Phones that secretly listen to us are a myth
bbc.co.uk
bbc.co.uk
Wasn’t it just last year that a wide network of android apps using inaudible cues for ad tracking was uncovered? What are they trying to prove here?
Likely snooping happens more when phones are moving, and not lying about in a room with recognizable recordings playing, and that belong to people somebody cares to snoop on.
But it is true that readily available metadata being deliberately sent by users, via clickstream, is much easier to extract usable detail from.
But the notation that phones, due to their system insecurity, widespread of malicious applications, the reliance of voice recognition over 3rd-party servers (and in turns, their insecurity), and the ethical problems of handing training data and samples, are all avenues that can be easily exploited to secretly listen to us, is very true.
Overemphasizing the first notion while downplaying the second one is a way to manipulatively shutdown the public concerns over privacy issues.
Disturbing. The fact that there is a difference suggests that they are doing something with microphone input...
To your specific point, Shazam has to be activated (hey siri, what song is this?) on iOS.
This feels like it was dictated to the writer directly by a not-super-competent intern at an intelligence agency.
I feel like this could’ve been more similar to what was being suggested, adverts or background TV/radio isn’t what any ad-driven telemetry is going to be interested in. Definitely not discounting the research, just seems like this element could’ve been improved.
Short summary: I received in my Google news feed a story about something I would never expect to see in my news feed. The only rational explanations I could think of were that (i) Google had eavesdropped on an earlier conversation, or (ii) Google had received the full data for an offline credit card purchase in a bricks and mortar store made with a credit card which had been saved in my Google profile.
Full story: My wife went to a bricks and mortar bookshop to buy a boy's birthday present. In the bookshop, our daughter said he liked football, so she bought a children's book by an English footballer. She did not know what to buy beforehand, and did not look the author up online afterwards, so there was zero online footprint for the transaction. When she got home, I asked what present she'd got, and she told me it was a football book. When she told me the author's name, and I said I'd never heard of him, joking that the only footballer's names I knew were Scottish footballers from the 1980s that I'd memorised to try to fit in at school. Again this conversation had zero online footprint. The next day there was an article in my Google news feed about that specific English footballer. I don't recall ever seeing any football related story in my newsfeed, so would never expect to have seen that specific footballer appear by chance.
I'm inclined in this case to believe it was Google buying data on credit card transactions for credit cards linked to the Google account. I keep on meaning to ask around if anyone knows if Google do this. Perhaps someone here knows?
https://www.theverge.com/2018/8/30/17801880/google-mastercar...
It's interesting to see how slowly we are all catching up to what is going on behind the scenes, and how we all struggle to come to terms with the implications.
"I vaccinated my child and 6 months later he was diagnosed with autism. Cause and effect!"
Well: it is. Autism is a childhood disorder (therefore) whose symptoms usually follow vaccination. It is not unreasonable to hypothesize a causal link.
It may be unreasonable to maintain it in light of other evidence (eg., no difference in rate amongst the non-vax'd). But people don't live in the macro (ie., comparative contexts) they live in the micro (ie., their own experience). And its hard to communicate macros to micros.
Being listened to, or companies being able to predict my behaviour before it happens based on the data they’ve got on me.
But I recon, you're case is creepy. But more likely that the VOD service you use sent data to Facebook.
https://en.wikipedia.org/wiki/List_of_cognitive_biases
Or maybe you watched john wick on netflix or amazon and boom.
Now, is this reassuring? Maybe the ad-placement algorithm with all the data available is much better at knowing who you are and what you want that than recording audio, and extracting meaning from it.
That or you and I are just a lot more predictable than we think (which is actually what I think).
* Firmware is patched after the fact either by inserting a backdoor into the build process, or binary patching the resulting firmware image. Such an operation is likely to be compartmentalised to avoid employees knowing about it.
* Intelligence agencies seed online discussions with false assurances (note that I'm not suggesting any wrongdoing on your part - merely pointing out that an anonymous forum post is hardly verification that can be relied upon).
That said, I do agree that exploits are likely sufficient, and that planting a mass backdoor is probably not worth the risk of it being detected.
There's also hardware exploits. The firmware doesn't need to have a back door if a certain sequence of packets sent to the network controller will cause key memory to be overwritten and live patch in a backdoor.
That said: monkey-patching is much more easily concealed than hardware or source-code changes, and is more in line with how US spooks have been seen to operate.
everyone is ignoring what was pointed out by "kennywinker"
https://news.ycombinator.com/item?id=20884384
the fact that both for android and for iphone seperately, there is a correlation with sound / silence and data usage, even if in the opposite sense. why did this not at least prompt the investigator to dig deeper?
Do Android and baseband firmware run on one and the same processor(s)? Or are we calling ARM Secure World / TrustZone baseband these days?
I haven't used iOS in a while but hasn't it always been extremely obvious when an app was using the microphone in the background?
It’s a distinction without a difference.
All this would just require a few thousand bytes transferred between the phone and the ad-network. Since they are using information they already have about you, and there are little or no additional CPU or network usage it would be really hard to detect.
Because we know they're doing it. Therefore, not a secret.
I saw some guy on Reddit once triumphantly declare he had proof that Google (or Facebook?) was listening to his microphone because he started receiving Spanish language ads after he began working at an office with a bunch of Spanish speakers. Come on dude, you share a wifi network with them, your GPS location overlaps with theirs 8 hours a day, and you presumably frequently send/receive emails from them. Facebook/Google doesn't need to listen to your mic to know that you have a bunch of Spanish speakers in your social network.
For a decade or more vendors have been shipping voice recognition technology onto consumer devices, with less and less friction to operate, actively attempting to make it part of very common device interactions.
Now the only questions are:
A. Do these omnipresent hot mics have adequate access control?
B. How many parties have access to them, and
C. Are these parties worthy of being trusted with such responsibility?
While I am not a fan of conspiracy theories, such half-assed pseudo-proofs actually make me believe there might be something behind the underlying conspiracy theory.
Usually I just heard ambiant noise like computer, media, some distant talking. My naive assumption was that it had misfired on "OK google" and recorded for a few seconds to see if I'd give it a command.
I've never opted-in for any OK google type service or device but I did own two vanilla Pixel devices.
I've since opted-out of such recordings and it appears that Google has made no more recordings of me since then.
But as a technologist and software developer myself, I know just how difficult it would be to make a device that would be able to constantly transcribe the audio input stream and surreptitiously upload that data all day - and do so without destroying the battery life or having a noticeable network bandwidth footprint.
Not too mention the fact that if any memos/emails documenting any part of these "black-ops" advertising programs were leaked, it would be the tech story of the decade and probably result in billions of dollars of fines and legal fees for Facebook/Google/Apple/Amazon.
No, in the end, it seems much more likely to me that these occurrences are just the Baader-Meinhof phenomenon in effect.
After all, how many things have you talked about that DIDN'T end up in your advertising stream? I mean, this is pretty easy to test. Why don't you just start talking about adult diapers in front of your phone right now and see what happens?
Plus sending full audio recordings to a server would be somewhat odd, isn't collecting key words converted in text and sending that a lot more plausible?
I am hoping that the datasets used by Wandera will be available for us to look at.
https://support.google.com/websearch/answer/6030020?co=GENIE...