Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

271–280 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#271
post #189

Earlier quoted context omitted.

Yeah but really this isn't true. Popular open source that has tens of thousands of eyes on it still gets compromised all the time (see: npm). Even the Linux kernel has had rogue git commits injected into it.

> the Linux kernel has had rogue git commits injected into it What? Who "injected" what and when?

I'm also interested to know more about this.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#272
post #96

I call it Misplaced Distrust. Every cellphone in the world has a microphone that could be listening all the time and sending data anywhere. So does most every computer. It's a better threat vector by 1000x, more stealthy, easier to conceal traffic. But all anyone ever talks about is a device designed to listen to you talk because hey, so obvious, big brother MUST be listening in there!

You have a point, but what makes you believe that such things are not happening for some people? Do you have any proof that the low power microphone is not recording voice all the time?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#273

Earlier quoted context omitted.

> To suggest that a serial root console is a point of attack for an Echo device is bordering on insanity. That was not what he said. He argues that Amazon/Google could remotely use a similar exploit (without direct access to the hardware) to start recording without lighting up the LED.

Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network. Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, gi…

As indicated in your previous comments, e.g. https://news.ycombinator.com/item?id=18616219 , you work for Amazon. It would be a better look if you disclosed this openly when commenting about Amazon.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#274
post #188

Earlier quoted context omitted.

Do you think being an open source project makes it more secure somehow? It doesn't.

This is code you can inspect running on hardware that you own and control. It's trivial to ensure it's secure at that point. Unlike when it belongs to a company.

I'm tired of explaining why this isn't a valid argument for security. Being able to compile your code means _nothing_.

As is tradition, just read "reflections on trusting trust":

https://www.archive.ece.cmu.edu/~ganger/712.fall02/papers/p7...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#275
post #96

I call it Misplaced Distrust. Every cellphone in the world has a microphone that could be listening all the time and sending data anywhere. So does most every computer. It's a better threat vector by 1000x, more stealthy, easier to conceal traffic. But all anyone ever talks about is a device designed to listen to you talk because hey, so obvious, big brother MUST be listening in there!

Cell phones have batteries, so it would be even less practical for phones to be "phoning home" a stream of what's going on around it at all times than a "smart speaker".

How about your computer?

Here’s a parallel construct: It would be trivial for Microsoft to have a key logger in Windows that sent every keystroke to Redmond.

Why does anyone trust that they are not doing it?

Indeed, they could scan your computer for whatever data they like and send it to Redmond. But no one even suspects it, or at least at nowhere near the level people seem to distrust Amazon and Google over sending your voice to them full-time.

This is what I mean by Misplaced Distrust. We already trust Google and Amazon with far more of our personal data without a thought.

But a microphone? Ooh, scary!

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#276
today I learned that rain forest fungi hack an ants brain and cause the ant to spread the fungus further on. We live in a wonderous world.

Here it says the fungus is pulling this trick only on its favorite ant species, amazing:

https://www.livescience.com/47751-zombie-fungus-picky-about-... https://www.sciencedaily.com/releases/2014/08/140825142124.h...

Wikipedia has a list of mind altering parasites; it turns out that this not a unique hack. https://en.wikipedia.org/wiki/Category:Mind-altering_parasit...

Scary stuff, don't read HN past bedtime! It's probably more tricky to pull of this trick with complicated brains, but who really knows how we tick and who is running us.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#277
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Edit: It’s very unlikely because Amazon and Google pay for false positives, so they have a strong incentive to develop really good trigger word detection.

If the false positives give them data that increases the value of your marketing profile by more than the cost of processing the interactions then they actively profit from false positives, and have no reason at all to stop them.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#278

Earlier quoted context omitted.

> How do you know? And, how do you know they will not do this silently in the future? Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught p…

> If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught pretty quick because the device would be "lit up" constantly (another _hardware_ thing) From pure technical perspective, can the device not be programmed to be waked by wakewaord “the” with the light off?

> "can the device not be programmed to be waked by wakewaord “the” with the light off?"

It absolutely can be.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#279
post #138

Earlier quoted context omitted.

I just kinda doubt this. How much backlash was there when it came out that the NSA was recording the full content of every cell phone call in the Bahamas? Edit: codename SOMALGET, subproject of MYSTIC. https://en.wikipedia.org/wiki/MYSTIC_(surveillance_program)#... http://www.documentcloud.org/documents/1164088-somalget.html

Why would there be? The Bahamas is not inside the United States and thus is part of the NSA's mission of monitoring foreign communications. Spy agencies spy. It's their job description.

[deleted]
Post reply on HN