Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

291–300 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#291

Earlier quoted context omitted.

Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network. Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, gi…

I'm quite confident Amazon has remote root on every Echo device. It's called a firmware update.

True enough. They could easily push a new update that would record every single thing you say, and despite not indicating anywhere on the device, it would take a matter of minutes before it was in the news because what they certainly can't do is hide network traffic.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#292

Earlier quoted context omitted.

Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network. Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, gi…

As indicated in your previous comments, e.g. https://news.ycombinator.com/item?id=18616219 , you work for Amazon. It would be a better look if you disclosed this openly when commenting about Amazon.

It's easily located in my post history, however, I don't work with anything even remotely related to the Echo devices. My interest in this discussion is as a user, not as an employee.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#293

Earlier quoted context omitted.

I'm quite confident Amazon has remote root on every Echo device. It's called a firmware update.

True enough. They could easily push a new update that would record every single thing you say, and despite not indicating anywhere on the device, it would take a matter of minutes before it was in the news because what they certainly can't do is hide network traffic.

Right, the bigger concern for me is targeted attacks. One user, especially a non-technical user, getting a "special" update pushed out.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#294
post #86

Earlier quoted context omitted.

Explain how this is an improvement?

Mostly what supermatt said -- this is a lot simpler. Particularly, it's been a long time since I looked, but when I last looked neither Google nor Amazon were offering the voice assistants in nice package where you could bring your own hardware but use their APIs. So beyond the hardware, the project would've also involved building my own voice assistant software as well. Both of those ecosystems have evolved alot so…

Look again:

https://developers.google.com/assistant/sdk/guides/library/p...

https://developer.amazon.com/docs/alexa-voice-service/set-up...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#295

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

Nice summary. For those who believe that one of these companies might (intentionally or accidentally) "flip the switch", would a project like this really do that much to persuade you that the device had now become safe for use? Or would you simply avoid knowingly purchasing any such devices? (In that sense I'm struggling to understand the true customer for a neat hack like this.)

That's a good point. If you can already translate words you could implement some of the basic features like search on the same device.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#296

Earlier quoted context omitted.

And it beeps, and the audio from the other end starts coming through the echo's speaker. There is just about no way to know someone dropped in on you.

But is this behaviour implemented in hardware or software?

My understanding is that the light at the very least was hardware. Sound can be disabled.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#297
post #54

Earlier quoted context omitted.

And I have a feeling many people who make a privacy case against Echo/Home forget that their phone does the same thing.

My phone is in my pocket, which signficantly degrades the audio quality of any recordings. Same reason I have a cover over my laptop camera, but not over my phone camera.

I've made several audio recordings with my phone in my pocket. Unless you're very consistent with the pocket and placement of your phone, that isn't a significant mitigation.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#298
post #281

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?

I picked up a google home a week ago. I pretty much use it as a glorified alarm clock, and I love it.

I was running into issues with my phone’s alarm not being loud enough (either off or in a pocket, wrong room, etc) — with the Home, its always there.

The other ‘smart’ features are handy, but I’m not using those very much. When the price is right I will get some lights, though.

Does everybody need one of these? No. Is it any better than a phone? Yes, only because it’s exactly where I want it at all times.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#299

I get that this is an art project, but I think it would be more effective as a privacy device if it inserted a switch inline with the microphone, doing away with the "white noise" entirely. :)

Are you implying that turning off the mic stops it from listening? If they're gonna steal your data they're gonna do it properly

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#300
post #281

This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…

I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?

There's a huge problem with a phone, that's not a factor in stationary home appliances. The home slaves have unlimited power compared to phones. If my phone starts recording everything I'll notice because the battery life will get crushed. There's no such issue with an echo.
Post reply on HN