Samsung Global Privacy Policy - SmartTV Supplement
samsung.com
samsung.com
Now it is fair to say that the attack I just described requires the ability to MitM the network and have physical access to the device, however, remember that these TV's use an IR remote & all an attacker needs is visual access to the TV. If it can be seen through a window it can be controlled through a window and these things typically don't require a password to modify the WiFi settings. Some smart TVs also have proxy settings which again, typically don't require a password to modify.
Given what I just covered, think hotel. From a risk perspective that's what I'd be most worried about. I wonder how many are installing smart TVs with voice recognition? For all other scenarios basically the situation in many cases on the ground is that you are secure because no one is targeting you. In the case of a hotel, someone could be targeting everyone. Such an attack could prove valuable, especially if done in executive suites near financial centers.
Most of the hotels I've been to have stripped-down TVs (special Samsung and Panasonic models seem to be the most common). That could change, of course.
I would love to see a TV vendor prosecuted for this.
In fact, one might say that email is more secure than normal mail, because normal mail doesn't have a password and is default delivered to a publicly accessible mailbox. If a neighbor wishes to invade your privacy via your email, how do they do so? Probably by entering your password somehow. If that person wants to steal your physical mail, how do they do so? By walking up to your mailbox when nobody is looking.
Also, email at least has a very plausible chance of being encrypted; even if you don't know what that means, your workplace may be doing it for you. But companies, including financial or accountancy firms, don't encrypt physical email to their customers.
I think most reasonable people have the belief that email is safer than mail, and in 2015 I think they might be right.
And even the definition of "objective" in "expectation to privacy" is what general society holds to be true -- it doesn't speak to demonstrating reality of privacy.
There has never, ever been any expectation set that internet email is private. There have been many examples in the broader media that show how one might compromise email. Also, you have no way to assess the quality of the email service provider, network provider, or client environment.
Postal mail is more secure for 99% of the public for several reasons, including:
- A paper envelope is tamper-evident. My dad used to correspond with radio operators in the Warsaw Pact... envelope tampering was trivial for me to detect as a 5-year old.
- Stolen mail is stolen. You don't get the message. Detecting a pattern of missing mail is pretty easy.
- If you're not a police organization, tracking postal mail metadata is risky. Bystanders will notice somebody rifling through a mailbox every day. There really isn't a way to surveil outbound letters.
- It's a serious felony to tamper with mail. Linking physical mail theft to a perpetrator is pretty straightforward. Also, Postal Inspectors take mail integrity very seriously, sometimes too seriously. With electronic crimes, you probably have a 1/100 chance of finding a cop who understands your complaint AND has the means to do anything about it.
- It's much easier to implement physical security practices/procedures that keep secrets transmitted by mail secret than via digital means.
When I send an email to somebody, I do expect that no human other than the recipient will read it, and that automated processes do not attempt to divulge meaning from its contents past that required for advertising (and that data is used for no reason other than advertising).
I expect that it might be read by the police with a warrant, as with anything else. I also expect that any post I send might be read by the police with a warrant - resealing an envelope is actually easy, and worst case scenario, they could simply use another envelope and copy the addresses and stamps, and I'd be none the wiser.
The technical ability to read my email has little/nothing to do with my expectation of privacy. Technically, someone could read all my mail with ease (it gets delivered to my apartment's hallway where anybody could pick it up), but I still expect that people will not do that. They could also read RF emissions from my apartment to figure out what I'm typing just now, and IIRC that's a violation of privacy.
Do you affirmatively know that every email that you've ever sent isn't an account managed by a third party (like an employer) whom the recipient has ceded (or shares) control of their mailbox to?
Any employer can trivially read email, and many do so routinely. Most people allow for the sharing of devices in the household... So the spouse and kids can probably access the computer pretty trivially. That's two trivial examples that doesn't involve spy stuff or conspiracy theory.
You cannot access postal mail without a warrant or physically stealing the mail. Once received, you can physically destroy or secure it.
They could also send my post to them off to a processor for whatever reason. When I give my personal details to my ISP, they could sell them to advertisers. I expect that they will not, and feel violated when they do.
> Any employer can trivially read email, and many do so routinely.
If I'm sending an email to a UK employee, they in fact cannot legally do so in the general case - doubly so if it's a personal email.
> So waving away and dismissing concerns about the vulnerability of email feels like the right thing.
No, but there's a point to be made that just because something is possible and easy does not mean it should be legal or even right, nor that people should expect it to happen. If it were something I really wanted kept secret, I'd encrypt it - but most things I email are, while not things I would necessarily want public, not life-destroyingly secret either.
I don't expect or want to be tracked everywhere I go in public either, but I don't wear a mask to ensure I can't be. On the other hand, perhaps I might want to do so in some circumstances because the stakes are higher.
Most normal people believe, intuitively, that email is private. You need to enter a username and password to send it, and you need to do the same at the other end to read it. Prima facie private, like physical mail.
Sure, you may believe the corporation providing your email service could look at your text, but a delivery company could do the same thing to your physical mail; it's just harder (but not impossible) to read physical mail without evidence of tampering.
WRT legal definitions, everything is a bit woolier. Case law sets precedent, and precedent can be based on circumstances in the past that were different than today. People using email used to be more technical, more aware of how insecure the whole thing actually is without a lot of effort. And service providers have a vested interest in disclaiming legal liability for breach of privacy; they'd much rather the public believe things are private, but not have any legal expectation of privacy. That way, they get to have their cake and eat it.
There will be a time when future generations laugh at our current popular scientific misconceptions, but until then, that counts as reasonable belief. We just don't have the benefit of retrospection to know which things are crazy ahead of time.
Also, I do believe that email should be private, but that is a separate discussion.
The original legal question is about wiretapping. Previous posters asserted that people think email is technically secure. My assertion is that someone with passing knowledge of the subject does not believe that to be true.
Of course there has.
I'm not sure why this was voted down... not only has the Supreme Court said repeatedly that there's no expectation of privacy since you're trusting the information to a third party... but email isn't even transmitted securely.
If anyone expects their email to be private (and isn't using PGP or something), they have a false expectation of privacy. It's unfortunate that's the case, but that is reality.
from here: https://www.samsung.com/uk/info/privacy-SmartTV.html
So, disable it. I don't understand everybody's fascination with voice recognition. I don't find it more convenient at all. I'd much rather just push a button. It's really not that complicated.
This option (to minimise data collection/retention) ought to be enshrined in law.
If you pay (or not) for a service, you should be able to get the service without the expectation of your personal and private data being harvested.
The voice recognition is done on remote servers, and they have no means of preventing you from saying something private when it is recording.
Amazon Echo uses on-device keyword spotting to detect the wake word. When Amazon Echo detects the wake word, Amazon Echo streams audio to the Cloud, including a fraction of a second of audio before the wake word.
http://www.amazon.com/gp/help/customer/display.html?nodeId=2...
Interesting that they are able to transmit audio-data that occurred prior to the wake word being said (in essence to transmit the wake word). Looks like Amazon is keen to redefine "collected" just like other groups are...
It's not "collected" since it only has 1 second of audio until it wakes up.
Unless you are talking about the half second before the trigger word? But even then - it only sends when triggered.
Then you are alone in this. Even amongst technological people, never mind the general public. This amount of time is perfectly reasonable.
> Once we allow those technicalities to slide, the truth is easier to bend and/or ignore.
No it doesn't. Slippery slope might be a valid argument in some places, but not here. You are overreacting.
> to prevent this sort of subtle-switcheroo.
There is no subtle switcheroo.
It's very very simple: It only sends audio when commanded to. That is the essence of the difference, and it's all that matters.
And don't tell me "next they'll send 1 hour of audio when triggered" because they won't. You are being ridiculous if you think that's where it's headed.
Taking outrageous positions like this just makes people ignore you.
> the trigger word (I feel dirty saying that phrase)
? Why? Does it have some special meaning I am not aware of?
While possible, this is not theoretically necessary, and I find this highly doubtful in practice.
What about the delay on each voice command as it pings the server? If it was generally the case that voice commands were sent remotely, I suggest usability would be 0.
There are many services that provide real time processing of large amounts of data on server cluster/farms, and more are coming. It is very much possible to perform large computations in almost real time in these situations, and you'd be surprised at how little latency people notice, particularly when there's no indication of what the actual number is.
I'm surprised to learn that people do use Siri in genuine situations, so thanks for your reply in that regard; although I still feel gratified that another commenter has the same experience that I do.
Judge the delay for yourself.
Relying on the internet for "real time" computation is a recipe for inconsistent behavior.
I agree the fascination may be excessive, but there are a few legitimate use cases where it's not obnoxious (anyone within hearing will likely end up listening to the TV anyway, so presumably you have their acceptance for noise in the first place) and actually useful, and searching for stuff to watch is one.
But I agree. I'd much rather have a dumb tv and upgrade my attached boxes.
So you trust the manafacturer/software provider of your attached box more than that of the TV?
What I don't like is paying for smart tv features that don't work or don't trust just to get a screen. Maybe the company that makes great screens make untrustable smart tv features, and maybe the open source smart tv of the future sits in a crappy screen.
More probably the smart tv features gets outdated before the screen.
starts playing 'Resident Evil'
Besides, when they can hack the database itself and get a list of what they know to be passwords, why wouldn't they just do that instead of hacking a bunch of voice snippets and combing through them hoping to maybe find where somebody said a password. It's stupid.
People can use the service and come to terms with that fact or they can not use it. If they choose not to use it, they need to live with the consequences of that decision. If it means they have no other way to access some service, then that's something they need to take into account. I can't think of any service in existence that can only be accessed by voice recognition instead of having an phone representative, physical branch, or other options. If you really, really need to access your bank account, there are plenty of options aside from speaking to your smart TV. Nobody is getting marginalized here.
Or you just pass the data to Siri or Cortana (or whatever microsoft is calling it). Protecting against hacking is defense in depth. If the database is well protected and monitored, attack the target that is not well protected and monitored.
If you have small children, it's incredibly handy. Even with Chrome, it's much easier to sneak in a quick click of a button & then say my query than to try to type it all out.
Here is the relevant part: "Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition."
This must be a data protection violation ?
"Your SmartTV is equipped with a camera that enables certain advanced features, including the ability to control and interact with your TV with gestures and to use facial recognition technology to authenticate your Samsung Account on your TV."
We've come so far since Orwell's "telescreen" in "1984".
"Big Brother is watching YOU."
"‘Smith!’ screamed the shrewish voice from the telescreen. ‘6079 Smith W.! Yes, YOU! Bend lower, please! You can do better than that. You’re not trying. Lower, please! THAT’S better, comrade. Now stand at ease, the whole squad, and watch me.’
A sudden hot sweat had broken out all over Winston’s body. His face remained completely inscrutable. Never show dismay! Never show resentment!"
*I pulled this number out of the air
[1] http://androidwidgetcenter.com/android-tips/how-to-use-offli...
When connected over wireless, something in the TVs networking stack crashes my entire wifi router too.
Some people have rooted them, which is what I was hoping for when I got it, but if you update to a new version and try to root it can brick.
Honestly, I think this conversation should be more about the right to control the devices we own more than just egregious privacy breaches. If we are to prevent such breaches from other manufacturers then what we need is the ability to control our devices. I have a quad core processor in my TV, but apparently if I don't want samsungs crappy proprietary OS and want to install Linux, too fucking bad for me. I think that's bullshit and needs to change.
I consider it a mistake purchase.
I agree, reading your entire comment, you probably should have researched it more if your intention was to replace the factory OS image with one of your own. But it happens to all of us; I have a useless Motorola phone sitting on my desk because I naively thought "it's Android, it must be hackable", and only discovered after I bought it that Motorola made the bootloader impossible to unlock.
I decided a while back that a TV should just be a dumb monitor, and whatever "smart" features I want it to have can be had via a set top box, home-built HTPC, or a streaming stick. So far I've been very happy with the Roku 3 combined with a home-built HTPC/PVR. If I decide I want to upgrade to bigger or better screen, I only have to replace that one component. Ditto for the "smart" side of things. I see so-called Smart TVs as the TV/VCR combo of the 90s: When one half inevitably fails, you have to throw out the whole thing.
The trend for Smart TVs these days is to leak data like a sieve. The small risk of vulnerabilities in e.g. a TV's HDMI layer being exploited is arguably a price worth paying for privacy.
The discussions around smart TV vulnerabilities is making me very pleased about that decision.
That doesn't really solve the problem that your TV could be relaying everything you say to a remote server, does it?
Nothing like downloading the facial recognition features of Carmen San Diego into all the hotel TV's in a country to see where she is staying.
License plate readers don't hold a candle to this. Now to check to see if every Samsung TV coming into the US has to go through 'special customs checking' ...
(Nuance/Apple Siri, Microsoft Cortana, Google Now, IBM Watson Speech, Amazon Echo, LG-Smart TV, etc.)
From a consumer perspective you want an offline speech product like Nuance Dragon NaturallySpeaking: http://en.wikipedia.org/wiki/Dragon_NaturallySpeaking (it's the same technology that powers Nuance cloud based products like Apple Siri, IBM Watson, etc.)
But, if anyone commenting had actually used one of the new samsung smart TV's with this feature, you'd see that this is being blown out of proportion.
The TV isn't even listening for a keyword. It's waiting for you to press a button on the remote. The microphone for voice control is actually in the remote itself.
Samsung Smart TV remote with Voice button: http://goo.gl/DkgWPb
I would caveat the above by saying that the TV may also have a microphone in it, because I have noticed that when you use the built-in skype app, the camera does a cool digital/zoom to highlight whoever is speaking, which it probably does either with a microphone array, or moving-lips detection in the camera. The camera, by the way, can be physically disabled when not in use, by pushing it into the TV.
The non-remote one does use a trigger word ("hi tv" by default) and it definitely does that processing locally (I know because i disconnected my TV from the internet and tried it). Basic commands ("channel up" etc) also worked. I don't know what else to try to figure out when it goes out to the internet. I'd also add that the camera/microphone have a very visible hardware off (which I keep off, because life is too much like 1984 already).
Again, this is a 2013 model.
People talking to control their tv's want to be able to iist talk. Thus, instead of training the software you offload that training to the cloud and massive computing to do it.
I agree that the tv setup could include a bit of voice recognition training. But then the TV only changes channels if Ann asks it to. Bob's out of luck, he has to use the remote.
But then again anything with an Internet connection and a mic (laptop, cell phone, etc.) is a potential spy device with the right malware installed.
Submitted: https://netzpolitik.org/2015/samsung-warnt-bitte-achten-sie-... which links to http://martingiesler.tumblr.com/post/110325577280/samsung-wa... which links to http://mostlysignssomeportents.tumblr.com/post/110300533107/... which links to http://boingboing.net/2015/02/06/samsung-watch-what-you-say-... which links to http://www.reddit.com/r/technology/comments/2uuvdz/samsung_s... which references https://www.samsung.com/uk/info/privacy-SmartTV.html
On the other hand, the HN rules suggest doing things like this if you want to cherry pick a certain aspect of a page...
Not ideal but doesn't strike me as a big risk