corporation with, in this case, the the wrong incentives to self-regulate to my expectations.

I've always wondered how much OS code gets audited or if everyone just assumes someone else will do it (bystander effect)

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#256

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

There is hard evidence [1][2] you can remotely operate Echo recording capabilities without a wake word. Hope this puts the 'hardware limitation' claim to bed.

[1] https://news.ycombinator.com/item?id=18905161

[2] https://m.youtube.com/watch?feature=youtu.be&v=Mme9d-ojpNo

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#257
post #76

Earlier quoted context omitted.

True, but hopefully that's banal things like "play Despacito" or "What's 2 + 2", not "Please add 'rending me in the gobberwarts with a blurglecruncheon' to my depraved kinks list" or "Set my root password to 'secret123'" or "How do I build a nuke in my basement off of stuff I can order from Amazon".

Whenever I find a stray Alexa or Google home at a friend's place I ask it how to import cocaine or where I can buy uranium. So far nothing's happened...

You can by uranium from Amazon [1].

[1] https://www.amazon.com/Images-SI-Uranium-Ore/dp/B000796XXM

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#258

Earlier quoted context omitted.

But doesn't the device light up when that happens?

And it beeps, and the audio from the other end starts coming through the echo's speaker. There is just about no way to know someone dropped in on you.

But is this behaviour implemented in hardware or software?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#259

Earlier quoted context omitted.

You are making an enormous amount of assumptions based on a semantic argument. Echo devices only begin recording if they think they hear the wake word. Obviously this is less than straight-forward, hence the recordings that didn't follow the wake word (just examples of an Alexa device incorrectly thinking it heard it). To suggest that a serial root console is a point of attack for an Echo device is bordering on insan…

> To suggest that a serial root console is a point of attack for an Echo device is bordering on insanity. That was not what he said. He argues that Amazon/Google could remotely use a similar exploit (without direct access to the hardware) to start recording without lighting up the LED.

Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network.

Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, given network traffic will be a dead give away?

If what your suggesting is actually what he meant, that's even more absurd than attackers trying to do the same.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#260
post #187

Earlier quoted context omitted.

No. You just have kids. The rest of what you said is incidental.

I have two kids, 9 and 11, and neither of them are screaming and yelling about what music to play. If they want to listen to music, they know to go to the rumpus room and pick out a vinyl.

I love that you provided your kids with a time machine to play with.
Post reply on HN