I went there for a meeting but was not allowed on the floor because it was not pre-approved by security.
If the Apple centers where Siri errors are reviewed is like that, it would be hard to sneak recordings out.
I went there for a meeting but was not allowed on the floor because it was not pre-approved by security.
If the Apple centers where Siri errors are reviewed is like that, it would be hard to sneak recordings out.
At some level, you have to accept that things like Siri operate just like talking to human customer service representatives, who these days always begin conversations with a rote "This call may be recorded for quality and customer service purposes."
What it comes down to is whether you trust the company to be unreasonably diligent in controlling what happens to these recordings. If there is a criticism to be levelled here, I think it is around the question of how well Apple and everyone else in this space allow consumers to make informed choices.
Fine print in a voluminous user agreement is not nearly the same standard of disclosure as "Your words may be recorded for quality and customer service purposes" every time you say "Hey Siri." The latter may be impractical, of course, but perhaps there is a middle ground. It's not a dichotomy.
They took this very seriously.
Now when it comes to a deliberately bad actor, well, nothing is 100% perfect, but there were many other security things going on that I am not going to describe here, plus I know for a fact that there were security measures they did not disclose to me.
But let's face it: Somebody, somewhere, can train themselves to memorize a screen full of information. They could memorize something, go for a smoke break, and upload what they memorized. Lather, rinse, repeat.
The point I made, and am still making, is that some companies care enough to do everything reasonably possible to keep customer data secure, while other companies do not. The company I described here cares. I believe Apple cares too.
I suspect it will always be possible for someone to pull a small data heist, but extraordinarily difficult to set up a regular pipeline to exfiltrate data. The weak point is probably the digital systems. Most attackers would want everything, and the way to get everything is with a vulnerability.
Then why isn't it mandatory for Siri to start every conversation like that too?
https://www.youtube.com/watch?v=JsVtHqICeKE
I'd also be concerned with leaking of mass amounts of records at once due to a security lapse on servers where it's a bit easier for grossly inadequate protections to lurk unnoticed-
https://news.ycombinator.com/item?id=19191241
I think I've read that Google doesn't even store the original recordings, but distorts them randomly to make them unrecognizable but still intelligible by their models. That seems like a pretty reasonable way to protect people, provided they're informed and there's no link back to the original account.
I guess the voice scrambling thing must have been specific to their human-supervised learning program. I expect the unaltered voice data is treated with some special care on Google's backend... but I'm still creeped out.
We live in an age where everyone wanders around with a device for broadcasting video to the world in their pocket.