I can’t see how this is fear mongering. Device was not acting against owner’s will: that person specifically does not tighten relevant privacy settings and enables always-on mic because they see useful content suggestions as a feature.
It is different from my outlook (and I take it yours too), but I think that point of view deserves the right to exist.
The issue is that now when I am talking to someone like that in real life, I know I may be implicitly agreeing that Google would pick up my speech as well. It’s a clash similar to one between a person (e.g., my mom) who grants messenger apps full access to their phone’s address book for convenience, and their contact (e.g., myself) who does not want their information to be shared with Facebook et al.
Addendum: a cursory search confirms this experience.
— https://www.vice.com/en/article/wjbzzy/your-phone-is-listeni...
— https://www.makeuseof.com/tag/your-smartphone-listening-or-c... (2019)
— https://www.quora.com/Does-Google-listen-to-my-conversations... (the first answer does not mention ads, but others share similar experience to what I saw)
— Counterpoint: https://www.bbc.co.uk/news/technology-49585682 “phones that secretly listen to us are a myth” (2019). Notably, with all my respect for BBC, this article lacks a lot of context (did they turn off voice activation before testing? what were their privacy settings?), and to test devices listening they played commercials in presence of the phone rather than using voice (I have relatively high confidence that modern devices can easily distinguish between speech nearby and sound from a commercial before recording leaves the phone).
Some sources claim that as of last year Google is changing the way their apps work. Not sure if they stop listening or stop showing relevant content.
(I don’t personally own an Android phone, and even if I did I would have turned off virtual assistants & disabled always-on mic just as I do with my iPhone, so I wouldn’t be able to present first-hand proof.)
Maybe read up on the concept of "extraordinary claims requiring extraordinary evidence"
Every company vehemently denies this is possible.
Regarding iOS, I hadn’t observed ads obviously based on what I spoke about in presence of my iPhone, but then I don’t use voice-activated Siri and generally tighten up privacy settings.
(Similar to Vice’s article I linked, but faster.)
Again, the owner of the device saw that as a convenience feature and consciously did not set the phone up to prevent it, which made me feel a little old-fashioned and unnecessarily paranoid.
Also, unlike Vice’s article, in the scenario I have witnessed the recording did not necessarily have to leave the phone: the news app could have kept a large cache of recent articles and locally pick the ones matching the %SUBJECT% that we spoke about.
I am inclined to believe that Google, given their business model and scale, is unlikely to store voice data insecurely or insufficiently de-anonymized, so I’m primarily worried about third-party apps getting access to always-on microphone without visual feedback. (Hopefully it’s not very likely and app stores have tools to detect nefarious uses of relevant APIs at review stage.)
As a person who's made a living the last few years working in the guts of Android on embedded devices, there are so many holes in this way too common myth that phones are listening all the time.
You don't even need to dive into the technical aspect of it, what on earth is the risk reward here?!
Risk: Forever break the trust people have in your devices, this isn't some grey area intrusive tracking that would just get swept under the rug...
Reward: Get noisy info about people's interests when you literally own the device that contains more information about than their own short term memory does!
It's nonsensical, and there's no way that Google could do this that wouldn't already have been caught.
I mean is the theory that all Google devices do it and somehow no OEM has realized their microphone is getting accessed? (Because even with the lowest level access on the device, modern microphones are not so unsophisticated, there's no universal way to access it in a way a manufacturer wouldn't catch onto sooner or later
Or Google did this but only on phones they own or something?
It's nonsense.
There is no proof it happens, and no proof it doesn’t happen, because it’s non-trivial to detect based on network activity. The only evidence is observing content relevant to what was being spoken about being suggested across apps.
> Risk: Forever break the trust people have in your devices, this isn't some grey area intrusive tracking that would just get swept under the rug...
Reward: get people to love your services for relevant suggestions. Believe it or not, there are people outside the extra privacy-conscious bubble who do not at all mind their devices listening.
> Or Google did this but only on phones they own or something?
I am pretty sure this depends on software. I have seen this demonstrated on a Google-branded phone with a Google app.
Like I already pointed out this is nonsense.
Always on listening even with perfect parsing would INCREDIBLY noisy. There are a million and one reasons for a term to come up in speech. The simplest conversation could surface hundreds of targeting terms.
Meanwhile they literally own the device and the services most people use. They have your search, they have your email, they have social graphs. They can literally make inferences before you even think to talk about them with other people! (and we've seen this happen before with things like disease and pregnancy reveals)
We're at the point where most people's cell phones hold more personal data than they could even recall on demand.
So why on earth would they go and muddy all that easily weighted data with noisy data like everything you say, literally every other form of interaction is already giving them better more concise information about you...
-
> There is no proof it happens, and no proof it doesn’t happen, because it’s non-trivial to detect based on network activity. The only evidence is observing content relevant to what was being spoken about being suggested across apps.
I can't believe people are entertaining this kind of stuff on HN.
You make an unreasonable claim... then act like because you yourself can't prove your unreasonable claim it should be entertained? What?
That's not how that works. You have no actual proof for your unreasonable claim... then that's it. It ends there. The burden doesn't suddenly fall on others to prove the contrary!
Come back with even a modicum of proof. Literally any real proof other than anecdotes where the ad companies who literally have almost all the data in your life anyways are able to come up with topics you're interested in... and maybe someone will entertain this.
And no, talking about something and getting an ad for it after is not proof any more than having a leaf fall on your head while you stand under in a mid-autumn forest right after you whispered "gravity" is proof that the forest is listening to your words.
FWIW there’s a technical paper[0] that summarizes existing studies as of 2019, and it’s been neither definitively proven nor disproven that it happens. Turns out it’s not at all that trivial to detect.
From the paper:
> Perhaps most importantly, Pan et al. were not able to rule out the scenario of apps transforming audio recordings into less detectable text transcripts or audio fingerprints before sending the information out. This would be a very realistic attack scenario. In fact, various popular apps are known to compress recorded audio in such a way [10, 33]. While all the choices that Pan et al. made regarding their experimental setup and methodology are completely understandable and were communicated transparently, the limitations do limit the significance of their findings. All in all, their approach would only uncover highly unsophisticated eavesdropping attempts. …
> Therefore, the fact that no evidence for large-scale mobile eavesdropping has been found so far should not be interpreted as an all-clear. It could only mean that it is difficult – under current circumstances perhaps even impossible – to detect such attacks effectively.
(Apparently, noticing relevant content being obviously suggested is the only way of detecting it at this time, and of course it comes with its own caveats.)
[0] https://link.springer.com/chapter/10.1007/978-3-030-22479-0_...
For sure, it’s an arms race between ecosystem’s root vendor and app developers, but the possibility of vendor itself using some privileged APIs that do not provide visual feedback is also a concern.
Until they get caught. They they issue a wishy-washing non-apology and put out a press release stating "We can do better."
We've been to this rodeo before.
In case of my friend showing me this, this happened a few months ago and I can’t remember exactly how the demonstration went. I’m inclined to believe there was no hotword activation, as I remember myself being quite startled (at that point I disbelieved that a phone can be listening and suggesting relevant content right away), and as you noted with hotword activation it would have been markedly less surprising.
> For your smartphone to actually pay attention and record your conversation, there needs to be a trigger, such as when you say “hey Siri” or “okay Google.” In the absence of these triggers, any data you provide is only processed within your own phone. This might not seem a cause for alarm, but any third party applications you have on your phone—like Facebook for example—still have access to this “non-triggered” data. And whether or not they use this data is really up to them.
If listening constantly was widespread it would have a dramatic effect on power consumption - and so battery life - and be noticed.