Company Says It Uses Your Phones Mic to Serve Ads for Facebook, Google, etc.
news.itsfoss.com
news.itsfoss.com
What I suspect is actually going on is the boring ol kind of location tracking and fingerprinting. Locations, searches, and call history. Metadata, in the language of surveillance law. Of course, the cruel joke of surveillance law[0] is that metadata is content: you can infer the content of a conversation from the circumstances of which it took place. Three-letter agencies rely on the fact that nobody understands this, and so do advertisers (of whom they pay money for data from).
[0] I'm resisting calling it the "holographic principle of surveillance" on principle.
https://kieranhealy.org/blog/archives/2013/06/09/using-metad...
Does that show up with the always-on "hey siri/google" listening?
Ultrasonic tracking has been a thing for a long time
https://www.zdnet.com/article/hundreds-of-apps-are-using-ult...
That pretty much killed this practice.
Frankly, the idea that no app or company is doing this or selling the data would require an enormous conspiracy of secret suppression. The argument that one can't easily hash compressed sound fragments in a way that matches for copyrighted music or generic advertising terms and send that data back linked to a location/ID is sort of laughable.
A team of CS engineers at NSA.
1-2 people in privileged positions either at the point of assembly/programming deployment to ensure the code is delivered. - for each company which is basically just alphabet, Samsung, and Apple or their chip providers which is about five companies.
This does not seem all that impractical - how many people are dumping firmware from in the wild consumer cellular devices and reverse engineering enough of the code to see if this functionality exists or not? Anyone with that skill is likely making a killing doing other work.
I suspect many types of technologies are starting to use voice for identification, demographics, emotional analysis, and the data is being saved and/or shared.
And lots of phone trees now require you to talk instead of using touchtone sounds.
Even better, lines that will not help you if they are not recorded where they ask for key information that can be used in any number of scenarios (age/birthday/address/full name) and then has their recording hacked. :chef's kiss:
The referenced articles are light on details and appear to be “he said she said they said” and pointing to the same archived blog post from CMG.
That being said, I see a rising popularity of Alexa all over my circle, so no high hopes. Even if I can battle my devices, I can’t battle my family, friends and neighbors from adding Amazon Echo devices everywhere and mindlessly talking to it all day.
Edit: redundancy and typo.
On Android I can toggle the camera and mic OS wide, and per app. When I'm not taking pictures or a call I turn them both off OS wide using the quick toggle buttons. On iOS I can only find options to disable them per app which doesn't give me as much confidence.
The odds are stacked against the attacker. Unless they can also figure out whether you're looking at the screen or not, they're rolling the dice every time they attempt a recording. As they make more recordings, the probability of being discovered approaches 100%.
These companies are most likely lying or exaggerating their capabilities. Since so many people believe in audio eavesdropping anyway, it's in their interest to make the buyers of their software believe they're much more powerful than they really are.
It's the same as how it's good for AI companies to talk about how AIs are just on the verge of ending the world and must be regulated at any cost - more people believing that what they're selling is absurdly powerful is good for sales.
Can you link to people who have checked?
I had a couple of the last BlackBerry phones, that ran Android. They came with this "DTEK" [1] app that monitored when apps accessed your phone's sensors. And I remember every time I checked it, the various social media apps had all been caught snooping something like hundreds of times a day. This was happening even when I didn't use the apps, so there definitely didn't seem to be any reason that "makes sense" to do it. Not sure if it was microphone, or maybe just location or something, but audio eavesdropping isn't really out-of-character based on that.
1: https://docs.blackberry.com/en/apps-for-android/dtek-by-blac...
https://crackberry.com/how-control-your-mobile-privacy-black...
They're sending pretty much everything BUT audio.
Main reason is that audio is just tremendously inefficient compared to other signals. It's large and expensive to store and process and doesn't really give you that many bytes of information you can't get elsewhere for how expensive it is to handle.
Could have a delay. Could only work when physically moving, indicating activity. Could only be activated for some user profiles based on usage patterns. Could only activate for device owner's voice, like the voice assistants.
I used to think audio would be prohibitively expensive for Facebook to eavesdrop. But they could easily sample at random, compute it on-device, then only send keyword hashes. I think it's much more technically feasible than you're giving it credit.
I agree they probably aren't. Most likely, they predict using their other spying, then people notice frequency illusion/coincidence. But I find it odd nobody's checked.
I'd assume that at major social media and software companies, this data from individual devices is accessible in almost real time, feeding a dashboard of information that only top executives can secretly monitor world-wide conversations and user activity for people that have their specific devices.
I'd also assume that this method of bootleg monitoring has been in play legally and illegally for some time now... It's far too tempting to company execs and CEOs to not get hooked on the god complex of having access to this level of data... If you think about it, imagine being able to access any photos and conversations from anyone on the planet any time you want...
Congress does nothing about it because many of them are afraid it will destroy the economy and upset the wealthy backers to these companies that fund all of them. One day long into the future, there may be a low-key class action settlement that won't change a damn thing, and lawyers will sweep up most of the paltry settlement money.
We pay thousands of dollars now for devices that spy on us, while they barely provide any means of opportunity and extra utility to us. Use black tape and cover your front camera, and leave devices at home sometimes... We're really defenseless against corporate greed and corruption though, watch what you say around tech devices now more than ever.
"Our technology is on the cutting edge of voice data processing. We can identify buyers based on casual conversations in real time. It may seem like black magic, but it's not-it's AI. The growing ability to access microphone data on devices like smartphones and tablets enables our technology partner to aggregate and analyze voice data during pre-purchase conversations."
IMO, the smoking gun here is their partner ingesting and analyzing the voice data.
Some reporter would have to dig deeper to get to the bottom of it.
The key issue here is that we don't own our phones. We have little control over what those apps do and often apps are hidden and can't be uninstalled.
Last occurrence, 6 months or so ago, of that happening was when one of my colleagues discussed vacation in a specific place I absolutely have no interest in visiting, so I was 100% sure I didn't google it or discussed it online. Surprisingly, the next day, I was swamped with booking.com and airbnb deals for stays in that specific area.
I emphasize next day occurrences intentionally, as I am under impression that it takes some time for them to process the data and supply the results to the marketeers.
You only notice these ads when it matches what you spoke about.
Discussion: https://news.ycombinator.com/item?id=41404229
Do they still do that?
I assume that the feature was not worth privacy implications and potential fallout.
But why would a company say they do this? It's because so many people believe that this happens anyway that there's next to no cost to them in saying it - and the buyers for this kind of technology think of this as a good thing.
It might be fake, but people being scared of your powerful technology is good for sales.
AI labs do the same thing by actively courting fearmongering.
But I guess your general point is still accurate; you can repeatedly break laws as long as your privacy policy says so. (no AG is going to put you in jail or something to _physically_ stop you).
To me this seems:
1. not mobile specific; 2. totally plausible; 3. despicable in many ways, but “opt-in” makes me think of (a) masterfully crafted fine print in some Terms of Service that would acknowledge the collection of audio, and (b) that this has nothing to do with a phone mic maliciously being turned on without the user noticing, but it’s rather recording from a mic intentionally activated by the user during the normal interaction with an app or web site.
Our TVs (2020-era Vizio and 2018-era Samsung) are on a separate VLAN for home automation control, and are otherwise blocked from the internet¹. Additionally, they have the various "content intelligence" features disabled...just in case.
We also have a few Nest devices (the 1st gen wired Hello doorbell cam, The Nest/Yale deadbolt, a 2nd gen thermostat, and some Nest Protects) that are normally similarly segmented, though the Hello is allowed to communicate to the necessary domains for video streaming and PubSub notifications.
On August 1, while on a neighborhood walk without any electronic devices, we formulated the plan: every day, we'd find a reason to discuss mulch² in the presence of various devices in our home. What color of mulch we think would look best around various trees. The virtues of recycled rubber as a mulch substitute. The drainage issues it causes. And so on.
We committed to never searching for mulch online (to hide from the ever-present surveillance online), never discussing it with anyone (to avoid social network effects), never buying it (no data broker can hoover up mulch purchases), not dwelling on any social media post about mulch (analytics, man, it's crazy what that bit of metadata can do)...not even hanging around the garden department of local stores (gotta avoid bluetooth/BLE/wifi tracking).
But I DID disable the DNS blocklists (much to our browsing frustration). And while the smart home stuff remained on its own VLAN, I allowed it otherwise unfettered access to the internet during the month of August.
Since the experiment began, we've seen the net sum of zero (0) targeted ads about mulch. No banners, no interstitial social media posts, no phone calls, no flyers in the mailbox. Nothing.
I really don't believe that our devices are eavesdropping on us, but in the interest of science, the experiment continues for another month.³
---
1) Yes, I recognize that Sidewalk/ethernet-over-HDMI/hard-coded DNS/etc is a purported "thing", but I don't believe it's likely. I'm controlling for this during the month of September by re-enabling the filtering mentioned at the start; if our TVs are committed to exfiltrating surveillance data.
2) We've not really been discussing mulch. I'm using that as a proxy here, because all of the internet is a series of tubes that lead to advertising networks. But we did choose a unique topic of conversation that would be relevant to our demographics, geographical location, and season, and meaningful to advertisers.
3) On September 1, I re-enabled all the blocklists and VLAN network filters/blackholes. But we continue to discuss, er, mulch. Like I said, if our stuff really really wants to phone the mothership to have Big Mulch pay us a visit, there are supposed to be ways for them to do that. Right?
___
EDIT: The topic we chose is also something that's not typically discussed in our social network, nor our kids' social networks. I will say that it's related to a profitable market, and we're in the target demographic, but we did our best to identify a market that we didn't have in common with our social groups.
https://www.youtube.com/live/zBnDWSvaQ1I?si=GTF9CIe8wsqpDHet
Is this video bullshit? It seems like bullshit.