[1] https://www.amazon.com/gp/help/customer/display.html?nodeId=... and https://www.washingtonpost.com/news/the-switch/wp/2014/11/11...
[1] https://www.amazon.com/gp/help/customer/display.html?nodeId=... and https://www.washingtonpost.com/news/the-switch/wp/2014/11/11...
The important question here is "What happens to the audio data streamed to the cloud, a few seconds AFTER the query has been identified (or not identified) and the results sent back to the Alexa device?"
The nieve assumption is "all audio data is deleted after processing". The reality is that data is still valuable to Amazon for a variety of uses such as
(1) further training their voice recognition software
(2) advertising data mining [how many people are in the room, things they are talking about --- note, Facebook's mobile app infamously does this]
If they just store the query text, that is 'best case' from a privacy perspective. If they just store query text and query audio, that is less than ideal, but not too bad. If they store all audio, ever recorded, for an indefinite period of time... that is what this police request could reveal: Audio data stored for a non-keyword-trigger, and for days/weeks after the fact.
"You can delete specific voice recordings associated with your account by going to History in Settings in the Alexa App, drilling down for a specific entry, and then tapping the delete button. Or, you can delete all voice recordings associated with your account for each of your Alexa-enabled products, by selecting the applicable product at the Manage Your Content and Devices page at www.amazon.com/mycd or contacting customer service."
It's a serious question, and one that I think Amazon (and anyone else streaming audio to the cloud, Siri and Google Voice Search are only slightly less constrained) needs to have an answer for.
It is also true that if Alexa was listening in on conversations so as to have "social conversation context" for "improved processing of commands" ... well.
I would be very surprised if Amazon sends everything up to the cloud; it would be very expensive to do so. Looking for "Alexa" in the audio is done locally, and probably triggers recording then.
As others have pointed out, network monitoring has shown the Echo only transmits after it's heard the wake-word, so it would appear Amazon doesn't capture everything.
I won't be surprised if we find out this is happening. They'll probably call it a "bug", fix it in an OTA, but then accidentally regress 6 months later.
A big part of customer obsession is not eroding the trust of customers by treating their privacy as extremely important. For example, I've never heard of an incident in the more than two decades that Amazon.com has been in business of them selling customer data to a 3rd party for marketing purposes or otherwise. They wouldn't do something that could erode customer trust, or would be anti-customer, because they are in business for the long haul. Customer trust can only be earned slowly, over time, but can evaporate instantly with one mistake.
I trust Amazon more than Google and others to protect my customer data, because they've frankly earned this trust over 20+ years.
I'd be very surprised if this is happening -- Amazon knows people are watching, and it would erode trust with customers if it's found out that they are spying.
I'd be much more concerned about whether or not my phone is spying on me, even if it says it's only listening if I say "Ok Google" or "Siri". It's much harder for me to see what traffic my phone is sending across the cellular network than to snoop Amazon Echo's wifi traffic. And phone malware (sometimes baked in by the manufacturer) is increasingly common. Since the Echo does not allow user-installed Apps, at least it's less vulnerable to malware.
Sometimes the wake-word detection is mistakenly triggered and some unrelated audio gets streamed to Amazon, but the LEDs will still light up, and at times it'll even reply to a query that was never intended (I've been watching TV when my Echo will hear something and reply that I don't have any timers set, or whatever) but these recordings would still be covered by the link I pasted in the help text above.
I think a lot of the HN paranoia about these devices is overblown. All of this functionality is provided by devices that you already own, including hardware wake-word detection on all modern smartphones, which I assume everyone here carries around everywhere and recharges daily without much concern.
Because the wake word is able to be processed offline, there is no need for the Echo device to record and transmit audio all the time. While the hardware is physically capable of doing this (and therefore, it will never be possible to fully eliminate doubt in the device's security) it would not be in Amazon's or the customer's best interest. Talk about a waste of resources, and a privacy nightmare!
They could do sneaky stuff like upload the audio after the wake word + a few seconds BEFORE the wake word. The cost benefit of this doesn't seem high especially if you consider that Amazon says all the time that they want to 'earn customer trust'.
Do you trust them not to waste this opportunity to get more user info? What about future software updates and especially user targeted software updates? They could avoid detection by only doing surveillance on selected targets. When they are caught, they can justify it with some "improving services" or "software bug" bullshit excuse.
This is an unquestioned assumption actually.
I think it's way more to do with the NLP system being very very proprietary.
I wouldn't be surprised if it could be done locally, computing is pretty powerful, but they never bothered to even try and make it work locally. Because "cloud computing" is a dream come true for businesses, hiding their special sauce, not having to explain what they're doing (whether it's hard or not) and always maintain control.
You do understand that it is trivial to operate the LED lights and microphone independently, right? The hardware /could/ be designed so that the microphone can't be activated without also turning on the LEDs, but I'm guessing they're independently controlled by a microcontroller, and that it's the hidden software which is responsible for turning the LEDs on when the microphone is in use.
Yes, this is a concern for smartphones as well. The capability, even if it is not currently in use, is a concern.
1: http://www.macrumors.com/2013/12/18/software-allows-hackers-...
[1] Or, y'know, about some subject more subpoenable or privacy-sensitive.
[2] Or, y'know, not including the word Alexa but triggering the on-device recognition anyway. "Alex, uh, here's your payment for murder."
It's possible that they keep a rolling buffer of all audio in the device though. There could be legitimate reason to hold onto such a window of audio. Would make for an interesting discovery.
Even if the trigger word is Alexa, different languages, dialects, and slang might vary quite a bit. Some significant portion of people might use "Yo, Alexa...", vs "Hey Alexa...", vs. <a second or two pause> "Alexa...". I'm sure someone with a spouse or child named "Alex", "Alexander", "Alexandra" and so on might also trigger it by accident a bunch, e.g. "Alex, uh, who called?".
Matching all of those trigger patterns would help filter out false positive matches, or take false negatives and refine them so more people can use the product with their own language style and be less frustrated.
By saying "Alexa" first, it gives me a chance to hear the wake-up tone before I continue my sentence.
So if I'm saying to my friend Alex "Alex uuh, tomorrow we will rob the bank", I have a chance to stop before incriminating myself. But if I say "Tomorrow we'll rob the bank Alex uh... are you in?" and the Echo interprets that as a command, then it's too late, it's already been sent and analyzed.
I trust Amazon more than Samsung, Chevy or, well, Samsung. But at least I can verify that my Echo is not sending home unusual amounts of data when it's not in use.
Ummm source? I know there has been a bunch of paranoid conspiracy theories about this that are mostly backed by confirmation bias, but I don't believe anyone has actually came out with any proof.
Facebook as denied they are doing this, so I guess you're saying they're lying? http://www.theverge.com/2016/6/3/11854860/facebook-smartphon...
The speech recognition part could run on a Pentium 133 in the nineties (Nuance software, Dragon naturally speaking), the Echo device has probably a more powerful CPU than that.
The NLP part could run on the device as well, it's mainly a storage problem, you need dozens of GB, at least 32GB sdcard.
Ideally only the search phrases would be sent to Google/Amazon/etc. That's also how Bill Gates vision was described in his 1995 book The Road Ahead. A personal agent in a wallet PC would surf the information super highway for you. ...well we are "almost" there but with a different solution.
Echo "just works", and is clearly doing it by punting to the cloud.
1) Put the speech to text. 2) Put the text to speech. 3) Send the data over Tor.
Although #3 would use a Tor exit node and would allow packet sniffing/logging/mangling etc, it'd at least be more anonymous.
Thing is, this is in nobody's interest. Not in the police or Amazon's interest. For the owner, it'd depend on if they are the defendant/suspect or the victim. The victim is not always the person who owns the Amazon Echo. But an Amazon Echo is a nice point of defense because the proof cannot be deleted anymore. All one has to say during a robbery is "Alexa, call the cops". That's quicker than having to dial the number. And at any point, if you do say Alexa, you can also trigger a warning or proof. Ultimately, if you could change the keyword to something more generic you could trigger it without a robber noticing, or by tricking them. A keyword like "put your hands up"? I don't know.
That doesn't solve a murder.
Maybe the cops are just hoping to get lucky.
"Hey we allow you to delete past recordings associated with your account and as far as you are concerned they will be, but we're gonna keep a copy for ourselves right over here, that you'll never know about."
/sarcasm