Sometimes the wake-word detection is mistakenly triggered and some unrelated audio gets streamed to Amazon, but the LEDs will still light up, and at times it'll even reply to a query that was never intended (I've been watching TV when my Echo will hear something and reply that I don't have any timers set, or whatever) but these recordings would still be covered by the link I pasted in the help text above.
I think a lot of the HN paranoia about these devices is overblown. All of this functionality is provided by devices that you already own, including hardware wake-word detection on all modern smartphones, which I assume everyone here carries around everywhere and recharges daily without much concern.
Because the wake word is able to be processed offline, there is no need for the Echo device to record and transmit audio all the time. While the hardware is physically capable of doing this (and therefore, it will never be possible to fully eliminate doubt in the device's security) it would not be in Amazon's or the customer's best interest. Talk about a waste of resources, and a privacy nightmare!
They could do sneaky stuff like upload the audio after the wake word + a few seconds BEFORE the wake word. The cost benefit of this doesn't seem high especially if you consider that Amazon says all the time that they want to 'earn customer trust'.
Do you trust them not to waste this opportunity to get more user info? What about future software updates and especially user targeted software updates? They could avoid detection by only doing surveillance on selected targets. When they are caught, they can justify it with some "improving services" or "software bug" bullshit excuse.
This is an unquestioned assumption actually.
I think it's way more to do with the NLP system being very very proprietary.
I wouldn't be surprised if it could be done locally, computing is pretty powerful, but they never bothered to even try and make it work locally. Because "cloud computing" is a dream come true for businesses, hiding their special sauce, not having to explain what they're doing (whether it's hard or not) and always maintain control.
You do understand that it is trivial to operate the LED lights and microphone independently, right? The hardware /could/ be designed so that the microphone can't be activated without also turning on the LEDs, but I'm guessing they're independently controlled by a microcontroller, and that it's the hidden software which is responsible for turning the LEDs on when the microphone is in use.
Yes, this is a concern for smartphones as well. The capability, even if it is not currently in use, is a concern.
1: http://www.macrumors.com/2013/12/18/software-allows-hackers-...
[1] Or, y'know, about some subject more subpoenable or privacy-sensitive.
[2] Or, y'know, not including the word Alexa but triggering the on-device recognition anyway. "Alex, uh, here's your payment for murder."
It's possible that they keep a rolling buffer of all audio in the device though. There could be legitimate reason to hold onto such a window of audio. Would make for an interesting discovery.
Even if the trigger word is Alexa, different languages, dialects, and slang might vary quite a bit. Some significant portion of people might use "Yo, Alexa...", vs "Hey Alexa...", vs. <a second or two pause> "Alexa...". I'm sure someone with a spouse or child named "Alex", "Alexander", "Alexandra" and so on might also trigger it by accident a bunch, e.g. "Alex, uh, who called?".
Matching all of those trigger patterns would help filter out false positive matches, or take false negatives and refine them so more people can use the product with their own language style and be less frustrated.
By saying "Alexa" first, it gives me a chance to hear the wake-up tone before I continue my sentence.
So if I'm saying to my friend Alex "Alex uuh, tomorrow we will rob the bank", I have a chance to stop before incriminating myself. But if I say "Tomorrow we'll rob the bank Alex uh... are you in?" and the Echo interprets that as a command, then it's too late, it's already been sent and analyzed.
I trust Amazon more than Samsung, Chevy or, well, Samsung. But at least I can verify that my Echo is not sending home unusual amounts of data when it's not in use.