How is this not a massive red flag?
How is this not a massive red flag?
One thing Amazon or Google could do here for voice apps, though, that Apple and Google (Android) can't for standard phone apps, is audit voice responses for anomalies or user input that matches a suspicous pattern and flag apps that trigger it.
They can do this because every utterance a user sends a voice assistant passes through Amazon or Google systems. If an app has access to user PII, they could add some automation to flag suspicious user responses or anomalous activity that differs from x days previous and pass it up the chain for review.
One thing I do like about Alexa development is that if you, as a developer, are privacy-minded (and don't need nor want user data for anything), you can protect your users by configuring your apps not to collect any of your users' info . As a developer, you don't even get IP addresses as everything goes User > Amazon > Developer > Amazon > User.
You always get session and Amazon-assigned user id, but they're typically pretty anonymous unless the user says "I am Jane Doe" -- which, I guess we should be honest, probably does happen more than it should, and this is what the OP researchers are exploiting.