Amazon's Alexa Team Can Access Users' Home Addresses
bloomberg.com
bloomberg.com
i'm not sure why location is the scary part here, i'm more concerned that real people and not just algorithms have access to my audio recordings or transcripts from alexa.
I worked a company with over a trillion dollars in assets that had hundreds of “highly confidential” (their own words for classification) that were available to anyone on the network.
I took all the appropriate courses of action to report, no action on their end. Reported it to the teams responsible and offered a solution, no action. I debated blowing a whistle and making an example, but I didn’t feel like I’d be safe.
This post even makes me paranoid.
In the sense that country and state or province might be close enough, it's certainly not accurate enough to nail down county, or zip code level accuracy with more than a coin flip's reliability.
Some IP addresses are well known, and bound to physical locations like places of business, retail store fronts, starbucks wi-fi, but that's not really the purview of home assistants, when discussing the meat of these services and their intentions.
> While there’s no indication Amazon employees with access to the data have attempted to track down individual users, two members of the Alexa team expressed concern to Bloomberg that Amazon was granting unnecessarily broad access to customer data that would make it easy to identify a device’s owner.
It's like when you're on the phone to some robot booking service and a real person takes over you're suddenly embarrassed to have been talking to the robot at all.
This is just very sloppy/lazy security.
How is this different than Amazon literally shipping packages to someone's home address and having their billing information?
Combining the knowledge of what you say inside with knowing where you live is different than the knowledge of a purchase you made and where you live.
Also, I would certainly assume Amazon to know my home address if I bought Alexa and shipped it there. But most people wouldn't assume that Amazon actual employees are listening to their conversations who also know where you live. HN might expect that, but Amazon makes a privacy promise that is violated here, as described in the article:
> In an April 10 statement acknowledging the Alexa auditing program, Amazon said “employees do not have direct access to information that can identify the person or account as part of this workflow.”
Bloomberg is saying that this statement by Amazon was false, because the location information from the Alexa devices can, in some cases, identify the individual or account "as part of this workflow".
The headline and your interpretation are leaning very heavily on the "ZOMG SPYING!" angle, where... I honestly don't see it. This seems like pretty heavy spinning.
Yes, they should probably have a policy of scrubbing data better before voices get presented to human ears.
> Combining the knowledge of what you say inside with knowing where you live is different than the knowledge of a purchase you made and where you live.
Technically true, but... is it actually worse? I can see convincing arguments made either way, frankly.
Well yes I know, I figure this data is likely years-old or whatever, I don't see how that matters? I didn't bring up real-time access and I'm well aware that Amazon doesn't (likely) even have that capability. Nobody here is asserting real-time access to microphones!
> Technically true, but... is it actually worse? I can see convincing arguments made either way, frankly.
Yes, it is much much worse, because it is a direct violation of their own statements about privacy. Amazon makes no statement about their box packers or labellers not knowing your address, because they obviously have to know that in order to put the label on or knock on your door.
But Amazon does make a privacy promise to not do what they are doing here. So they are totally different things and it matters due to customer expectation and their own written words.
Edit: I'm "posting too fast" and am not allowed to reply to the user below. I will state that I do care about privacy, I was simply taking the simplest debate stance to demonstrate that the two concepts are quite different (package delivery knowing your address and human reviewers of your voice commands knowing your address).
If you look at my comments on this article you will surely see that I care about privacy.
Yeah, you're spinning here. The headline and your hyperbole above quite clearly want to frame this as a "Amazon is spying on your family" thing. And when challenged, you're retreating to a bland critique of their process adherence.
So fine, Amazon didn't honor their agreement and they should fix it. They didn't spy on your kids.
If the don’t honor agreements about handling data it means means they can’t be trusted with that data.
Your response sounds crazy to me.
I absolutely care significantly about my ability to make informed decisions about my privacy. Such informed decisions are based upon having transparent and honest communication about the trade-offs.
It's like saying we shouldn't have a concept of informed consent when making a medical decision because I probably would consent anyway.
I should have the right to make an informed choice. I can do that if they are honest about their written policy. If they are lying about their written policy, then I no such choice is possible.
So, ultimately, yes, I'm absolutely concerned with Amazon's fidelity to their written policy. That's a huge issue!
- Annual Report on Compliance (ROC) by a Qualified Security Assessor (QSA)—also commonly known as a Level 1 onsite assessment—or internal auditor if signed by officer of the company - Quarterly network scan by Approved Scan Vendor (ASV) - Attestation of Compliance form
https://squareup.com/ca/guides/pci-compliance
Not sure how much "protection" that provides, but at least it's an area where Amazon itself is not the sole arbiter of what is considered OK and not OK when it comes to data collection.
The bigger issue is disclosure and informed consent. Amazon buyers know when they purchase a product that the vendor has their address and CC info, which they believe is protected. They may not know that the Alexa they bought as a holiday gift for their nephew is giving up location data to a team of "thousands of employees and contractors, spread across work sites from Boston to Romania and India."
If I'm asking a company to ship something to my home address, I've given explicit and active consent to them to have and use that information for that purpose.
So my data is popping up on a dashboard even though I've never once used an Alexa? Gee thanks.
A privacy-respecting design would have been:
1. Contacts never leave the device.
2. Location data is sent anonymously, in subsequent requests not associated with the initial query.
Not really disagreeing with you, but every smartphone app that has access to your contacts also violates your contacts' privacy. WhatsApp, FB, Google Auto, etc, etc. More than anything, I hate the way this has been allowed as an acceptable practice.
https://f-droid.org/en/packages/opencontacts.open.com.openco...
Unfortunately, it's not always so easy to not share contacts with certain services. For instance, WhatsApp works just fine with a telephone number but it actively encourages users to upload their contacts - assumably consumed by (the) Facebook (group of businesses) as part of its social graph.
I very much distrust it and am not at all surprised by this news story. I think that people need to learn that privacy is not about having nothing to hide, it's about not being taken for a ride.
Location is highly relevant to many frequent queries (e.g., weather) and a common Echo device does not have GPS or similar location-determining hardware. Consumers may choose to configure an address for things like weather and traffic / routing.
"Alexa, what's the nearest pizza place?" "Alexa, is the corner coffee shop open now?"
(Disclaimer: not an Amazon employee, but [generally] happy Alexa user.)
Maybe, but you haven't found it. To resolve your query, simply fudge the locations by 50-200m in random directions. You'll still get good local results and won't pin the exact room or house down with needlessly accurate location data. Amazon can keep that data of course, it just need not be shown to human reviewers.
Edit: I'm "posting too fast" and so cannot reply to the Uber comment below. I'll say, I still don't understand how human reviewers would need your address or GPS coords to improve their service after you get an Uber. How would they even verify the Uber came to the right place, they don't have the verification info there.
I just don't see this as a valid use case at all.
1. Customer makes a request that requires location — “Alexa, what’s the weather?”
2. Alexa gets the response wrong — “A turkey is a flightless bird.”
3. You flag that as incorrect in the application.
4. An Amazon employee reviews that flagged response, and needs to figure out how Alexa misinterpreted — did she mishear you? ...is your location data malformed, so that interpretation was discarded? etc.
I don’t see how Amazon employees can troubleshoot the Alexa application without both reviewing the audio files and the contextual information provided.
Disclaimer: at one point, I reviewed security for Alexa teams. I no longer work there, my opinions are my own, etc.
From my point of view, the issue isn't really that Amazon does this. The issue is that Alexa users are surprised that Amazon does this. Their surprise indicates that no real consent was obtained.
If Amazon had done something like, when a user flags an incorrect response, asking the user for permission to use that data, I would not have any issue with it.
I just hoped to give a better idea of how it came to be people who (in my biased experience) are thoughtful about user privacy, ended up bringing together a data set users were uncomfortable with:
Of course the team reviewing responses needs to see the user context!
Whoops.
You'd have to do something to adjust that for the population density or something like that. Adding 50m of error to my location wont get you off my property. 200m is close, but now you have to decide if it was at my house or my neighbor's house. Yes, I know you just threw out the idea, but it is a fun problem to think about once the location is no longer in a city.
Having my address isn't the scary part. It's having access to the content of all of my conversations inside the address that's worrying.
A voice assistant is just something I'll never allow in my house. The risk/benefit ratio just isn't there. It would have to be at least an order of magnitude more useful before even considering it.
Alexa Team also know when you are home, your work hours and when you are on vacation just by the time stamps of you using Alexa.
I agree. These mass surveillance dragnets are a society-wide risk even more than they're a risk to the individual. The socialized risk is that malicious actors (whether the company itself or anyone else who can get access) will use them to attack the entire society in a variety of ways. I personally consider these systems to be a risk to national security.
The risk is also in the panopticon effect itself. If people think they're always under surveillance, they will unconsciously self-censor and cultural innovation could halt. People will just silently stop doing things they think other people might judge.
Smart phones, on the other hand, are used by billions of people everyday to do all kinds of legitimately useful things.
I think it is safe to say that intentional and targeted suffering of minority groups directly due to our surveillance society is objectively bad. The only wiggle room here is, as you said, the existence of people who believe that targeting minorities for suffering is a good thing but I surely and dearly hope that we can still call those abhorrent ideas "objectively bad".
Do you think that's the net result, or is just the fact that somebody somewhere is suffering means the rest of us need to turn off the internet and hand in our smartphones?
I have a very hard time believing that the total harm of devices that watch us (actively or potentially) exceeds the actual benefits delivered by those devices.
Yes, 100%.
> I have a very hard time believing that the total harm of devices that watch us (actively or potentially) exceeds the actual benefits delivered by those devices.
This is a false dichotomy logical fallacy. You are incorrectly assuming that all of the good from smartphones comes at a forced, dramatic reduction in privacy. I know this is false because even a kitchen timer with no permissions is a useful element of smartphones that can have 0 privacy concerns.
The invasion of personal privacy at scale has indeed caused enormous societal harm that I personally think quite obviously outweighs any "good" that could come from it - and I also personally think that any "good" done from the direct causing of suffering of others is not in fact good at all.
No, I'm saying that the dramatic reduction in privacy from the typical use of smartphones is more than offset by the benefits.
There's lots of abuses of privacy that I'd like to see reigned in (I would definitely support the introduction of GDPR-like regulations in the US). I'd like to see my search data have the same protections as my video rental or health data.
> any "good" done from the direct causing of suffering of others is not in fact good at all
I assume you are talking about things like the trolley problem. That's something that I've never been able to resolve for myself.
What do you mean, isn't this the first article on this topic?
> So a dev can listen to conversations because they write software to transcribe voice to text?
That has nothing to do with this article. This article is about exact GPS/location coordinates, has nothing to do with "a dev can listen to conversations".
> Sigghhhhh....
I think you have misread the article, this is new information about a new topic. There's nothing repetitive about this news item and there's no need to sigh so heavily about people who care about privacy and the honesty of corporate statements.
User: "Alexa how long does it take to drive to Walmart"
Alexa: proceeds to give totally nonsensical directions to a Walmart that isn't even the nearest one