Shazam Keeps Your Mac’s Microphone Always On, Even When You Turn It Off
motherboard.vice.com
motherboard.vice.com
That's not a bug. It's intentionally deceptive software.
"modifying or altering computer software and hardware to accomplish a goal that is considered to be outside of the creator's original objective"
Furthermore while set off the microphone is only doing is local pre-buffering.
How would you make "keep a microphone open for faster startup, (which is the creator's original objective)" fit into the above definition.
(which is the creator's original objective)
It's not macOS' original objective.>conceal a miniature microphone in (a room or telephone) in order to eavesdrop on or record someone's conversations secretly.
>"the telephones in the presidential palace were bugged"
Arguably it is a bug that users should know about ;) Pedantry aside, I seriously hope it's a software bug, and not an intentional wiretap bug.
Leaving aside any privacy concerns, it's reasonable that everybody with this installed loses some battery life leaving the audio hardware powered up all day on the off-chance they might want to tag a song at the very last moment at some point?
It's not like the latency to start an audio stream on the Mac is huge to start with.
On the other hand, this kind of behavior steals real resources from the system. In aggregate, apps that do this can waste noticeable battery and slow the system considerably. I don't want random apps deciding they're "important enough" to always run. It's user hostile even if it's not intended to be.
I don't have Shazam installed on my laptop and honestly can't imagine I ever will, so this is academic for me.
It would be great to have the light show for both microphone and webcam access.
The reality is you don't need everyone to audit their devices, you only need there to be credible auditors. Better: standards mandates that require isolation of any ambient capture devices.
In the alternative, the ability to flood and overload such circuits might be of interest.
I can't verify by watching the clip now, but I believe it's in this interview: https://www.youtube.com/watch?v=yq0ecBGg5Q0
How? Seriously, if you don't trust a hardware switch to work as advertised, then you probably don't trust software correctly to report the state of the hardware; so what would you trust? (I wish that I could say that I think you're being paranoid, but I don't; I just wonder what a zero- or minimal-trust proof of disconnected hardware would look like—short, presumably, of something like a visible air gap that could only be implemented at considerable expense to the portability of modern electronics.)
Physics. Their not being an unnoticed second camera/microphones/etc.
If you main concern is that your computer will be used to spy on your physical life, then having verified switches can give you confidence from first principles that it it has no way of observing you (modulo secondary sensors that you did not notice.)
Right, but this is what I meant to ask: how does one verify a switch that has been manufactured by someone else? I suppose that an electrical engineer could check the schematics, but how do you verify that the actual hardware in your device matches the schematics?
Sarcasm, I hope? I spent an hour this weekend replacing some micro switches in some decrepit robots. These are about 5mm^3, which is pretty tiny, but huge on the scale of a modern phone. They are basically hunks of plastic with a button on one side and six or so leads coming out the other side. No, you can't open them up and see the air gap without destroying them. And yes, they are small enough to easily contain a full CPU, some flash memory, and a few sensors, even though they only really need a few sliding metal and plastic bits.
I'm guessing he probably didn't buy the new iPhone 7...
The microphone is a hard one. Even if you cover the holes in the casing where the mic is located the sound still travels just fine via the keyboard.
IIRC when a photo came out of Mark Zuckerberg covering his webcam I noticed he covered his mic port with tape as well. He should have checked the volume levels from his mic - it would still pick up everything just fine. In fact I think the tiny mic holes are mostly vestigial.
Depends on the make/model of computer - current MacBooks use a lot of glue to hold components together, making minor hardware tweaks a bit of a gamble. It's not impossible, just not as hassle-free as it used to be.
> or at the OS level
If your computer has a rootkit then doing it in software is no good.
Maybe a solution would be no integrated microphone, a small low profile microphone in the laptop box to be connected through the laptop mic jack.
My PC doesn't have a mic plug and the headphone one is only out, no in. With two mics (internal and USB) I can switch among them by software. I'm pretty sure I could do that with an analogue mic.
I wonder if an app could do the same on a phone, switching from the outside dummy mic to the internal one. You'll definitely notice that if you're calling somebody, but if the app only listens when no other app is using the mic, then it's easy to record audio most of the time.
Back in the old days of 1/2" mag tape reels, the rule was "no ring, no write". There was a physical ring that needed to be present before a tape drive would write to a mag tape. This was also relatively failsafe. If the ring fell out or was removed, for any reason at all, the data was guaranteed to be safe.
This same mentality carried over to floppy disks. It was possible to protect media in hardware.
But in the interests of saving money, hardware write protect circuitry is quite passe these days. As are hardware switches of all sorts.
POSIX (and the upper, newer, layers of API) is really starting to show it's age, since it's from a time when "untrusted software" was not that much of a thing.
(sorry for the forbes link: http://www.forbes.com/sites/katherynthayer/2013/12/19/the-al... )
Unless there's a way for an app to use the microphone without that appearing?
fuser /dev/snd/*
Will list most processes using audioYesterday I wanted to Shazam the second song of an Instagram video playing on my computer. The app was open while the first song was playing and I pressed the record button as soon as the second one started playing. I was really surprised to notice that the song found by Shazam was the first one and not the second.
How much longer?
It sounds like Shazam is storing the 5 seconds buffered, ready to hash then upload when you press go
I'm not sure how you can be confident in stating that as fact. I'm not at all. In the US there are many issues with switching carriers, for one example.
You state that you're in control of the device but then say "What's to stop any other software vendor from ignoring the configuration". Ignoring what seems like a contradiction there, I think we would have different definitions for what it means to control your own device.
No affiliation other than being a satisfied user.
While I agree that you don't know that this app isn't spying on you, surely it doesn't decrease the trustworthiness of your computer? In some sense, it seems to me like centralising all your distrust in a single person: you now have only to trust the author of this piece of software, rather than of every piece of software you use.
Shazam may be looking backward in time to build its fingerprint, so it would need to buffer some audio first.
https://bugs.chromium.org/p/chromium/issues/detail?id=500922
> the mic is kept on “for technical reasons” but “no audio is processed
Beg your pardon? That's two, contradictory statements. You are either buffering the audio or not. If yes, then the "no audio is processed" is very thin truth. If not, then the only time you win it takes for the Mac to switch the mic on, surely that takes a very small fraction of a second...?
I know that Google Now, Siri, Amazon Echo, and others respond to commands like "Ok Google [...]". Those devices must necessarily be listening if they're to catch those voice commands, right? Or is there a more clever solution for recognizing predetermined phrases?
Note that Bluetooth is not an acceptable substitute.
http://images.apple.com/support/security/guides/docs/Leopard...
Hi. Are you sure about that?
Using one of the other tools mentioned here (Oversight) it looks like Microphone starts when you open Input and closes when you close Input tab. Which makes sense as you do want to see Input feedback instantly. Mac 10.11