Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

261–270 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#261

Earlier quoted context omitted.

> To suggest that a serial root console is a point of attack for an Echo device is bordering on insanity. That was not what he said. He argues that Amazon/Google could remotely use a similar exploit (without direct access to the hardware) to start recording without lighting up the LED.

Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network. Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, gi…

I'm quite confident Amazon has remote root on every Echo device. It's called a firmware update.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#262

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> Because it's a literal hardware limitation.

Citation needed. Further, listening for a wake word and reacting to that is likely done completely in software: the fact it's even listening for a "wake word" means the hardware (microphone) is in fact always listening, it's just [presumably] not actually sending that audio to The Cloud (tm).

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#263

Earlier quoted context omitted.

Good point if I set up the Pi myself, but it's unclear if this will apply to the device if it gets produced commercially.

Even if it gets produced commercially, no network access means no problem.

In the “let’s go down the what could be done” path...

No network accesss doesn’t mean no access to the outside world. “Alexa, tell some tracker that ...” when you are asleep. And how many people audit their past activations on the Alexa app?

No, I don’t believe this would be the case... I have half a dozen Alexa devices of various builds, a google home (that is currently powered off) and some iDevices plugged in for hey Siri in different rooms.

The thing I was trying to point out though is that no network access is not no outside world access for this device. And if one is paranoid enough to desire this device, then the device itself should be worried about.

And yes, with the right software, it could be reprogrammed via voice too. “Alexa, read some reprogramming site”.

The only acceptable solution is to make it yourself and audit the code yourself if you are concerned enough to desire it in the first place.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#264

Earlier quoted context omitted.

And it beeps, and the audio from the other end starts coming through the echo's speaker. There is just about no way to know someone dropped in on you.

But is this behaviour implemented in hardware or software?

This feature is configured via its software.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#265
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Afaik by now, there have been least two court cases where Echo recordings were handed over as evidence [0] [1].

At this rate, it's only a matter of time before evidence like that gets leaked/released, which would serve as a good probe on how much these devices really record.

[0] https://techcrunch.com/2018/11/14/amazon-echo-recordings-jud...

[1] https://edition.cnn.com/2017/03/07/tech/amazon-echo-alexa-be...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#266

Earlier quoted context omitted.

Cell phones have batteries, so it would be even less practical for phones to be "phoning home" a stream of what's going on around it at all times than a "smart speaker".

And metered data. I would be very aware if my phone was eating my data plan via constantly recording audio. Even a measly 12kbps audio stream adds up to nearly 4GB/mo if recording 24hrs/day. Non-techie users would absolutely notice that their data and battery is being used up in the background pretty quickly. Further, the cell networks simply could not support that kind of usage from every single subscriber at the sa…

Your phone could easily wait until it's on wifi to upload 24hrs worthy of ambient voice data (which is only trigged by voice activation, so not a full 24hrs)...

The feds have been using cellphones as full-bore wiretaps since the early 2000s when they used it on mobster's "dumbphones". I'm sure they've figured out clever exfiltration techniques on smartphones by now.

Especially considering how willing the ISPs/telecom companies are to bend over backwards to hide surveillance. Even 3g/4g wiretapping is probably feasible.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#267
post #189
post #179

Earlier quoted context omitted.

Nothing is 100% guaranteed, but with an open source project, given enough users, its far less likely for someone to be able to bury nefarious stuff without many eyes looking at it and at least one person sounding an alert.

Yeah but really this isn't true. Popular open source that has tens of thousands of eyes on it still gets compromised all the time (see: npm). Even the Linux kernel has had rogue git commits injected into it.

The probem with npm isn't that open source doesn't help, its that the eyes get spread out thin when you have thousands of modules - so nobody is looking at the changes that happen in their lots of small dependencies.

Which is not to say that thats not a valid approach - but for it to work we need better tools to handle lots of git repos at once (for example, the ability to get notified about any new code on github that affects your project would be pretty cool, especially if its coming from people or organisations you haven't explicitly marked as trusted yet)

I would like to see someone try and sneak rogue commits into Linux. It would be quite the feat.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#268
post #145

Earlier quoted context omitted.

Surely somebody in the '90s said something similar with regard to location data, and yet your location is tracked 24/7 by adtech megacorps, and the thousands of tech/adops employees don't say a peep. The playbook has 3 easy steps: 1. Get people addicted to technology X. 2. Keep bugging people using technology X to surrender their privacy using classical dark patterns. 3. Profit! There is no need for whistleblowers. I…

That’s my big concern with this tech, training people to have always-on surveillance in their homes without a second thought. I realize that the typical and trite response by some involves throwing away my phone, but there are holes in that. First, it is trivially easy to control where your phone is, you can get burners, root your phone, and all of the other good things we know and love. An Echo, or similar dross is…

> training people to have always-on surveillance in their homes without a second thought

Even worse: when always-on surveillance devices become popular enough that a judge could rule that the technology (in the abstract, not a specific product) is "in general public use"[2] - crossing the bright-line rule created in Kyllo v United States[1] - the police no longe4r need a warrant to use the technology see the "details of a private home that would previously have been unknowable without physical intrusion"[3].

I'm not talking about the police being involved with Amazon or using the Echo. When a technology is "in general public use", the police can use their own always-on microphone to transmit previously-private speech to a 3rd party on the internet. Normalizing surveillance devices not harms the person using the device, it also reduces *everyone's 4th Amendment protection.

[1] https://caselaw.findlaw.com/us-supreme-court/533/27.html

[2] Used throughout the ruling[1], but especially section II of Justice Stevens' dissent.

[3] The ruling[1], 2nd paragraph

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#269

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

I'm privacy conscious and bought a couple of minis. I don't use the mics but I thought I had a legitimate use case without one. It's falling short and I'm looking around for replacement devices.

I flipped the hardware mic switch off on it, to try to make it a dumb wifi speaker instead of a "smart" one. Then I built a software alarm clock that forces me to leave the room after I wake up in order to turn it off.

For me, it's very important for my alarm clock to be both effective, and to always work. The alarm clock runs as a remote task and connects directly to the mini, telling it to play an MP3 from the local network (by IP because the mini ignores DHCP DNS server). If I hit the mini touch controls to turn it off, the software starts playing a different MP3 a second later. If I try to unplug the cable from the device, duct tape stops me. Thoughtful wrapping of the cable around a solid furniture post prevents any yanking from being effective at tearing it out of the wall. If one mini is down (fairly rare but possible point of failure), the other one is attempted.

So, it's fairly impossible for me to just turn it off without waking up and giving it a bit more thought. I have to leave the room and tap a button on a touch screen (ubuntu in kiosk mode reaching web app on local network).

The unfortunately fatal flaw is that after months of effective use, I recently discovered that my highly available alarm clock was not actually highly available. It breaks when the internet is out. I could not connect over local network. There's always the possibility that something else was a factor, but I reproduced it a couple of times intentionally.

It also concerns me that the mini doesn't require authentication. Anyone on the local network can directly reach the device and do the same thing. A script meant as an alarm clock could turn into a device of psychological torment in someone elses hands. This lack of authentication, and the ability to auto-discover the speakers, is probably something they consider a 'feature'. I don't like seeing Chrome waste system resources in its attempt to scan my local network on the off chance that Google's speakers are there. And I don't want it to reach out to those speakers when it does find them. But it does it anyway.

In the end, with the microphone disregarded, it's a cheap wifi speaker. I won't count Chrome's bad behavior against it, but its software could be improved by offering (any) secure connection options. The lack of internet as a single point of failure dooms any kind of gadgetry with a reliability requirement from using it. It can't be considered reliable enough for serious tasks like waking you up for work or a flight unless they fix the software to work in a local-network-only mode. But, it is cheap, and, well, mostly available, which is often good enough for to-hand use cases.

Speculation: Is the lack of mini's heartbeat phoning home Google's own way of determining network reliability across wide geographic areas (eg, the lack of data in an aggregate area)? But they probably know this already from the wide spread of Android devices. Or do they maybe just not want their device to work unless it can reach back to them?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#270

Earlier quoted context omitted.

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

I don't own either of them but Siri and Google on my phone both require training when I first use them. Do these devices not? IF they do then isn't that proof they are re-programmable and could be programmed to respond to anything?
Post reply on HN