Locked-down lawyers warned Alexa is hearing confidential calls
bloomberg.com
bloomberg.com
[1] https://caselaw.findlaw.com/us-supreme-court/533/27.html
[2] Used throughout the ruling[1], but especially section II of Justice Stevens' dissent.
[3] The ruling[1], 2nd paragraph
You cited the summary, which may be useful but isn’t legally binding. The actual opinion starts after “Justice Scalia delivered the opinion of the Court.”
Also, Kyllo isn’t relevant to your concerns. A microphone and radio which picks up audio and transmits it is a technology which has been around for more than 60 years. Use of that technology has been addressed by the court in Katz and its predecessors, which collectively found that warrantless use by the police of such tech is often prohibited by the fourth amendment.
A more relevant question is whether the fourth amendment would allow police to access records stored by Amazon in the case of conversations picked up by Alexa devices. Usually, such data is fair game (third-party doctrine), but there are some constitutional restrictions (See e.g., *Carpenter v. U.S., 2018). However, even if there were no restrictions, the question is probably moot because other laws (Wiretap Act, Stored Communications Act) restrict police behavior. Basically everyone believes that these restrictions apply to Alexa recordings.
Recently there was a case in which a police department served Amazon with a subpoena for Alexa recordings from the scene of a suspected murder. I don’t remember the outcome in that case, but that too is irrelevant to concerns about warrantless collecting or searching of Alexa data, because there a warrant was or could have been obtained.
The ruling is about agents using thermal imaging technology to bust a marijuana plantation, performed from a car on a public street. The court stated that this does not constitute a search, since any random citizen could've done the same thing using commodity equipment.
Always on microphones that transmit via the internet (i.e. bugs) have been a commodity for... a few decades? But you still cannot legally bug your neighbor's apartment.
It has not been normal until the last few years for people to typically have an Alexa-like device that is always listening for the "I'm about to make a request" signal, which frequently gets turned on by accident.
It's not ridiculous that someone might conclude in the future, "if you're in someone's house with such a device, you should reasonably expect that some part of your conversation might get sent to the third party", which would mean a diminishing of the right to such privacy in 4th amendment jurisprudence.
And frankly, the whole concept of using voice to activate it is reckless. It is unavoidable to have significant false positives. It should be done with a non-audio signal that can't be faked (up to the limits of modern crypto), like an authenticated EM signal to turn on the listening.
Google Now: 2012 Siri: 2010 Microphones in cell phones: longer than those two.
It hasn't only been a few years.
In any case, 4 years vs 10 years doesn't matter. The point is, a court hasn't addressed it in the context of changing norms, at which point I claim there is a danger that it will re-evaluate what counts as private, just as OP was.
Google Now never was, to my knowledge, though I could be wrong.
From the court's opinion (the above [1]):
>> ... obtaining by sense-enhancing technology any information regarding the home's interior that could not otherwise have been obtained without physical "intrusion into a constitutionally protected area," constitutes a search--at least where (as here) the technology in question is not in general public use.
>> Based on this criterion, the information obtained by the thermal imager in this case was the product of a search.
>> the imaging in this case was an unlawful search
That's why face recognition bans and other privacy protection laws ("personally identifiable information") are so welcome.
Now as to whether they could find anything to charge you with that would stick that would depend on if the state had any sort of peeping tom laws, and if the police went up to the house and found if anyone was naked or partially naked in the house while the thermal camera was being used.
That said if there was a peeping tom law, and there was a naked person, the party with the camera that was charged could then argue that thermal cameras don't show enough to be considered under the law.
However it is my experience that police can be creative when they want to charge someone when that someone is doing something they don't like, so not sure that just a peeping tom law would be brought into play on such a circumstance.
I suppose after all this you might argue that police overreach does not make it actually illegal, but in general my viewpoint is that something being illegal is determined by power and in the case under discussion the court wanted what the police did not to be illegal because they felt it benefited the power of the system that it be so, and therefore shaped their arguments to their wants, not to any particular logic or moral sense. Thus when later another court wants the people on the street using the tech to be illegal, power gets what it wants.
As you imply, none of this prevents the police from arresting you and taking you downtown anyway. They can even say they thought it violated peeping tom laws (Heien vs. North Carolina). Beyond that, "you can beat the charge but you can't beat the ride" is an old truism among abusive police.
Kyllo is almost 20 years old, so the likelihood of a city having a law contravening it is probably low (IANAL).
I think you're wrong that they generally require the peeper to be looking while on private property because if that were the case the peeper would be trespassing and could be charged with that, although certainly it may be the case in some places. State by state basis makes it difficult to say for sure.
I guess it might be beneficial to have peeping tom laws limited to what one does on private property with the understanding that rich people have big enough property that you have to get on it to reasonably violate their privacy. Thus you can construct the law to protect the privacy of rich and poor alike as long as they have 5+ acre estates. And it is true that is is nice to have multiple things you can charge someone with, so they can plea bargain some of them away. So that they can be charged with trespassing still doesn't mean that they wouldn't want a law to charge them with peeping as well.
But as I understand it the reasonable expectation of privacy generally applies to stuff like your home, or a private dressing room (if talking about actors) and so forth.
Thus if someone is having a shower in the upper bathroom and you have climbed up a high tree off their property to look through an open window that they would not expect anyone to climb because wtf, then you are probably a peeping tom and violating a peeping tom law if it exists in that state.
You... not. But the police? Issue a warrant and they don't even have to risk, as in the decades before, having a spy physically break in to the building or the target discovering the bug.
Secret services (CIA/NSA) probably even have their direct uplink to Amazon or at least under-the-tables cooperations established to snoop on foreign people "for antiterror reasons" (aka helping out allied services, just like with the BND and MI5 with snooping on global Internet traffic).
Note: intent and expectations matter. A cellphone by itself (without any type of "voice assistant" app or feature) is only intended to record audio when it's being used to make a call. Yes, malicious actors or buggy software could enable the microphone, but that's not the expected behavior of the device. Kyllo v United States is all about what the public understands and expects about a technology.
[1] https://www.cdw.com/product/att-trimline-210-corded-phone/30...
I think to your point, there is possibly more legal protection around wiretaps than voice assistants. However, how many apps have access to the microphone? Are these apps covered by the same protections as making a phone call using POTS?
Edit: I see you've linked that your phone is an old-school landline, which doesn't really help people understand the legalities around smartphones, which many feel are a requirement to daily life.
The point of the original comment is mostly that devices like echos are expected to always be listening, and this has legal implication.
The biggest profile case where Alexa audio recordings got turned over was during a murder trial after a judge's orders.
I am not entirely clear that the ramifications of Kyllo v. United States are as dire as OP is stating for Alexa-like devices. How exactly do the police freely gain access to a "in general public use" Alexa-like device that is secured through something like an Amazon account and secured WPA password-protected WiFi network? Amazon would have to turn over credentials or the police would have to hack your account or WiFi somehow...
They don't, Kyllo v United States isn't about gaining access to someone's devices. The police used their own thermal camera to search Kyllo's residence:
>> In order to determine whether an amount of heat was emanating from petitioner's home consistent with the use of such lamps, at 3:20 a.m. on January 16, 1992, Agent Elliott and Dan Haas used an Agema Thermovision 210 thermal imager to scan the triplex. [...] The scan of Kyllo's home took only a few minutes and was performed from the passenger seat of Agent Elliott's vehicle across the street from the front of the house and also from the street in back of the house.
That's a neat phone, but we already know pretty much all phone communications are intercepted and recorded. This is why I do all of my communications over IPoAC[1].
Sure, a bit naive, but I digress. Even if it's illegal, it would be better if it was simply not possible in the first place. It's optionally having that functionality, rather than building solutions considering privacy in the first place.
> without any type of "voice assistant" app
I don't think you can uninstall Siri or Google Assistant on neither iPhone or Android, so that point is kind of null. Only with root or custom roms you'll be able to do that.
I wouldn't trust that whatever people who sit in power doesn't have a way of overriding that.
Not defending it, but your smart phone is not quite as bad as Alexa. At least for the moment.
The only additional danger from an Alexa device is that you are trusting amazon as well, but the core functionality of an Alexa device to always listen for the wake word and communicate to a server if it thinks it heard the wake word locally is the same as what most smartphones have.
Source: Mine does, very useful!
Once it is activated, it starts recording and sending audio data to google.
Every such device has a false positive rate on keyphrase activations, and of course the do, there is only limited processing available in those phones (that also try to conserve power), and people tend to mumble sometimes so you have to be a little generous and balance false positives against false negatives - the latter of which people refer to as "shit don't work".
Devices in lawyers' home offices aren't any different. And if the device encounters a false positive and activates, somewhere on some server some recording of your confidential conversation may get stored. Or worse, you buy 100 copies of "The Art of the Deal" off amazon by accident.
Even worse if your client's name, or their wife's or mom's name, is Alexa... or Alexandra/Alexander, which also cause a lot of false positive activations, or so I heard from a friend of a friend with that name.
typing to an alexa device should be an option, just like having an AI chat.
Thank Google / Amazon for creating drama where none existed.
This is possibly the biggest single problem with modern surveillance/privacy culture. The idea of requiring an individual's consent to something that is potentially a risk for them is laudable, but it's also largely a symbolic gesture when some of the largest and most powerful organisations in the world are duping all of their friends into providing much the same information without their consent or even necessarily their knowledge anyway. The whole business model is fundamentally flawed, and privacy laws are a long way from catching up.
That gives me enough information to guess there's people who would make apps that take the private data without asking, whether the option to turn off privacy feature blocks them all or not is the question.
Except Amazon was caught with their hands in the cookie jar listening on 'regular' people's private conversations on more than one occasion.
[1] https://www.bloomberg.com/news/articles/2019-04-10/is-anyone... [2] https://news.ycombinator.com/item?id=19629513
Source: worked on project for ~3 years.
When text is “start outdoor walk” then start an outdoor walk workout...
to the watch?
The thermals were 'in plain view' technically but given that the technology was highly expensive and of limited application it was clearly disingenuous if the general public couldn't access it.
Essentially the argument is that just because a signal is emitted doesn't mean that the police have an automatic right to observe or decode it beyond a common observer.
Essentially if they had patrol bots on the street with human level hearing it is still 'in plain view' levels. If they started pointing parabolic microphones or laser mikes at people's houses that would be beyond plain view and into an outright search.
If that suggested interpretation jurisprudence were applied then audio bugs should have long been perfectly legal and not a search as nearly-everyone is already capable of hearing sounds and remembering them.
More soberly: I had no idea what Elija stands for so I asked the device, which recited part of the wikipedia. It then said, "while I have your attention here are some notifications you missed" and began to recite the first of her messages from her work which are definitely not for public consumption. (She was able to throttle it, but still -- what if I had asked and she had not been present?)
However, they clearly CAN, and while they almost certainly don't on any massive scale, if they by their overlord or a security hack, did on a targeted basis listen, record and send conversations on, that would be very possible, and very harmful for whoever was targeted.
I can't imagine the NSA and other covert organizations not drooling at the chance to do just that. I'm also fairly certain those devices are not secure as by and large the tech industry has a complete failure rate at making anything computing related secure.
https://www.forbes.com/sites/thomasbrewster/2017/01/15/polic...
> The FBI appears to have begun using a novel form of electronic surveillance in criminal investigations: remotely activating a mobile phone's microphone and using it to eavesdrop on nearby conversations.
https://www.cnet.com/news/fbi-taps-cell-phone-mic-as-eavesdr...
Besides the fact that they have better antennas, this is true for pretty much any device with a microphone and a processor with audio processing capability, no?
My laptop has a microphone and video. Surely Microsoft could just start recording with the with right windows update?
My Avaya VOIP phone has speaker phone, could do the same.
It's a commonly mentioned issue, and a somewhat regular occurrence with various malware or "security solutions".
That's why a number of laptops have either visual indicators or shutters (though mostly for the cameras, sadly hot mics are rarely a consideration), and a rare few have physical disconnection switches (again mostly for cameras).
AFAIK, the T2 is always powered on even when the main CPU is off, so this could have ultra-long-term persistence.
Hacker1: we've got root.
Hacker2: yeah, but how the fuck do we get audio to work?
Hacker1: modify grub to default to windows partition and reboot, or maybe install Virtual Box and run windows. Probably not possible otherwise.
Hacker2: No, waaay too slow, they're on an ATT gateway. Find a softer target.
https://shop.googlemerchandisestore.com/Google+Redesign/Acce...
haven't tried it though, anyone has any experience? Does it really muffle the sound enough?
But I feel like switching input (or even collecting multiple sound inputs) on a nix OS is not much more convoluted than dealing with the sound stack in general. But that's probably also related to how the driver itself interfaces with the audio device...
Yes, that's why automatic updates was seen with a lot of skepticism at first. And the reason automatic updates are winning is because everything is so full of holes that disabling automatic updates is even less secure than enabling it.
Yes, they could. I get some scepticism when I say my businesses have declined to move to Windows 10, mostly because we don't trust the security and privacy aspects. However, we deal with personal data, and we also deal with various types of information that are protected by statute and/or contract. It would be very obviously against the spirit and quite possibly against the letter of several different laws for us to knowingly store and use that kind of data on a system that sends information we can't control up to the mothership and/or that could be updated without us agreeing to it. Indeed, there are multiple ongoing investigations into Windows 10 because of exactly those kinds of concerns across the EU right now.
It's a good thing that non-technical people who do take privacy seriously, such as lawyers, are starting to notice the glaring problem with these modern technologies and advise against using them. With a bit of luck, we'll then get statutory regulation requiring disclosure in advance of exactly what these devices are doing and the security and privacy implications including when they don't work properly or if they get compromised. Again, there had been much discussion in Europe recently, at least up until the world was more concerned with another kind of virus over the past few weeks, of requiring much stronger standards for security in IoT devices, and those sorts of laws really can't arrive soon enough. Mandating controls to physically isolate all cameras, microphones, transmitters and receivers at the hardware level might not be a bad idea, either.
https://www.latimes.com/business/la-fi-tn-amazon-alexa-echo-...
> According to Amazon’s website, no audio is stored unless Echo detects the wake word or is activated by pressing a button. But sometimes Alexa appears to begin recording without any prompt at all, and the audio files start with a blaring television or unintelligible noise.
An occasional false positive is funny, but it gets old pretty quickly.
But unless you have multiple devices, those make up a relatively small proportion of requests, and hence most of the time false positives is something they have a strong incentive to stop because it causes negative user experiences.
[If you have multiple devices it will happen "all the time" when a request is genuinely meant for a Alexa device but more than one device hears the request, but then it has no UI effect - one device will usually answer, and the other(s) will stand down; this is by no means perfect, but it works reasonably well]
Unless the trigger-matching was performed by some sort of tamper-resistant secure module which would also trigger the indicator and not feed any data to the rest of the system, but then you'd have to trust that that is properly implemented as well.
I guess a suspicious mind could be able to check that by looking whether there is traffic between the device and the cloud servers. And the paranoid mind (who wasn't paranoid enough to not have such a device, oddly enough) could only allow the device 'net access when desiring to use its capabilities (though obviously there's no guarantee said device wouldn't have been buffering hours of conversation while offline).
It's not like people are perfect at doing this task either.
If I was to have a very sensitive conversation, I'd unplug them.
But day to day it really does not concern me (or I wouldn't have four of them around the house...)
If they are not doing this now they will be.
You can see this in their home defense feature on the echos, where the echo can have the sounds of broken glass and wood breaking added as wake words so it can notify you and/or police in the event of an intruder.
Which I figured someone would raise a fuss about. It makes me sad that we can say that and just accept it. It shouldn't be this way.
> I can't imagine the NSA and other covert organizations not drooling at the chance to do just that.
Why doubt? Why imagine? You know that, for data on big corporation's servers, the NSA already gets a copy of everything - and everything is recorded forever without you really being able to delete it. Why would this be so different for voluntary self-espionage devices (Alex, Dot etc.)?
It a reasonable assumption that a lot more recording happens than is claimed.
This is squarely in conspiracy theory realm. Nothing in the Snowden documents or other leaks hinted at this (except for the NSA snooping on unencrypted internal links, which is useless now that everyone encrypts everything).
> Why would this be so different for voluntary self-espionage devices (Alex, Dot etc.)?
Why would a big tech company willfully infringe on their customer's privacy? How would they even do it? They have every reason to prevent it.
On the contrary. The leaks say this, specifically. You should read up on:
https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
https://en.wikipedia.org/wiki/XKeyscore
To quote Snowden personally (on XKeyscore):
> You could read anyone's email in the world, anybody
> you've got an email address for. Any website: You can
> watch traffic to and from it. Any computer that an
> individual sits at: You can watch it. Any laptop that
> you're tracking: you can follow it as it moves from
> place to place throughout the world. It's a one-stop-
> shop for access to the NSA's information. ... You can
> tag individuals ... Let's say you work at a major
> German corporation and I want access to that network,
> I can track your username on a website on a forum
> somewhere, I can track your real name, I can track
> associations with your friends and I can build what's
> called a fingerprint, which is network activity unique
> to you, which means anywhere you go in the world,
> anywhere you try to sort of hide your online presence,
> your identity.
"Why would a big tech company willfully infringe on their customer's privacy?" to comply with a national security order. These companies are not lawless entities fighting for good.
Now, clearly there's a lot of questionable practices like secret courts, gag orders and ineffective oversight in general, but this is still far from "for data on big corporation's servers, the NSA already gets a copy of everything", and very far from "being forced to deploy a firmware update that turns a smart home devices into a bug".
Companies act exclusively in their own interests, which I would hope includes to not engage in covert surveillance of their own customers.
This will only stay this way if we keep demanding and expecting privacy, and push for stronger oversight. But defeatist claims like "the NSA gets all data anyway" are not useful.
To sell advertising and recommend products?
This is absurd. Plenty of leaks clearly indicated that they succeded at breaking different types of SSL.
However, the much bigger concern should be your phone, which has a mic, is internet connected, and almost always listening. You need to also disable the Google Assistant, Sciri, etc. there too.
Oh, and that doesn't just go for your home. That's in the office, at a client, on the train, in an Uber... Everywhere you take your phone.
Once you're out of your home it's hopeless - then you have everybody else's devices to contend with.
I'm rather short of praise for Amazon but if this is still the case, great.
https://puri.sm/posts/lockdown-mode-on-the-librem-5-beyond-h...
It just doesn’t have a website where i can see all the times it was activated by accident AFAIK.
In this case it's pretty easy: dont buy these garbage products to begin with. Phones, on the other hand, are a bit more difficult to find viable alternatives for in many cases
Apple doesn't really have a good track record with their data sharing without opt-outs in Siri :(
Microsoft might. I don't know what their cortana does right now though.
A couple of days ago, I lost all respect for a coworker when we were in a meeting and somebody said something which woke up the Echo he had on his desk.
If we're talking about illegal wiretapping, a smart phone is significantly more risky and problematic than a smart speaker.
Speaking of Ring knock-offs:
In these days of self-imposed isolation, this hands-free motion activated connected door knocker seems seems pretty useful for scaring away unwanted visitors without spreading germs:
https://blog.smartthings.com/how-to/smartthings-door-knocker...
I've been in the business long enough to know that if something is digitized, it often never ever goes away. You don't know (nobody does for sure, actually) what is the internal retention policy of this information or its metadata. You can delete the recordings but the only thing you know for sure is that you and you alone cannot access them anymore.
How can a device activate 1.5 times a day? Does it have to activate right before midnight then deactivate the same amount of time after midnight? Technically that's still activating on a whole day. Or can some devices half-activate?
Or, they wanted an alliterative title.
In the advertising industry harming you is often a great business decision. Dissatisfaction breeds demand.
I've found a lot of improvement in my life satisfaction (and the size of my savings account) since getting rid of ads almost entirely. I've also found that I never feel the need to be in a hurry to buy something. Buying seems to be a slower process -- whenever I want the thing and feel good about it, not just because it's hot right now or I'll miss a deal. I know there will be another.
This may not apply to everyone but it was my experience. Clearly not a big fan of the ad industry haha.
> it won't be a good business decision
You don't think it might be better to assume all this data will leak or be hacked? You most likely have decades of life ahead of you, and once a file is free on the net, it's there forever.As if having assistants from other companies listening in was any safer. Why namedrop Amazon's own?
I think it's important to not overly freak out about these home assistants. Your phone company or video conferencing company is already listening to your confidential client calls. Your email provider is reading your email. Your internal applications run on Amazon's servers. Your upstairs neighbor has their ear to the floor. I think lawyers are used to thinking "as long as it's not in writing, we're okay", but with speech recognition getting better and better, your phone calls / VCs are going to show up in court someday.
You treat these things as third-party listening devices - bugs, because that is exactly what they are, and adjust your conversation accordingly unless/until it is unplugged.
Look at it from a lawyer's perspective: imagine your privileged conversation with your client did leak. Your client sues you. If there was a surveillance speaker in the room it doesn't matter if it leaked because of it. You just demonstrated extreme lack of care by discussing privileged information in front of a networked microphone.
There's also a thing where if a communication is privileged, and you accidentally produce it, you may not be able to unscramble the egg just because in principle it was covered by lawyer-client privilege. So there is a real risk to recording things even if there are rules protecting you.
And only corporate firewalls and some bad providers would prevent it from working today.
My email provider surely isn’t reading my mail, but then again, I seem to be in a minority that doesn’t use gmail.
The threat of real-time speech-to-text is real, but police all over the world have made the mistake of spying on lawyers now and then.
If my neighbor was listening to my conversations AND running the third largest ad platform on the internet, it would alarm me.
These aren’t apples-to-apples comparisons.
But, incentives are not crypto. There is probably nothing nefarious going on, but if you use open-source software with strong cryptography, a service provider that wants to be nefarious is simply unable to do so. That is what lawyers should be aiming for; freaking out about Alexa is a feel-good stopgap at best.
==“Perhaps we’re being slightly paranoid but we need to have a lot of trust in these organizations and these devices,” Hancock said. “We’d rather not take those risks.”==
Seems like a pretty reasonable measure and advice. The baseline assumption you make is that you know the who, what, where and when of Amazon sharing data.
Does Amazon actually have an incentive not to violate your trust? You could make the same argument about Facebook and they have routinely violated users trust. It seems the real lesson is that without legal protection for consumers, companies will continue operating in the gray area.
Sure. But the title is what it is.
The correct answer is that yep you should consider what is in the room if you need a private conversation because devices are listening.
The title is also incredibly niche and alarmist. Only locked down lawyers need to worry about Alexa??
Google sneaked a microphone in some speaker device trojan-horse style, enabling it only when lots of such speakers were already deployed. Sneaky.