I read: "Our cloud servers can hear you, no matter what."
It's a killer idea. It's too bad privacy concerns might lead it to an early grave.
I read: "Our cloud servers can hear you, no matter what."
It's a killer idea. It's too bad privacy concerns might lead it to an early grave.
You people completely ignore the mode of operation and start making idiotic claims about "well NSA!"
In this case, as the website makes clear, you have to say the word "Alexa" for it to start listening. If you had been paying attention to the mobile scene even a little bit you'd know that this is on-chip listening for the term, rather than in the cloud.
So, no, you're in fact wrong. Nothing will be transmitted to the cloud unless it is the word "Alexa" or sounds similar enough to the term.
For example the idea that there's a debug mode that dumps the whole audio stream for troubleshooting isn't exactly tinfoil-hat paranoia.
Yes the original post is making an assumption, but you are as well.
You can't be certain that there's no way to activate it remotely without you knowing. Seven mikes in your lounge is an attractive nuisance.
I bet that market will be huge, eventually.
Ditto with every electronic device with a microphone: Smartphones, tablets, laptops, home phones, bluetooth in your car, Microsoft's Kinect, baby monitors, etc.
And while we're on an NSA paranoia trip, let's also remember that if you bounce a laser off of one of your windows it will allow them to pick up sound from within, plus signal leakage via the electrical grid, and of course unless you're in a faraday cage tons of EM leakage from everything you use.
While there's a lot of truth to this, that is no reason to go even further down that road. If it's wrong for laptops to be used to eavesdrop then it's insanity to install a seven-microphone listening station in your lounge.
"paranoia trip" is a rather condescending and dismissive way to refer to matters of documented fact, e.g. http://news.yahoo.com/yikes-nsa-turn-iphone-camera-mic-witho....
That means that it is ALWAYS listening. It needs to listen for that trigger word at all times.
Most of the time, it is not paying attention - the chip that is processing the sound is looking for the ONE word that will activate it. That passive audio processing is happening locally on a chip that is dedicated to the task. Once activated - the expensive processing happens and the sound gets processed, converted to text, sent to the cloud.
Same shit with cellphones, I have to admit.
"It could be an update check, or it could be the transmission of a new voice fingerprint."
Incorrect. The device is always listening, waiting for you to say "Alexa" so that it can start acting upon your commands.
I'd take Amazon's claim that no data is transmitted or stored without the wake word "Alexa" purely at face value. There have been enough examples of devices and corporations collecting/sending data they weren't meant to in the past few years for us to deny any new closed-source device the benefit of doubt.
So no, this isn't "pathetic baseless fear mongering".
You say "incorrect" then re-phase exactly what I said in a different way but retain exactly the same meaning.
The detection of the key word is on-chip. That's all that matters. Until the chip signals that it was spoken nothing is transmitted.
> So no, this isn't "pathetic baseless fear mongering".
Sure it is. If you know that on-chip keyword detection is a "thing" (which you do by your own admission) then you know also that claiming that everything you say in a room is sent to the cloud is entirely "pathetic baseless fear mongering."
You fully admit you know that that isn't the case here, but yet continue on like it /could/ be the case. Pathetic.
Amazon publishes the leadership principles that they demand their employees aspire to: http://www.amazon.com/Values-Careers-Homepage/b?node=2393650...
Look over those for a moment. Assume for the moment that Amazon engineers and their management take them seriously.
When Amazon employees working on this project raised concerns about privacy, do you think that they were berated? Or do you think that they were heard out? The sort of attitude that you have towards these concerns is exactly what so many people fear. It is part of the reason those guideline principles were created.
But it's not open source. Therefore it's technically possible that Echo waits until you make a request, and then bursts a transcript of everything ELSE you've said, as well. Or maybe the device only does that if Amazon receives a valid Search Warrant, and they flag your device to enter "transcript mode." Or even "live, continuous broadcast."
People have a right to be concerned about their privacy. They have a right to ask questions. They have a right to boycott a product unless they feel satisfied their concerns are addressed. They have a right to worry that their government (maybe not even the US) could force Amazon to violate their privacy.
You calling them "pathetic" is not remotely constructive. You don't share their concerns, is all.
Both sides loudly proclaim the foolishness of the other without ever having an opportunity to establish some reasonable grounds on which an actual discussion could proceed.
-- Mark Twain
Pro-tip, when people make such outlandish comments and call people idiots en-masse, (which I am amazed hasn't been flagged away), just ignore them. :-)
...but I feel like it's an important topic, and this conversation thread was ALMOST worth trying to redeem... I thought I could maybe shine a bit of light where there was a lot of heat...
But yeah, I hear ya.
We assume either of 2 engineering designs:
(#1) the trigger word "Alexa" is detected within an embedded chip. The DSP (digital signal processing) intelligence for analyzing sound waveforms is inside the device. Therefore, the words spoken after "Alexa" are then sent to the cloud.
(#2) the trigger word "Alexa" (and/or other words) are detected remotely via cloud computers. There is no "smart" DSP chip within the Echo device. That means that the device must send a constant 24/7 stream of digital waveforms to the cloud.
If we continue on the #2 scenario, we can guesstimate what data transfer volumes would look like. To be conservative, we use 8kHz 8-bit audio as the parameters which is telephone quality. (Reliable voice recognition probably requires inputs with greater audio fidelity e.g. 16-bit 32kHz but we'll keep the 8kHz-8bit as a possible lower bound.)
Using 8kHz-8bit, it means that the device would have to stream 691 megabytes a day which leads to 20.7 gigabytes a month. Likewise on the back end, the amazon infrastructure would have to scale up to constantly analyze millions of parallel 24/7 digital waveforms. The amazon datacenters would be burning up terawatts of electricity to ignore the 99.99% of digital waveforms that is not the word "Alexa".
So, are there any consumer devices out there surreptitiously uploading 691 megabytes of digital waveforms (or any data) every single day? Is it realistic that Amazon would engineer the product to work like this?
I have a router that has a fallback option to a cellular connection in case my cable is disrupted. I and others would hate to get a surprise bill from Verizon/AT&T for going over my 2GB/month transfer limit if the amazon device was designed via scenario #2.
EDIT TO ADD scenario #3:
(#3) there are unpublicized/secret list of words in addition to the documented "Alexa" within the embedded chip's "vocabulary". Such words might be "vacation" and "book" and depending on the subsequent words sent to the cloud, you'd see ads for suntan lotion or Stephen King novels on your next visit to amazon.com. The chip's vocabulary may also include listening for transient sounds like dog barks or sneezes. You'd then get ads for dog food and cold medicine. In this scenario, a constant digital waveform is not uploaded 24/7 but extra trigger keywords unknown to the consumer causes more data to be sent than he/she agreed to.
You think the ISP's are cheesed off at Netflix? You haven't seen anything yet. The screaming from a non-trivial portion of their customers suddenly uploading multiple gigabytes of data per day would be deafening.
Sarcasm aside, anyone who thinks that this is seriously some kind of government listening device needs to up their medication. The number of insane assumption that have to be made for this to be plausible are:
* This is a listening device, live transmitting everything you say, when it would be more economical to listen for a codeword on chip. (Amazon is wasting money because they are not a corporate enterprise, and we all know how much companies love spending money they don't need to)
* That the data being transmitted is being stored for long term periods of time (Amazon is wasting money on storage when it makes more sense to just process commands)
* That that literally nobody actually notices the data stream going to Amazon servers when not in active use. (Not bloody likely)
* That ISPs will not flip their collective shit at the data usage should this catch on (Hello? Netflix? And that's a company whose business is transmitting large quantities of hard to compress data.)
* That customers won't notice this data usage when their next bill comes in or when their shitty connections get saturated by the upstream
* That the sorry state of connectivity in the USA (especially with regard to upload/download asymmetry) doesn't render the entire exercise meaningless from a surveillance standpoint even if we ignore every other point above
* That the outrage angle once these things that are never noticed are noticed wouldn't be played up in the media
Fucking. Seriously?
If I were a high level NSA guy, and this was the plan that was brought before me? I'd fire the guy for rank incompetence.
You present a scenario that I certainly did not imply, namely that Echo must be performing voice recognition in the cloud. Also, you make it out as though that is the conceivable alternative possible to on-chip voice recognition, from a privacy point of view.
Let me present another scenario to you - Echo keeps "listening" to all our conversations - on-chip of course - but creates additional metadata that is stored locally and uploaded to Amazon servers periodically.
What might theis metadata be?
- Audio streams that were close enough to Echo's threshold for "Alexa", but not quite, thus got rejected (perhaps some of them were falsely rejected, so let's keep a copy to feed our algorithm).
- Data on how often Echo heard voices in the house, from which rooms and at which times. Perhaps Amazon would like to know when a household wakes up, when it likes to listen to music or when to order groceries. Why should Google Now have all the fun?
I could give many more scenarious why Echo might want to retain some data from ambient conversations, so as to make itself more "useful". It needn't store the entire audio stream in these cases, but just metadata or logs.
Such a scenario falls outside your 1 vs. 2 design options; is plausible; useful; and fairly easy to program too. I'm sure there will be many others like that.
My point is - don't implictly trust a closed-source device that is inside your house and always listening in all directions. If Amazon were so careful about the Echo user's privacy, wouldn't they have mentioned the word at least once in the entire page? So let's not rush to give them a free pass till we know they even want it, much less earn it.
P.S. My profile says I'm a "recovering" engineer, not a "recording" one :)
Yes, I went back and added scenario #3... apparently at the same time you typed your reply. I think my scenario #3 is similar in spirit to what you're warning people about.
>P.S. My profile says I'm a "recovering" engineer, not a "recording" one :)
I have several browser tabs on music recording and I definitely had a dyslexic moment there.
People carry around a GPS tracking device with a mic and camera built-in. They use it to post their entire lives on social networks. And they're worried about privacy.
Hilarious.
There's an "always listening" feature, but this is off by default and only works when you are plugged into external power.
"Yes, it's possible the technology respects your privacy."
If you can suggest that Amazon Echo is potentially listening and transmitting the data to Amazon even when you don't explicitly say anything, the same can be said of Apple and Siri.
I take your meaning, in the sense that there's no inherent reason to trust one but not the other; but I think that it's fair to say that there's a big difference between:
Hey, wouldn't it be handy for our users if we started storing and pre-processing audio *before* hearing 'Alexa', so that we're ready to respond instantly? Let's quietly take down the text that says that we don't do that.
(which is a plausible reasoning process somewhere down the line) on the one (Echo) hand, and Hey, wouldn't it be a good idea if we ignored our users' explicit election to turn off a feature?
on the other (Siri) hand.i think people who are worried about privacy are not the people who are broadcasting their entire lives on social networks
I think that's a fairly naive point of view. Consider the simple fact that these devices are not to be used in isolation - e.g. you come to someone's home, etc. If you think this is too alarmist a mindset, maybe you'll remember how quite a few folk were outraged about facebook's new app which was to actively listen via your mobile's mic (so it can e.g. recognize music and add "while listening/watching" etc. info to status updates and so on.)
The problem in that case was not (just) the actively-listening part ("don't use it if you don't like it"), but rather that people (in)voluntarily become the dreaded dragnet surveillance infrastructure.
"Such future hope for decentralization." Ha! :)
Not everyone has the same level of concern over "priacy" that you do, deal with it. It's 2014, everything is being recorded now and will be even more so in the future.
Because they are not psycopaths.
well, generally speaking.
I don't let people eat poisoned food because they didn't know it was poisoned.
You'd resent me if I let you do that, wouldn't you?
Now if you turned to me and said "I don't believe you." Should I forcibly stop you?b If you turned to me and said "I know", what then?
Yes, people carry smartphones, use social networks. However that doesn't automatically disallow them from worrying about privacy, as they simply don't have an option. And no, sometimes not using a smartphone or a social network is not an option for a lot of people.
What they should do is advocate for privacy and try to change the situation.
Anyone who elects to put their personal information in a public forum or any kind has willingly surrendered that information. They made a choice to make private information public.
How then, can they be concerned about privacy?
I CHOOSE what to share on a social network. Devices spying on me rob me of that choice and my ability of filtering what public knows about me.
>No, what I'm saying is, what you choose to share is public. People share so much every day, nobody needs to spy on you at all. Everyone thinks the govt./bigco is out to get them. If they are, they don't even need to do any actual work, people give the information away hand over fist. [1]
Perhaps I want to be in charge of what can and can't be known about my personal life. I know, a radical thought... Maybe I want other people to know some things and not others. Why so many people seem OK with notion of corporations doing whatever they want with the data they collect without accountability?
They even blame the victims: "You bought a device with the things that 99% of devices in that category bring and can be used to collect information about you. So it's your fault, you could have bought that very difficult to get (or obsolete) device that doesn't have them, or none at all. Of course, neither corporations nor security agencies can be blamed for their sociopathic behaviour. It surely has something to do with business or security that's entirely reasonable even though they kept it in secret."
Everyone thinks the govt./bigco is out to get them. If they are, they don't even need to do any actual work, people give the information away hand over fist.
I care about the content of my private communications w/ other people. Including in-person conversations.
> I care about the content of my private communications w/ other people. Including in-person conversations.
A widely accepted security fundamental is that metadata, such as where, when, and with whom you interact, is as valuable as the content of those communications. People in the surveillance business (from security agencies to businesses who track users) value metadata for a reason.
Think about it this way: If you wanted to spy on someone what would be more valuable?: Recording everywhere they go and everyone they talk to, or recording the content of those communications?
Knowing I talk to Vendor X is worthless because soooooooooo many people talk to Vendor X. Knowing I'm buying 1000Y from X is more useful, eh?
I joke! In all seriousness, did you find your concentration improved as you didn't feel the desire to constantly check for text messages or emails?
Then I was sitting down reading a book (Speaker for the Dead by Orson Scott Card) and realised I'd blown 4 hours on it rather than doing any work. Rushed and grabbed the laptop and nothing was broken, on fire and no one had emailed me. Then I did a two hour coding binge. Did more on that day than any other and it has just got better and better.
Concentration has improved as has tolerance and patience. I also read a lot more because I have the time to.
I'm only posting on here because I'm waiting for compile cycles :)
Granted - then of course you can have the argument that it's always recording, and then only sending data at the opportune time so that it's a little bit more hidden. And to that - I'd just say you can keep track of how much data should be being sent for the average command.
I don't think i'll buy one because I have Siri in my pocket at all times, but these privacy concerns aren't absolute truths. They only matter to you because you're sensitive to it.
In this case it wasn't even the NSA I was thinking about, rather Amazon themselves.
"Hey, I'm heading to the grocery store, do you need anything?"
"Yeah, get some milk?"
<user requires milk approximately every 4 days, enter "send Amazon Fresh promo e-mail" event for 3.5 days from now>
Nothing will be transmitted to the cloud unless it is the word "Alexa" or sounds similar enough to the term.
You don't know that. This is not going to be a piece of open source software you can evaluate. It's Amazon's literal black box to do with what they wish.
Granted, being able to audit this directly ourselves instead of observing it in other ways would be nice.
Getting really tired of HN stating obvious paranoia instead of talking about innovation these days. Yes, I get that privacy concerns exist, and this should always be kept in mind. But when more than 90% of the comments are about that, and circulating on completely theoretical claims, we've lost all value in the conversation.
My own take, which is either naive or mercilessly pragmatic depending on how you look at it, is that it's going to be a lot more productive to start thinking about how to protect privacy -- and, bluntly, what tradeoffs we're comfortable making as a society, which may not mean "share nothing unless explicitly told otherwise" -- in an always-on, always-connected world where networking will almost certainly become so pervasive that we largely stop even thinking about "the network."
> In this case, as the website makes clear, you have to say the word "Alexa" for it to start listening.
In order for it to hear the key word 'Alexa', it has to be always listening. They're just saying that they promise not to process the audio any further until they hear Alexa. Of course the obvious question is 'Does this promise apply for every situation?' What happens when Amazon gets served with a request to procure data from a user? Do they state this in the terms and conditions or in their privacy policy?
> or forcing them in peoples' homes.
Hence my argument for holding off from buying this and other devices like it.
https://news.ycombinator.com/item?id=8545144
There's always a guy on HN who wants to warn everyone like we're all a bunch of idiots.
It's ok to be paranoid but we should file it under an FAQ.
Our time is probably better spent discussing the value of the product itself. Hopefully, we get to that today.
Now would it be possible not to turn every post like this into an NSA warning? I'll make my own choices from here.
Sure, right after the need for an NSA warning on all of these things stops being necessary.
I don't see much difference between calling someone an "idiot", and calling them "paranoid" and dismissing their concerns to an FAQ.
> Our time is probably better spent discussing the value of the product itself.
Confidentiality has a large impact on the product's value, at least for many people. I don't see them as independent issues. If you feel, like many, that confidentiality is necessary to its value then the focus of the discussion makes sense (if it wasn't so redundant).
I know; sorry I didn't write more clearly. I meant that them calling you "idiot" and you calling them "paranoid" is roughly equivalent.
Hmmm ... that's not what I see above.
Generally I can understand frustration with any issue getting too much attention and drowning out others.
> it's my choice to decide to allow Google or Apple, for example, to get my data.
It's not your choice really. It's hard to function in this society otherwise, and I don't just mean having phone service or traveling. For example, my electricity vendor insisted on installing a 'smart meter', which allows them to record what and when electrical devices are used, giving them a good view of my activities in the privacy of my home. My choice was to let them install it, get my own generator, or go without electricity.
Did you get the part where there's an entirely different group of people who get tired of listening to you whine about it? I simply want to discuss the product itself.
You say that like the thing people are concerned about isn't possible.
That said, it's ignorant to blindly trust or blindly distrust anything. I believe the rational concern is not what it does now, or what Amazon intends it to do, but what it could be updated or hacked to do. Hence the "can hear," not "will hear" present even in my joking.
I'm making a deliberate choice to ignore your insulting language and look for the reasoning behind it, but you could stand to make it a little easier to do so. Let's be gently rational. Something about flies, honey, and vinegar.
http://mediabuzz.monster.com/benefits/articles/1288-google-s...
1) Its quite possible for a firmware glitch to "accidentally" leave it on.
2) Given I interact with Amazon's APIs enough to know they have "intermittent" issues that are quite hilarious, I fully expect #1 to happen at some point.
It is not at all unreasonable to say "Man, that functionality sounds a lot like spying. I sure hope that nobody roots this device."
Are you 100% sure (beyond some marketing copy on a website) that this is purely on-chip voice recognition? That this chip's firmware isn't reprogrammable? That it can't decide to, once activate on-chip once, stay on continuously?
You can't. Unless the hardware and software was open-source, and then was verified on-site, you can't. That's the problem with these kind of things.
And yes, we have the same problem with cellphones, laptops, tablets, soon cars, and everything else; that doesn't somehow magically make this any better.
Also, please stop saying "pathetic". It conjures to mind some jerk swirling cheap booze in a glass saying "mmm yes how pathetic the plebes" and then waiting for their next r/atheists post to get upvoted. You just end up sounding like a pompous ass.
The user has no way of knowing how that data may or may not be used.
The level to which the readership of HN abandons all pretense of critical and rational thought when a surveillance angle on a story presents itself is downright frightening.
https://www.qualcomm.com/news/onq/2013/02/20/snapdragon-wake...
cf. Stuxnet, BadUSB. There may not be a remote exploit for these chips yet, but I will bet my paycheck that intelligence agencies somewhere are working on doing so.
I'm not sure what protections you would have against a secret court order making the device always listen (via an OTA update) for select individuals, but you can at least check that they don't have such monitoring enabled for most devices.
That's what it's doing.
http://www.george-orwell.org/1984/0.html quote: There was of course no way of knowing whether you were being watched at any given moment. How often, or on what system, the Thought Police plugged in on any individual wire was guesswork. It was even conceivable that they watched everybody all the time. But at any rate they could plug in your wire whenever they wanted to. You had to live -- did live, from habit that became instinct -- in the assumption that every sound you made was overheard, and, except in darkness, every movement scrutinized.
To me, everything these big companies do is just a play to get information on people. Putting the kinnect in my living room and always have the mic on and it connected to my cable television and my internet, and constantly listening even when the xbox is off is freaky; just like this new echo. It's scary, but I bet personal recognition features are coming to this echo soon. Also, I can imagine being like, echo order me some stuff off of amazon, and then magically it appears from a drone in the sky.
In all seriousness, with Wikipedia being 22GB in textual state, it should be possible to build an offline system (that perhaps syncs online for news).
This is obviously not apparent in the HN/tech worlds, but the unfortunate perception I get is that no one really cares about their online privacy (unless it comes to their finances). When I talk to my non-techy friends, most say the cliches like, "I'm not doing anything wrong, so have nothing to hide". Therefore the reason governments can get away with forcing tech companies to give up data, is because the people don't really care, or believe the bullshit in the media about stopping terrorists, and tolerate it.
Now, we should not necessarily refuse to develop an idea because it could be abused, but we should always keep abuse in mind. Nearly everything can be abused, if only as a bludgeon, so obviously we need to have a certain level of tolerance for potential abuse. However it would be negligent to not consider the full range of ways something could be abused.
I strongly believe that engineers have an obligation to always consider and discuss the ethics of what they are building.
Even if you don't give a shit about ethics (I know many engineers don't), you must realize that many potential consumers will be concerned. Considering these possibilities is therefore just good business sense.