Live data from Hacker News

Project Alias hacks Amazon Echo and Google Home to protect privacy

fastcompany.com

71–80 of 301 posts

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#71
post #42

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

Groundhog Day on Hacker News 2 years and running: https://h4labs.wordpress.com/2017/09/27/groundhog-day-amazon... No one cares if you don’t want to use it. No one needs to justify why they want to use one to you.

Some may see smart devices as part of a greater cultural movement, in which corporations entice individuals to trade privacy for convenience

Someone who thinks these things are a gimmick, and a harmful gimmick at that, is right to express an opinion about the value these devices add. The same way I'd encourage a friend to quit chain smoking tobacco cigarettes, and not visit his house with my family if it were full of secondhand smoke.

Relevant xkcd: https://xkcd.com/1807/

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#72
post #67
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

It's an open source project. There's no company to trust.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#73
post #36

Earlier quoted context omitted.

The microphone on the Alexa needs to be constantly active so that it can hear its name (the trigger name). The point of this device is to defeat the microphone, by playing white noise. But yes this device does not address what data is captured after you have engaged your smart assistant (nor is trying to address that issue)

The processing for the wake word is handling on the firmware. If you point Wireshark (or another network monitor) at a Google Home or Alexa device you can see that there isn't significant network activity while idle.

If they (the smart assistant makers) would promote the fact that their devices only go online after the trigger word is detected that would go far is assuaging people's fear of the always-on microphone

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#74
post #67
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

Actually, it doubles your area of risk. Now you have 2 companies to worry about per device.

What, you think the rasberry pie is a internet connected listening device too? Why did you connect it to ethernet then?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#75
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

> How do you know? And, how do you know they will not do this silently in the future?

Because it's a literal hardware limitation. The device is built in a way that requires a wake word before any recording can possibly happen, thanks to it being built with 2 separate control boards. If they ended up maybe changing the wakeword to "the", then maybe they could "silently" listen to everything, but that would be caught pretty quick because the device would be "lit up" constantly (another _hardware_ thing), or someone would notice that it no longer responds to "Alexa" or "Google".

Seriously, a lot of people on HN need to do their damn homework about these devices before declaring them to be something they have been proven not to be. Packet sniffing and hardware inspection both instantly disprove all these conspiracy-theory nonsense claims that these devices are recording your every word.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#76
post #19

So doesn't Alexa already not record until you say the trigger word? If we don't trust that that is the case, then sure this device covers that, but it doesn't change the fact that they are still collecting data on every command you issue to the device.

True, but hopefully that's banal things like "play Despacito" or "What's 2 + 2", not "Please add 'rending me in the gobberwarts with a blurglecruncheon' to my depraved kinks list" or "Set my root password to 'secret123'" or "How do I build a nuke in my basement off of stuff I can order from Amazon".

Whenever I find a stray Alexa or Google home at a friend's place I ask it how to import cocaine or where I can buy uranium.

So far nothing's happened...

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#78

You could also just not buy one of those awful things. I have never seen a legitimate use for it that wasn't misplaced adolescent tech fantasies (omg I can tell big brother to make coffee and my keurig starts up!). But maybe my line of business has made me excessively paranoid / niche I would like to make an edit: functionality for those with disabilities is a huge use-case I did not consider. Thank you for your insi…

I have four. I like being able to ask a question while I'm still typing away. I like being able to turn on my TV and change the volume without having to find a remote control that is always somehow somewhere it shouldn't be. I like being able to turn off every light in the house and the iron by just saying "alexa, turn off everything" as I head out the door. My son loves being able to turn off the lights in his room and start a playlist to help him go to sleep with "alexa, good night". I love being able to start any playlist from anywhere in the house without touching any buttons, or turning the lights on or off when my hands are full without putting things down. Or asking for the time. Or when the next bus leaves the nearest bus stop.

Any one of those things are just a tiny little convenience, but it adds up, and while I bought one just to see what they'd be like not expecting to use it that much, I now use them dozens of times a day.

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#79
post #55

While I appreciate the sentiment...unless you actually think Google and Amazon devices are recording irrelevant ambient sound deliberately (they aren’t), this doesn’t help anything. Unless the software here is better than theirs at recognizing the trigger word (very unlikely), there will be even more false positive activations on this device than there are on the originals. Edit: It’s very unlikely because Amazon and…

> (they aren’t) How do you know? And, how do you know they will not do this silently in the future? Also worse detection does not mean more false positives. Usually, you can get the false positive rate very low by allowing more false negatives. In this way you have a choice, how you want to trade-off. Without this device, you are stuck with the choice that Amazon/Google make for you.

>How do you know?

Because that would be pointless. The real problem right now is false triggering. If you’re actually worried about being spied on, why on earth would you have one of these in the first place?

Re: Project Alias hacks Amazon Echo and Google Home to protect privacy

#80
post #42

Earlier quoted context omitted.

Groundhog Day on Hacker News 2 years and running: https://h4labs.wordpress.com/2017/09/27/groundhog-day-amazon... No one cares if you don’t want to use it. No one needs to justify why they want to use one to you.

Some may see smart devices as part of a greater cultural movement, in which corporations entice individuals to trade privacy for convenience Someone who thinks these things are a gimmick, and a harmful gimmick at that, is right to express an opinion about the value these devices add. The same way I'd encourage a friend to quit chain smoking tobacco cigarettes, and not visit his house with my family if it were full of…

So, you’d tell your chain smoking friend to quit smoking every time he lit a cigarette?

At some point, I would think he would say it’s none of your business.

Post reply on HN