Call me tinfoil I don't care, but don't invite me to your homes either if the place is going to be bugged, I'm good.
Call me tinfoil I don't care, but don't invite me to your homes either if the place is going to be bugged, I'm good.
I can imagine a late afternoon meeting in a lawmaker's office. The lobbyist shows the lawmaker almost his entire day, to demonstrate the "benefit" to the lawmaker, from when he leaves his DC apartment in the morning, to his one hour stay at the No-Tell-Mo-Tell, to the video of him being slapped on the back as he pockets another lobbyist's cash.
> I can imagine a late afternoon meeting in a lawmaker's office. The lobbyist shows the lawmaker almost his entire day, to demonstrate the "benefit" to the lawmaker, from when he leaves his DC apartment in the morning, to his one hour stay at the No-Tell-Mo-Tell, to the video of him being slapped on the back as he pockets another lobbyist's cash.
If this data is collected, there is no doubt in my mind that it will be sought after by malicious actors. Maybe then there will be legislation.
We are the the missing consciousness that births the AI.
So... Bezos?
It's not a conspiracy, just an inevitable consequence of technical progress.
The only "countermeasure" I can imagine is to have several independent surveillance networks. If hobbyists put up one for the public, we can at least watch the watchmen as much as they watch us.
All you'll have is a different viewpoint on the same watched public. "The watchmen" tend to be geographically segregated and use more private modes of transportation.
In Switzerland it is usually illegal to cover public space with CCTV and one is required to post signs visible before entering a private space with CCTV. AFAIK this rule technically would and should apply to guests and video in the home. It definitely applies to businesses filming employees.
I just bought into the Nest system (which also had great deals on black friday), and I'm just not worried about it.
In reality, bugging my residence isn't going to result in very interesting data. What exactly do you think is going to happen?
I just assume all of my data is already compromised, and so is yours, and neither of us can do anything about it. I think it's only useful to mitigate real world risks that materialize from compromised data. So PIN-lock your credit to avoid identity theft, physically secure your home to avoid break-ins, block ads to avoid influence campaigns, segment and restrict your IoT devices to avoid jumpboxes inside your network, etc.
If I'm doing something that I do not want recorded, I'd be using linux with a tor connection and strong opsec. The house can still be bugged as long as I don't have a camera pointed at my monitor.
If you're trying to host secret meetings in your house, maybe you should consider building a secure room to facilitate that. There's a reason the feds take this approach with SCIFs, because there's really no other way to do it.
This is literally "why do you need privacy if you have nothing to hide" in other words. What do I think will happen? I think someone at Amazon might be able to listen in on a conversation I have with my wife. I don't want a third party like Amazon to have a recording of things that I say to my wife because it's none of their business and I don't see a big utility trade-off in being able to ask a voice assistant how many quarts are in a gallon in exchange for letting Amazon record me in my private domicile.
And frankly the only reason I carry a mainstream cell phone is because I'm socially required to do so. I don't find the argument of "Google can hear you already through your phone so why not install more microphones in your house" compelling.
I'm not asking "why do you need privacy if you have nothing to hide?". I'm asking why don't you have protocols in place that you can enable for private conversations? If I've got my phone on me, I assume Google and governments can hear anything in microphone range. You should too.
Only you can decide how you want to define your threat model, but "Google can hear you already through your phone so why not install more microphones in your house" should be a compelling argument if you've already established which areas of your house are meant to be private.
You could have no IoT devices and demand all occupants and visitors check their phones at the door, if that's how you choose to live. I'm not passing judgment on where to draw the line, but it doesn't make any sense to be afraid of Alexa devices in your living room while you're sitting on your couch scrolling through Facebook on your Android device and watching Netflix on your "smart tv".
Another solution would be to never bring your phone (or any other device) into your bedroom, for example, and only have sensitive conversations there.
Because you close your curtains at night doesn't mean you're committing murder. You just don't want preying eyes into your home that you can't look back at.
That's the whole point that I'm trying to make. Identify if listening devices are actually a threat to you. Assess the area and see if a listening device would be appropriate before adding it. For most people, who are very insecure anyway, one more listening device is not going to have any significant impact on their threat level.
If anything, what we need is more training available on how they can assess the threats against them in a rational way. And, if they choose, how to mitigate the risks posed by those threats. Sometimes that will include removing listening devices, but for most people, that won't be their largest threat.
If you could have Alexa that doesn't listen to everything you say and offers the same service without the analytics, treating every request as a blank slate, wouldn't that be better in every possible way?
Sometimes it is convenient to have an internet-connected device that knows all of your preferences. You'll get better answers to your queries that way, and they'll be more personalized to you. That's ok, and I don't think it's something that should be completely rejected.
Google has been personalizing search for years, and that's ok too, because it probably is better for most users. But users also need to know about DDG and private browsing, so they can see unbiased results when they want.
> If you could have Alexa that doesn't listen to everything you say and offers the same service without the analytics, treating every request as a blank slate, wouldn't that be better in every possible way?
It would be worse in almost all ways except privacy. There's an expectation that when I ask for the weather, I mean at my current location. Or if I ask for sports scores, it knows what teams I care about. And most importantly, it should learn and get smarter over time, which you couldn't do with the type of device you propose.
I'd personally rather have areas with absolutely no devices and areas that are essentially public. I can see how some people would want a middle-ground with listening devices but with more privacy than Alexa. That might be possible, but if that's my concern, I'd rather just not have the microphone in the room at all. I think the market for privacy-vetted always-on microphones is small.
I'm sure my phone is leaking way more data than an Alexa.
But most people aren’t famous, so who cares?
- I walk down the street and everybody can see me.
And
- I walk down the street and my moves are recorded and stored forever in some db which may be abused or leak.
The chances of that piece of information coming back to hurt you in the course of the next decades are so much higher.
wow! this needs proof and evidence. you can't just pull this out of nowhere?
afaik it's becoming harder & harder to get data out of your phone without you unlocking them. now, if you choose to share your private information on said phone, that's another discussion.
i want to think that movement tracking and giving away private information about you -- and perhaps not-knowingly about people around you -- are different things!
I believe that privacy can co-exist in your life with listening devices (though maybe not in the same room, if you're concerned about your voice being recorded).
>> "privacy is dead"
>>> In reality, bugging my residence isn't going to result in very interesting data.
>> "nothing to hide"
> I'm not arguing "privacy is dead" or "nothing to hide".
Really?
Also, bugging my residence isn't going to result in very interesting data by design. I could have plenty to hide, but I'm not reading my evil plans for world domination aloud.
If you do need to talk about something private, nobody is preventing you from disconnecting all the microphones.
Know what you're trying to prevent, then take actionable steps. Privacy is hard, but not dead.
I agree that you're most likely not doing anything interesting in the eyes of the authorities in your home, most people aren't. But advertisers and content creators definitely care, and that's where the true problem is. They shouldn't have the power to anonymously collect all of this data, and then decide through the power of their far-reaching services which products are accessible to you or not, what information is presented to you through means that appear transparent, and so on and so on.
The "I have nothing to hide" argument has never been what today's privacy debate was about.
I don't agree there's nothing to be done short of building your own SCIF (laws are a logical place to start), but to me it's more important to point out what a privacy disaster all of our phones are that it makes everything else look much smaller.
You don't have to be doing anything wrong or "interesting" for that data to be collected and used against you later.
These days your normal everyday activities are being used to calculate things like your "consumer score" which determines things how much you pay for products, what your insurance company will charge you or will cover, what shows up to employers when they do background checks, and that's just on the private industry side of things.
The government is also collecting this data and you've either got an incredibly optimistic outlook or a very limited understanding of history if you think they couldn't ever use that data against you or against anyone who becomes an inconvenience to those in power.
And if there's no data available on you, don't you think they'll charge the highest rate anyway?
For the concerns you have, it'd be far better to maintain a socially-optimal profile with data collection, to show what a normal/happy/healthy/productive member of society you are.
I do support regulation on how companies collect and assemble data, but while they're doing it, your best bet is to have lots of uninteresting data collected on you.
Nothing is stopping you from having multiple identities for specific purposes.
Surely you understand that many people don't want to live in a world where you have to maintain a false persona 24/7 to avoid being flagged for some unknown perceived infraction. Many people already curate a social media presence for that reason, but are you really okay with extending that to every last facet of your life?
Should you have to worry if some future employer or your insurance company might possibly think that you're buying too much alcohol, are too supportive of the wrong political party, are too gay, opinionated, not social enough, not happy enough, dating too often, eating out to much, etc.?
It doesn't make any sense to try to change your behavior to try to look like a model citizen at all times because you can't know what the criteria is you'll be judged by, how accurate the dossiers on you are, or how they're being used to impact your life.
This is a broken, dystopian, dangerous system and telling people to give up even trying to limit the amount of data they expose and simply accept it is not going to help change anything.
Yes, but they have no choice today.
> Many people already curate a social media presence for that reason, but are you really okay with extending that to every last facet of your life?
Nobody is forcing you to buy an Alexa. If you want an always-on digital assistant, then yes, you're probably ok with curation of the words you say while at home.
> Should you have to worry if some future employer or your insurance company might possibly think that you're buying too much alcohol, are too supportive of the wrong political party, are too gay, opinionated, not social enough, not happy enough, dating too often, eating out to much, etc.?
Yes, everyone has to worry about this in today's environment. It would be silly not to worry about this with what we know about large scale data collection.
> It doesn't make any sense to try to change your behavior to try to look like a model citizen at all times because you can't know what the criteria is you'll be judged by, how accurate the dossiers on you are, or how they're being used to impact your life.
No model is perfect, but I believe there is safety in numbers. You can't know what you'll be judged by, but the more people who share your views and actions, the less likely you are to attract problems.
> This is a broken, dystopian, dangerous system and telling people to give up even trying to limit the amount of data they expose and simply accept it is not going to help change anything.
I'm not telling people to give up trying to limit the amount of data they expose. I'm saying that everyone should develop their own threat model and see if an always-on listening device at home is appropriate for their needs.
I do not see any future where opting out of Alexa or Google Assistant would mitigate any of the fears you have. I do see a future where knowing how to audit your own security and how to use more than one identity will mitigate your fears.
Until the police are looking for evidence to confirm it was you, and they pull footage of you getting home and walking into your "secure room" 5 minutes before the supposed activity started and exiting the room 5 seconds after it stopped. No warrant required of course.
Idk man good luck with the opsec.
In reality, bugging my residence isn't going to result in very interesting data."
You need to be doing everything you can to discourage any sort of data in this data-economy-style world we are pushing ourselves into. And if I want to walk down the street, I sure as hell don't want your camera recording me, especially since knowing the involved company, one way or another that recording WILL get used for a monetary purpose, and I sure as hell didn't sign a model contract, so despite being in public you're still potentially violating some of my rights with your doorbell camera.
I've already given up my location data to Google by using Android with Google's services. It's fine if the doorbell sees me entering and exiting. By adding the doorbell, my threat surface isn't expanded by very much, but I get all this extra doorbell utility.
I don't really have a problem with Google seeing the outside of my home. I wouldn't put a Nest camera inside. Personally, that's my line. The important thing is that I can change it later if I want.
As far as your rights, sure, sue Google or Amazon if you want. It's not really my problem unless the devices get banned, which won't happen. If they do get banned, I'll replace them with whatever the next best thing is, or roll my own.
I understand the frustration, but at this point, the only rational thing to do is adapt.
I find out it's YOUR camera that was involved in violating my right to control my image, you're an accessory and I would file against you as such in court.
So it is your problem, regardless.
“Nobody cares about you”,
and if they did, they would find a way to get all your photos or personal moments. If you really want to be secure getting rid of amazon assistants isn’t going to move e needle.
let's not jump to conclusions here.
but if attackers are really targeting your phone, then security and safety should be your first concern. it's beyond "let me have a little privacy" at this point.
in any case, people are conflating that with willingly (or unwillingly) throwing tons of private information about them and people around them at entities who don't know what to do with all that data right now.
If the NSA runs a few TOR hops between you and the target it would be unfortunately possible for them to perform a correlation attack on the traffic going through it's network and your confirmed position sitting on your home computer doing stuff, likely with a compromised router confirming TOR packets are leaving your house.
If you were running the Silk Road on TOR and the gov had reason to suspect it was you associated with a very specific illegal event, proving you were there at the right place and time can be enough without the content of the packets itself to sink you. Adrian Crenshaw's talks about Tor are fun for a laugh.
If you have a reputable friend visit your house that has been doing illegal things behind the scenes that you knew nothing about, be prepared for more scrutiny of your videos and potential recording devices. Just like swatting sent an average joe to jail for a few years because some kids called the swat in and they found a few ounces of weed. You may record technical negligence of your own child, forming a verbal contract you did not intend, agreeing or disagreeing to things that may publicly change your reputation and more.
Your images of your loved ones could be deepfaked to make a video phone call with a wavenet faked audio voice claiming to be kidnapped upon travelling through Asia and demand money to get home safe, because your home video system was hacked a week before...
The data of your existence is now an attack-surface intentionally or otherwise that authorities & criminals alike can explore.
Also, if Google's devices or networks get hacked and used for extortion, they've got deep pockets. It'd be a cool plot for a movie, but I'm personally unconcerned about that scenario.
I was using wavenet as an example of the technology that's possible, I don't think you need to compete with google's proprietary software to make a 30second video clip with faked audio.
My idea of their pitch will be: "our home cleaners can access your home while you're away and they will be monitored 100% of the time while in your house, you already have security cameras, etc. installed so there's no need to worry."
Amazon is playing with fire here. Hopefully these new workers will be able to develop solidarity to resist these actions, because the upper middle class these products are marketed to sure aren't going to care about the implications of the surveillance as long as it means no one can lift their new laptop.
Yeah... uh, about that...
However, most at-home services _are_ upper middle class, and owning a reasonable number of security products is upper middle class. Furthermore, we're interested in the intersection of those two things, implying an even more well-off group.
They are. Based on my experience few below the upper middle buy a used one (they opt for used/refurbished).
Many 'poor' people are poor because of spending habits and lack of saving discipline, and it's a hall mark of the modern poor in America to drive a car you can't afford, own an expensive phone, have a big TV, etc. Whether buying it on credit, or buying with money that could/should have been used to pay off debt, save fore retirement etc, it's trivial to buy something like an iPhone for almost anyone in America.
iPhones are BELOVED by the poor as a "rich" status symbol, for all the same reasons why you think the poor don't own them.
P.S. you can get a brand new iphone for like $30/mo from any major seller. An 18 year old with their first fast food job can buy a big shiny iPhone today.
P.P.S most of the 'upper middle class' I'm familiar with doesn't do iPhones and especially not brand new ones, they do budget phones or cheaper android devices because you don't get wealthy spending $1000 every 2 years on a device that costs $275 to manufacture.
(1) "Poor people make bad financial decisions" is practically a meme at this point. Why do they make those decisions? Perhaps the incessant advertising and rampant consumerism in America? Poor financial education? Why not fix those things instead of demonizing them for enjoying a few minor comforts in their lives?
(2) How does buying an iPhone have anything to do with rent? $500/yr on a phone would barely put a dent in Bay Area or LA rent. Once you include total cost of living the new iPhone is a rounding error, even in 'cheap' places, and especially if you have health problems.
(3) I'm not sure what upper middle class people you're talking about, but all of them I know have new iPhones. You don't save yourself to a $200k/yr income, that's a shitty argument pushed by the "personal financial responsibility" press to make rich people feel justified in their immorality.
You're just looking for reasons to feel justified keeping people poor. If you can't afford to eat, it's not because you're overspending on a car or a phone, you're probably driving a beater you pray every morning will get you to work.
Not only that, you're _still_ missing the point of my post. AT HOME SERVICES and CLOUD SECURITY PRODUCTS are for rich people. No poor person has a cleaner and a fucking ring doorbell, get real.
My understanding is they set a corporate minimum wage of $15/hour. Is this not a higher wage than more than half of Americans?
http://themostimportantnews.com/archives/51-percent-of-all-a...
Regardless, this doesn't invalidate my point. $15/hr is still no where near enough to participate in a lot of these at-home services. I make many multiples of that and find a cleaner + multiple security subscriptions too expensive for my taste.
Fuck the grim Amazon future, with cloud feudalism spreading to real life and Jeff Bezos is Emperor..
As it turns out I am personally CREST accredited and run a small IT company with ISO9001, 27001 and advise on PCI DSS and the like. I bathe in tin foil.
In the UK we have a pretty simple standard called Cyber Essentials and a higher one called Cyber Essentials Plus. https://www.cyberessentials.ncsc.gov.uk/ why not give it a go? Even if you are not from the UK then there is some good advice there - https://www.cyberessentials.ncsc.gov.uk/advice/
Anyway, VLANS and firewall and self hosting is the key to my idea of a decent IoT smart home. Also I insist on manual controls if the controller is down. I also do a proper risk assessment on each device.
That's what I tell people when they ask how I can stand having an Echo listening to me in my house -- and then he took out his phone and used Siri to look up the privacy problems. He didn't understand the irony even when I pointed it out.
Why is that problem justification for bending over to the expanding surveillance state?
[0] Who knows how prevalent this is, especially with the popularity of defective by design integrated Qualcomm chipsets etc. But at least this is at the level of national governments, rather than agile consumer companies with stated missions of datamining as much as they can for economic advantage.
For example: A phone's gyroscope might be able to listen in on you, even if your microphone is off:
you forgot, "sold" or "misused against you".
It's just as dangerous in the hands of amazon as it is in the hands of hackers.
google:duckduckgo:ring:?
No one cares, no one can be bothered to be galvanized to give a shit, and it's because there's too much money to be made from the status quo staying the same.
I'm not sure the American people have the ability to change it at this point. We elected Obama when he campaigned on a promise to end the mass surveillance of American citizens, but once he was in office he expanded the NSAs ability to do just that. James Clapper repeatedly lied to congress about what was happening and has publicly confessed to doing so, yet he faced zero consequences for it.
At this point it doesn't seem like the US government represents our best interests and we have very little ability to change that. We've got actual research showing that:
https://www.cambridge.org/core/journals/perspectives-on-poli...
In this kind of environment what exactly do you expect the general public to do? We have no power or representation in American government.
The funniest part of this opinion is that 95% of the time I hear it, I say, can you take the bugged device out of your pocket before you talk about not being near bugs?
Always with the iPhones and Androids, even though they have the same exact technology for always listening, activating, and sending your data to a database for collection.
Very rarely, they'll pull out a dumbphone and that's respectable since generally only governments bug those, and only once in my entire life have I heard someone criticizing bugs actually not walk with a cellphone at all. Now there's someone who demonstrates their convictions with their actions.
If you care, you care. If you don't, don't pretend lol.
He constantly uses an android device and it's believed that France, Israel, Russia and others listen into every call he makes.
Just saying, bugs are bugs are bugs.
I think there's a fair distinction to be made between a cell phone which you can configure to not listen to your environment 24/7 and even put into airplane mode so it isn't sending data vs intentionally bugging your entire house.
It is certainly possible that my cell phone is lying to me when I tell it not to monitor my every word and it tells me that it isn't, but at that point the fault is on Android and Apple. If I choose to bug my house and send the intimate details of my life to Amazon that's 100% on me.
It's also true that while these days a cell phone is basically required to function in modern society, a smart speaker is not.
If it's possible that your cellphone could lie to you and monitor you, then it's equally possible your smart speaker could lie to you and monitor you
Both are managed by the same firms, with the same rules. If one can, both can. If one can't, both can't.
And just because one bug is required for modern life and another bug is not required, doesn't make one bug more acceptable than the other. A bug is a bug is a bug. If you care about bugs, then carrying one around is hilarious silly. Better to re-align your morals so that you are not hypocritically violating them.