Alexa leaks private wishlists
shkspr.mobi
shkspr.mobi
I'd feel the same sense of annoyance if something like that happened to me.
This is not the first time large companies with built in wishlists have ignored or abused their users. There were times when a retailer would direct your loved ones no to your list but to an “Idea” list in a tab right next to it when they went to your link. Most often they just index your list on Google and it becomes a top result when someone searches your name (great SEO for them, bad for you). Or suggest gift cards to stores that are 30% overpriced to your loved ones right at the top of your list, when you never wished for one. I built DreamList by hand over the past few years to prevent these and other abuses with family’s wishes and money and now it’s growing. I would love to get your feedback as well.
Even if the try to limit the liability to just what you paid them, it’s still a useful barrier to selling your data or exposing it.
In the case of them blatantly selling it to “partners” you could still go after them for the value they gained by breaking the contract and selling your copyrighted information.
If you need a wishlist (in the Amazon sense) and you’re worried about privacy, write down the stuff you wanna buy in a notebook.
> "We may share information about you in anonymous and/or aggregated form with third parties for industry analysis, demographic profiling, research, analysis and other similar purposes."
If you think that savvy companies can't use other databases to aggregate user profiles and deanonymize data... well, you're the perfect user for Dreamlist!
EDIT: Or, as I found out by clicking on the parent's user handle, you actually founded Dreamlist. I might humbly suggest at this point, Diana, that you're open and forthright about the fact you sell data to other companies. Even if you're completely dutiful in anonymizing data, you have no control over what is done with the data once you sell it.
---
For what it's worth, I'm much more worried about the privacy implications of Dreamlist than Alexa. With Alexa, I know I'm giving access to my logged-in Amazon profile/account to anyone with access to my device. With Dreamlist, no one knows who my data is being sold to.
We went deeper than that, testing to make sure no data about the user leaks at any point even in the console, or caching, or any other section. External links go through one redirect page that removes source page information, so everything looks like it’s coming from the main site. If you have feedback, especially about privacy, please feel free to send it feedback@dreamlist.com - we push out changes and updates almost daily.
We noticed a well known billion valued startup ended up showing their employee emails in the network tab data streams of the browser console, because apparently they like to access people’s private content on occasion and their system leaves a trace of that that shows on every page visit. That’s why we also added a private memories and journal section for anyone on DreamList as well. Grandparents who are frequent users need to be able to save stories for loved ones, and we want them to have a place to do that that is private and ads free.
Always open to feedback. The site is bootstrapped and definitely looking for contributors.
Not really sure where you thought anyone was confused by a small box being a butler.
Not confused, surprised. A hallmark of a butler is discretion. I hope you didn’t read that I was contradicting you or disagreeing? “Don’t spoil the suprise by divulging the nature of the package to the intended recipient” is beyond Alexa’s programming. For a butler, it wouldn’t even be a checkbox option, it would go without saying.
I'm thinking back to when I was a child -- I wouldn't normally cry if a surprise was ruined. The ruining of a surprise would not have been a big deal. But I might have cried if I hadn't gotten what I'd hoped for.
Now, Google Maps has an Incognito mode, but now I know I must use it when buying surprise presents.
The problem is this interaction is impossible to anticipate, and makes me not want my preferences on communal devices at all.
I don't get the point of using a proprietary, crappy (in this case) implementation that gives an adversary an edge when a simple text file would do?
I imagine few users have both types of wishlists and want different deal notifications.
We just opened our Beta a week ago
If people are looking for an alternative, we'd love to hear your feedback
P.S: we have a private list feature ...
Edit: nm I had to be away from my phone for my watch to pick this up over my phone.
Voice control might be a need, Alexa voice control shouldn’t be.
Personally I have an Alexa but don't find it too appealing. I barely use it. My kids use it much more often. I don't worry about privacy. I trust Amazon (or Google/Apple/Microsoft) that non of the audio is saved or sent to the cloud unless the device hears the trigger word. Can someone hack it and listen to our interactions at home? I'm assuming it's possible but that's true for our phones too.
For the disabled, particularly blind people, it would be great to have interactive voice stuff if that whole ecosystem were really fleshed out. Some of this exists but a world of audio books, online banking, interaction with social media, all with interfaces optimized for voice use/audio listening would be great.
Interacting with a screen by having some software read it to you just seems incredibly clumsy.
Personally, I think the hands-off case for automotive use is dangerous. Talking on the phone or listening to email while driving is sketchy even though you're still gripping the steering wheel. AM/FM radio interfaces were perfected 75 years ago.
In order to really reach people with vision issues, it seems like places like Bank of America (just an example) need to do a good job of Alexa skills. Dunno how you deal with security.
As a side note, it's funny how absurd online banking websites are. It's a thing that would be well served by simple/secure pure text interfaces but that certainly isn't what you get.
The amount of cruft on the web just blows me away, whether it's a weather or real estate or recipe site. We're living in a world of shit.
While I agree physical and simple is best, I've also totaled a car by fussing with such a radio and driving. Safest is probably no radio and no distractions. Second best may be set and forget interfaces that don't allow changes while moving.
This is a technology site, the way these voice assistant works has been posted numerous times and is common knowledge at this point. They've been ripped apart by multiple security pros. Yet every thread we get unjustified replies like this. It is tiresome and frustrating.
But I'll post it once again:
- Wake phase detection is all handled locally (i.e. on device).
- It loops a continuous recording over itself. If no phase is detected within a few seconds the recording is permanently lost.
- We can see from data monitoring it isn't continuously transmitting (and that's also what the companies behind it claim).
- "It could be modified" is a red herring. You are already carrying ON YOUR PERSON an always connected microphone with not one by two layers of operating system on it (baseband + consumer OS).
It should not be popular to post "photographs can steal your soul"-levels of tech-spiracy on a site like this, but yet here we are again.
It's a microphone connected to the internet. If corporations and governments choose to use this variety of device nefariously, they won't be stopped. Many people are feel concerned when their society increasingly resembles East Germany.
So is a cellphone and they are way more ubiquitous
But I think you're tremendously overstating your certainty to contrast with people you're calling paranoid.
If lives depended on it, are you that sure you fully understand how things work? Are you that sure of the contrast you point out between Alexa and a smartphone?
I'm not questioning your opinions and facts; I'm urging you to examine your own feelings and motivations, which obviously only you can.
When people attack doubts in others as paranoia, well, it might be accurate. But strong emotions and especially anger on the subject tend to suggest the underlying issue is suppressing one's own doubts.
The general attitude of "we know how it works" always makes me think of the quote "Given enough eyeballs, all bugs are shallow" and OpenSSL.
My rule of thumb is, if something is technically feasible, if it's not possible to casually detect it, and there are likely no immediate, directly applied penalties for it, then it's unwise to bet against it.
Something I see people assert to comfort themselves is that companies care about reputation and therefore wouldn't do some thing. I think you have to have blinkers on and somehow repress all your experience working for corporations or consuming products made by them to think that way.
> As long as he gives me cheap same-day delivery, IDGAF.
It's disappointing that even when people know about the widespread harsh treatment of workers, as long as they get their cheap same day delivery, they don't care.
This title is inflammatory.
1 - That Alexa has access to information about any particular Amazon user? To me the registration process and features of the product make this extremely obvious, but maybe its not?
2 - That Alexa will send audio notifications related to the status of the account its linked to? This is the only thing that I feel is of any possible surprise. Most of the marketing around Alexa products show interactions initiated by the user.
3 - That 'private wish lists' aren't excluded from the full set of notifications? Amazon just calls them 'wish lists' and to me they are just cached shopping carts. I don't really see them as any more sensitive than any other information in the account.
If nothing else, giving the option to disable this on private lists would be nice.
Unless you explicitly share something, all of the information is protected equally except for credit card numbers and your password.
Like I mentioned above, if the author had a gift in their shopping cart or ‘save for later’ and Alexa notified on a price change, would they have a similar reaction?
It’s not a moot point now but either this is just a serendipitous occasion or somebody Amazon really listens, but I just opened up the app, went to manage lists, and there’s literally an option now to manage the list through Alexa or not.
These are different in that the person involved did not explicitly set them as private. They might feel annoyed, but would realize they made the mistake.
Let's take another example: harmful chemicals. Most people aren't aware that chemical X or Y is harmful until it becomes a scandal, at which point the companies switch to another that also hasn't been tested long term. In that case, like with privacy, I don't think the people are at fault. People assume that companies aren't going to abuse them.
That's why I don't agree with 'Obviously if you are sharing an account nothing is "private". Doesn't this go without saying?'. People have some expectations that sadly don't reflect reality, so in cases like that they need explanations.
If his wife logs in and opens up a private wishlist labeled "Liz Presents", she is choosing to spoil something for herself.
If the Alexa says you have a notification (with no more detail) and then immediately spills the beans, his wife did not choose to be spoiled.
So yes, it's very much not hyperbole to blame Alexa for spoiling this secret.
At the very least, the default should be "no notifications", and you could turn them on for the list if desired.
> As long as he gives me cheap same-day delivery, IDGAF.
for lower and lower quality of items, with less of a real selection (go look at electric kettles - there's 50 different brands - with weird names - but the kettles all almost look identical). Also the while prices creep up as any competition gets annihilated.
The high cost of cheap shipping
So the $29 kettle is $21. I've never bought a "used" item from Amazon that was unsatisfactory cause it was "used".