Prosecutors are just trying to cover every base but the likelihood that this will yield anything is very low.
Prosecutors are just trying to cover every base but the likelihood that this will yield anything is very low.
I wonder, how on earth do you know that, that you are able to dismiss it with such confidence as a non-issue. That's the problem with proprietary systems (proprietary always-on microphones at that). I would be surprised if they weren't actually listening and analysing and storing data from the microphone feed at all times.
Now this obviously doesn't rule out the device saving stuff locally, but plenty of people have verified that it does generally only send lots of data to the server when you have just asked it to wake up.
Not saying that they do though since if they were discovered to be doing that, it's way too damaging for Amazon's reputation for it to be worth going through the trouble.
For example, you could root the device and disable the encryption.
Or, you could perform experiments in a controlled setting where you play a series of identical recordings to Alexa and measure the statistical similarity in the outgoing data for each. The encryption scheme probably provides more entropy than just the audio, so maybe statistical analysis wouldn't help, but it's a start.
To which someone once replied to me: "But what if they aren't sending traffic through your network? What if they are using 4G or something like that?"
To which I replied that while I have not personally done it. You could scan using software defined radio to detect that sort of thing. And if it was doing that someone would notice. Plus if you tore down the hardware they would notice the antenna.
To which they replied "what it it uses something you can't detect with that?"
To which I walked away because I didn't feel like explaining how physics works.
1. Listen all the time
2. Use a small neural network on the device to detect when a voice is present
3. Collect this data into one zip file, then send the file when the user says "Alexa", or anything remotely close.
They could even put a size limit on the data upload to reduce the variance to prevent you from ever testing whether they do this.
Or, they could simply transcribe the audio on the device and upload the text. Any audio they are unsure of could be uploaded to the server to be handled by a beefier neural network.
I would be very surprised if they aren't doing something like this. The power of analysing which products you talk about in your home more often, what kind of stuff you consume, what affairs do you discuss at home, etc, is too good to pass up. And seriously frightening.
However, with that said, unless they do certificate pinning on their device the answer to that is to MITM the device and snoop on the traffic.
If they do certificate pinning the answer is:
1. Pre-record an Alexa commend
2. Play back the recording
3. Wait a minute
4. Replay the command
5. Measure the size of the packets going across the network
6. Wait a week while playing something that sounds like natural conversation - say an audio book
7. Replay the command audio file
8. Measure the amount size of data sent between the end of the second command and the end of the last
It should be slightly more than the second command was to account for things like checking for updates. But if it includes the TTS (which is essentially an audio book transcribed at this point) than it would be quite a bit larger even with text compression.
As someone else mentioned, they could of course record constantly, then compress and transmit in batches, and that would probably go unnoticed.
Possibly, but it can be fingerprinted by using known audio samples and intentionally producing very large amounts of data. See my other reply.
They're attempting to establish the precedent today. Tomorrow(figurative, not literal), when such devices send everything to the cloud to be processed "To reduce false positives", there will be much more data to mine.
I won't have one of these devices in my house. I won't have an xbone in my house for the same reason. Today, they're not much of a threat to privacy but long term, the risk is too great for my comfort. They can't be trusted.
At least this situation didn't give them the precedent; the defendant consented, so the court never got the ability to demand it from Amazon.
Wikipedia leak today claims hacks for Smart TVs. Perhaps in the future, basic things like light bulbs aren't even usable without an Echo-like device.
Bet on everything being recorded everywhere, at some point. Just look at what the satellite tech companies are doing now. If you are doing something off in a far remote area, you are still being surveilled, recorded in perpetuity. At this point I'm more concerned about AI actors than any government.
https://en.wikipedia.org/wiki/Defense_in_depth_%28computing%...
If and when that happens, we can fight it then. I'm a believer in picking my battles, and see no reason whatsoever to pick this one.
It WILL be used if it isn't smothered in its crib.
It's the nature of both government and technology.
Today, it's about convenience and whiz-bang "Look at what we can do" demonstrations but if allowed to continue, it will become a tool of the surveillance state. It's too powerful a tool to be ignored.
When CALEA was up for debate, those of us who feared that it would lead to widespread surveillance were ridiculed. It turns out, we were right. We're right about this too.
> just because they may, at some nebulous point in the future, be used against me in some nebulous way. If and when that happens, we can fight it then.
sounds very much like https://en.wikipedia.org/wiki/First_they_came_...
"If an argument uses valid reasoning, it would not be identified as the slippery slope fallacy,[2] and the term "slippery slope" may be used without an implying faulty argument."
https://en.wikipedia.org/wiki/Slippery_slope#Non-fallacious_...
If for no other reason, the behavior would be blatantly obvious to the kind of people that run Wireshark for funsies, the alarm would go up, and Amazon's reputation goes into the toilet.
Upd: > the behavior would be blatantly obvious to the kind of people that run Wireshark for funsies
Echo probably does not send the recordings all the time, it would be too simple to detect. However, it could simply send random parts of the recordings or send the data by a trigger from Amazon/random hackers. We can only say for sure that we have no possibility to check what it really does, since it is proprietary. I prefer not to trust for-profit companies (when it's possible). I only trust the source code.
The device itself has been rooted via a set of contacts compatible with what you'd use with a Raspberry Pi: https://www.reddit.com/r/netsec/comments/4inesj/rooting_the_...
and the ones that it mistakenly accepted as triggers, at least.
>No proof of any kind exists to even begin to suggest it does something other than that.
No proof exists to suggest anything about Echo. It is a question of trust. This is why I mentioned trust in my previous response.
Anyway, thanks for an interesting link.
I enjoy the devices, but also scoff at the "OMG CSI TECH ENHANCE!!" spin that can kind of find its way into discussions via less-than-knowledgeable journalists. Or ones who want to amp it up. Whatever the case, I think it's kind of interesting to hear about.
I do pity the audio tech who might have to get the audio file, put it in a DAW and turn it all the way up to listen for, uh, evidence. Ouch.
https://www.amazon.com/gp/help/customer/display.html?nodeId=...
Note that it says "this is when Alexa streams your voice to the cloud", but it does not say categorically that this is the ONLY time Alexa streams your voice to the cloud. I found that a lot of news articles said Alexa only records your voice when you make a request, but Amazon itself offers a more limited promise.