Live data from Hacker News

Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

threatpost.com

401–410 of 424 posts

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#402
post #159

Didn't Amazon tell it's customers, that Alexa constantly records locally, but only sends the words after the "Alexa" magic, including 6 seconds before and 6 seconds after it, to the servers?

There is nothing in this article that disproves that; and it likely would be featuring prominently if it were more. Also, it seems quite silly for Amazon to lie about this if it could be disproved with a GDPR request. The mistake that was made here is that the wrong customer's data was sent in a GDPR request.

You are right. But I remember, that I had read a similar story, a week, or two, ago and the topic was, that the police found out about the killer in a murder case, by listening to Echo recordings from the kitchen. I doubt, that this would be possible, if there is no constant stream of data on Amazon's servers.

That gave me the impression, that they store it all. At least for a while.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#403
post #207

Earlier quoted context omitted.

There's a big difference: having a GPS in my phone means I never have to worry about buying or carrying a map with me ever again, at the cost of potentially revealing my location to someone who I'd rather not know it. Having a voice assistant means I don't have to spend a few seconds typing, at the cost of having everything I say potentially overheard by someone who I'd rather didn't hear it. By my quality metric, th…

As others have said here, you're overplaying one and underplaying the other: 1. having a map on your phone doesn't necessitate gps; only automatically locating yourself on that map does, which is an added convenience as opposed to the core functionality. 2. even the core functionality of a map—navigation—is a rarer one than the plethora of things one can connect voice control to 3. apart from taxi integration, probab…

> find restaurants near me

How does that help me at home? I don't dispute the value of voice recognition on a phone. But we're talking about smart speakers here, in your home, always on.

(BTW, on a phone I can set up common queries like "find restaurants near me" as shortcuts and access them with a single touch.)

> gps represents a bigger value add relative to the trade-off

Yep. Also, I can easily turn my GPS off, restrict apps from accessing it, etc. Home smart speakers are necessarily always on.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#404
post #271

Earlier quoted context omitted.

The primary purpose of an Efho device is not to record you. You brought up a silly argument.

It has 7 microphones and its only purpose is to record you, then respond to your request. That's literally the only thing the device is made to do.

And a laptop has a keyboard and memory to explicitly record what you write. That doesn't make installing a keylogger the same thing.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#405
post #252

Earlier quoted context omitted.

Compare the workflows for leaving a reminder or note. Before: * Find phone/computer * Unlock * Locate self in interface and navigate to application selector * Invoke note-taking or reminder app * Type in note or reminder * Navigate through tagging/scheduling interface * Commit note/reminder Or: * Locate notebook * Locate writing utensil * Open notebook to current page * Write note * Remember to check notebook every t…

If it worked, yes, absolutely. On my Android phone, however, the note-taking process is as follows: "OK Google!" wait 5-10 seconds for the assistant to chime. It might work if I don't wait, but mostly doesn't. Sometimes it doesn't wake up at all. "take a note" wait for the assistant to ask what the note is "Remember to put your shoes on!" Check whether the note was taken correctly Also, if I was actually using the ph…

That's a bit odd. What version of Android are you on, does it have any of those junk manufacturer skins, and how old is the phone? If my phone is already unlocked I can spout off the hotword, invocation, and content in a single stream, the assistant pops up in an overlay and prints the note for me to check visually, and then it finishes and hides with no further intervention. Pixel 2 XL, fully patched, it's worked like that since I got the phone.

If you're having trouble with getting the assistant to wake up, and you don't see an improvement after running through the wizard you get when you say "retrain voice model" or "recognize my voice", you should also be able to get the assistant up by long-pressing the middle button in the navbar at the bottom. You additionally shouldn't need to wait for a response after saying "take a note", just dump it all in a single breath.

> when it occurred to me I should remember to put my shoes on

...Are you mocking me? I thought I'd made it pretty clear that I used that tools to help compensate for a memory problem that does, in fact, qualify as a disability. Try "okay Google, remind me at eight pm to reply to $friend about $thing". Or "okay Google, remind me every day at two in the afternoon to make a dentist appointment...".

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#406

Earlier quoted context omitted.

First, having talked a lot to people who actually lived under a somewhat oppressive government (USSR, and by the 80s it wasn't even that oppressive), most people _did_ in fact have something to hide. Second, just because it doesn't describe your government now doesn't mean it won't in the future, unfortunately. Consider examples of a 1920s German, or a 1960s Iranian (the old regime was oppressive too, but in differen…

> Second, just because it doesn't describe your government now doesn't mean it won't in the future, unfortunately. Consider examples of a 1920s German, or a 1960s Iranian (the old regime was oppressive too, but in different ways), or a 2000s citizen of Poland. This is the risk averse argument against certain technologies. If you believe your government won’t change and are willing to take that bet, you can lean into…

As I said above everyone can make this decision for themselves, and should. It's just important to me to not paint any of the decisions here as "only criminals would do that"! Past that, I figure adults can and should decide these things for themselves.

That said, I also think we should work toward changing the nature of the tradeoff, e.g. by changing how voice assistants work to minimize the privacy issues. I suspect there's a lot of work we could do on that front while not compromising the functionality of the voice assistants.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#407

Earlier quoted context omitted.

Just so I'm clear here, you're proposing a conspiracy theory where Amazon, the DHS, and The Pentagon are in collusion to collect and transcribe audio from Amazon Echos -- in such a way that none of the many people who have hacked and extensively reverse-engineered them would be able to tell? I can't find any holes in that theory.

The people who have "hacked and reverse engineered" the Echos don't have access to what happens on the server side. We are facing a situation of either trusting or not trusting, because verification isn't possible. There should be a word for believing that someone is working for your interests even though you have no reason to, as a counterpart to "conspiracy theory" which implies that you believe that a group is wor…

I think the most relevant term to this discussion is Hitchens's razor.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#408

Earlier quoted context omitted.

> Talking to the internet? No way. Not even if I had root on the device with the source code to the OS, firmware and applications. Can you explain how this is different from running your linux computer with a webcam attached?

I don't leave a webcam attached, or a microphone. I can also debug any code running on my machines and have some idea of what they are doing. I can also limit when they are allowed to talk to the internet and to what address.

> Not even if I had root on the device with the source code to the OS, firmware and applications.

Can't you debug code and control network access in that scenario?

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#409
post #24

Earlier quoted context omitted.

The only company I've seen take demonstrable action to protect their customer's privacy is Apple. Google, Facebook, Microsoft, Amazon have never given me a single reason to trust that they have my privacy concerns on their mind.

>The only company I've seen take demonstrable action to protect their customer's privacy is Apple. The same Apple that gave the Chinese government access to all their Chinese user's iCloud data? https://techcrunch.com/2018/07/17/apples-icloud-user-data-in...

Is there anything Apple could have done to protect the privacy of its Chinese users better (whilst still having some)? You could say they shouldn't have Chinese users, but that's a different argument, I believe.

Re: Amazon Sends 1,700 Alexa Voice Recordings to a Random Person

#410
post #250

Earlier quoted context omitted.

If we are playing the "you can't prove that" game, then you also can't prove that your $12 throw away phone isn't always recording, or that you new kitchen countertop doesn't have a recording device embedded in it, or that the maker of whatever device you are using to type that comment isn't breaking a plethora of laws to record everything you type or say or do around that device at any time.

At least you can pull the battery out of most "burner" tier dumbphones.

My battery falls out if I stare at the phone for too long. This works on goats, too.
Post reply on HN