Amazon researcher explains science behind Alexa's newly announced whisper mode
developer.amazon.com
developer.amazon.com
That’s not “programming language feature discussion”. It’s obsessively off-topic behaviour.
Listening to whispers is creepy.
The point is, they subject you to the same threat as an Alexa. You can’t say “Europeans don’t use Alexa because it could XYZ”, and yet they use phones which could also do XYZ.
Anyways,this is one if those problems that should be addressed in criminal law. Unfortunately most law is retroactively created,this means society will have to face irreversible damage of technology abuse before laws are updated.
Your iPhone might be closed-source, but Android devices can be compiled from source and fully inspected.
The vast majority of people both in Europe and the US use stock phones from a mainstream manufacturer without changing the default OS.
It's easier to make that argument for the SIM card, which is actually not a SIM card but also a small ARM core that runs Java code. You can embed small programs into the SIM card which is something a lot of carriers do. The SIM card and baseband work in tight concert though and you should just assume that the connections of the baseband are available to the SIM card.
https://www.scmagazine.com/home/news/black-hat-mobile-carrie...
NOTE: I own an Echo and love it, despite being otherwise fairly privacy conscious (I know that these two statements are wildly inconsistent).
There’s no real difference between “my Echo claims to only do low power wake word recognition when idle, but actually sends everything to Amazon” and “my cell phone claims not to listen to me, but actually sends everything it hears to the manufacturer.”
What do you mean? All digital assistants I know about use a wake word and they all seem to respect it very seriously:
- Incidents where the assistant has misheard the wake word causes headlines across the Internet and there's always a reply from an official spokesperson (e.g: https://www.theverge.com/2018/5/24/17391898/amazon-alexa-pri...)
- When Google Home Mini had a (hardware) bug where the button could cause it to record all the time, Google issued a software update which disabled the button completely. For months the button was a no-op. https://www.cnet.com/news/google-dumps-home-minis-top-touch-...
- In the Google Home app you can see all recordings that the device has done, play them back, and see how it was interpreted. It's pretty clear that they want to be transparent about what the device does.
All in all it seems to me that Google/Amazon is aware that a "we record everything"-scandal can be devastating for the product.
And now slightly tangential, my phone will never accidentally hear the hot word, start recording, send the recording. It can’t accidentally misunderstand my pronunciation and do whatever the hotword squatter wanted to do.
It’s easier to abuse the one core functionality of a device than one that’s an afterthought and can be more easily disabled or stands out when it’s used. That’s because the legitimate and abusive behaviors almost perfectly overlap from a user point of view in a digital assistant.
Imagine being spied through an always on live streaming camera and being spied through camera that’s off most times. You may notice it powers on and sends data it shouldn’t.
Sure it’s possible that that’s a lie, but that’s a different question.
The Amazon echo isn't even that mysterious; it has low-power hardware to listen for the wake word and doesn't even power up the main CPU until that point. And you can always monitor the network traffic. The fears are massively overblown for home assistants. Mobile phones, by comparison, track your position in real time everywhere you are and send that information to paying 3rd parties all the time.
This is meaningless if the connection is encrypted. The device can wait to send data that it's collected without telling you along with data you expect it to send to Amazon, and you wouldn't be able to tell the difference.
If the Echo was ever caught intentionally spying (either through analysis or someone leaking that information) that would be the end of that product line forever.
> If the Echo was ever caught intentionally spying (either through analysis or someone leaking that information) that would be the end of that product line forever.
Truthfully, I don't think many people would care.
The assistants in phones work in exactly the same way as the assistants in home appliances, no? They start recording when they hear their voice trigger.
Both classes of devices require trust that their maker won't invoke this functionality when it's not asked for, has hardened this functionality against bad actors, etc.
But to consider further: if you're in a situation where you have to worry about your smartphone grassing on you then you probably won't keep it powered on. Or will keep it in a Faraday case or whatever. In other words you'll be considering all attack vectors and behaving appropriately.
Whereas Amazon or Google could flip the notional 'record all' switch on their assistant devices on a whim and you'd be none the wiser.
Why can’t Google flip the “record all” switch in Android on a whim?
I'm sure there are a lot of people in Europe who disagree with you (and a lot of people in America who agree).
Grouping people together by some vague concept of nationality or ethnicity, and then claiming that your opinion is intrinsic to that group, invites some rather unpleasant associations.
It's neither nationality, nor ethnicity. I explicitly raised the question of history, and how it forms different values in the society. Why doesn't the US have the equivalent of GDPR?
Europeans are more inclined to think that if there's a problem, it is very logical for the government to step in and solve it because that's government's function after all. Americans are more likely to think private citizens should solve it if possible because government should be small whenever possible.
When it comes to privacy, an American might value privacy but think the best solution is a buyer beware approach. Such as, if you don't want to risk Amazon / Alex spying on you, don't buy an Echo. To many Americans, having to take on the entire burden of being responsible for their own privacy is the lesser of two evils because government intervention is to be avoided.
As an analogy, consider attitudes towards medication. Some people dislike taking any medications at all if they can avoid it. If they have a headache, they will usually just deal with the pain instead of taking a pill. If their doctor wants them to go on prescription medication for high blood pressure, they will hope to find a way to manage it without drugs. Then there are other people who have a more balanced approach and have zero problem taking medications as long as they have been studied well and found safe. Americans are more like the people who avoid medications whenever possible. Sometimes they avoid things which could actually have been pretty beneficial. But they don't avoid them because they think the problem isn't a problem. It's because they don't like that type of solution.
It's pretty fantastic for all those things and I'd probably buy one now if I needed to replace it.
https://h4labs.wordpress.com/2017/09/27/groundhog-day-amazon...
The value of debate, even debate that seems redundant, on a popular forum such as HN should not be trivialized. Witness the recent correction Google made with respect to Chrome and its automatic login functionality. Google did not specifically identify where they heard or read the feedback they were responding to, but any reasonable observer suspects they read a lot of it here.
When technologists grieve over the privacy risks of in-home voice "assistant" devices, even when they (as I often do) snarkily refer to them as surveillance devices, the visibility of that debate can serve many possible ends:
* It communicates to the vendors of these devices that technologists are suspicious of their devices. It suggests vendors need to either do better at communicating the privacy safeguards they have already created or do better at creating privacy safeguards in the first place if they want to reduce the degree of negative reaction they receive from technologists.
* It communicates to others who do not provide these devices that there is a market for more secure devices of the same flavor, such as self-hosted in-home voice assistants that do processing locally and exclusively for the benefit of the customer. Technologists may not be saying that specifically, but it's communicated as an undercurrent.
* It communicates to casual readers in the thread that there are risks that they should consider before purchasing and installing one of these devices. Providing clear criticism is one of the ways high-engagement people influence low-engagement people.
* It indicates that a segment of the population will not happily stand by if R&D resources are reallocated away from traditional user interfaces to voice UIs on these cloud-connected devices. It's hard to measure, but there is no doubt that as R&D resources are allocated to voice UIs, some amount of investment is moved away from building UIs that use traditional touch, type, and click UIs. People criticizing these devices are in a small way saying "this is not the future I want." It's a way of participating in the economy and communicating demand to suppliers.
Bottom line: Even though you and I have both "been here, done that" the value is not zero.
The first moment that somebody finds a home assistant sending massive streams of data to the mothership then we talk about it. But until then it's just a "debate" without any facts at all just wild incorrect speculation.
Europeans care about these sorts of privacy issues far, far more than anyone else in the world, for exactly the reason you point out. It’s very abstract to everyone else.
Maybe you’ll be proven right in the end, but for now, I love my Alexa device as it’s extremely convenient.
We did this to solve privacy issues, and empower makers!
"Surveilled By Default" is corrosive agenda to push.
[1] https://www.newsweek.com/watch-siri-heckles-british-defense-...
Edit: although I suppose the graph shown could be one of the better looking cases of certainty and not reflective of their typical result