Earlier quoted context omitted.
Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network. Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, gi…
I'm quite confident Amazon has remote root on every Echo device. It's called a firmware update.
Project Alias hacks Amazon Echo and Google Home to protect privacy
291–300 of 301 posts
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#292Earlier quoted context omitted.
Nobody has EVER gotten root console access on an Echo device remotely, and the only successful "remote" exploit that didn't require soldering requires that the attacker and the victim are both on the same wifi network. Please, feel free to explain how Amazon and Google could exploit that vulnerability (that has since been patched)? More importantly, I'd love to hear how they are going to pull this off and hide it, gi…
As indicated in your previous comments, e.g. https://news.ycombinator.com/item?id=18616219 , you work for Amazon. It would be a better look if you disclosed this openly when commenting about Amazon.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#293Earlier quoted context omitted.
I'm quite confident Amazon has remote root on every Echo device. It's called a firmware update.
True enough. They could easily push a new update that would record every single thing you say, and despite not indicating anywhere on the device, it would take a matter of minutes before it was in the news because what they certainly can't do is hide network traffic.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#294Earlier quoted context omitted.
Explain how this is an improvement?
Mostly what supermatt said -- this is a lot simpler. Particularly, it's been a long time since I looked, but when I last looked neither Google nor Amazon were offering the voice assistants in nice package where you could bring your own hardware but use their APIs. So beyond the hardware, the project would've also involved building my own voice assistant software as well. Both of those ecosystems have evolved alot so…
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#295This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…
Nice summary. For those who believe that one of these companies might (intentionally or accidentally) "flip the switch", would a project like this really do that much to persuade you that the device had now become safe for use? Or would you simply avoid knowingly purchasing any such devices? (In that sense I'm struggling to understand the true customer for a neat hack like this.)
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#296Earlier quoted context omitted.
And it beeps, and the audio from the other end starts coming through the echo's speaker. There is just about no way to know someone dropped in on you.
But is this behaviour implemented in hardware or software?
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#297Earlier quoted context omitted.
And I have a feeling many people who make a privacy case against Echo/Home forget that their phone does the same thing.
My phone is in my pocket, which signficantly degrades the audio quality of any recordings. Same reason I have a cover over my laptop camera, but not over my phone camera.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#298This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…
I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?
I was running into issues with my phone’s alarm not being loud enough (either off or in a pocket, wrong room, etc) — with the Home, its always there.
The other ‘smart’ features are handy, but I’m not using those very much. When the price is right I will get some lights, though.
Does everybody need one of these? No. Is it any better than a phone? Yes, only because it’s exactly where I want it at all times.
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#299I get that this is an art project, but I think it would be more effective as a privacy device if it inserted a switch inline with the microphone, doing away with the "white noise" entirely. :)
Re: Project Alias hacks Amazon Echo and Google Home to protect privacy
#300This thread has gotten long, so here's a summary: - There is not evidence that these devices record and transmit without an activation word triggering this behavior - However, there is nothing to stop companies from breaking this assumption - Some people think the risk of one of these companies flipping a switch and recording everything is negligible - Some people think the risk of one of these companies flipping a s…
I still don't get why a stationary assistant would be less trustworthy than a handheld phone. Shouldn't both devices be equally suspect?