21 ms·
'Samsung itself is aware of these risks. In its privacy policy, the company warned customers to be aware that "if your spoken words include personal or other se
by sky_nox 7y ago
'Samsung itself is aware of these risks. In its privacy policy, the company warned customers to be aware that "if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition." The language reminded some of the George Orwell classic dystopian novel 1984.'
- IshKebab 7y agoThat quote doesn't show Samsung's thoughts on the risk of hacking at all, and it shouldn't remind anyone of 1984. It's just a statement of how all voice recognition currently works.
- serf 7y ago>It's just a statement of how all voice recognition currently works. Amazon has said on numerous occasions that no data transfer occurs without a trigger word hitting the mic -- a feature that was a main point when discussing the safety of having an always-on internet-connected mic in the house. As for whether or not they're telling the truth, I don't know; but trigger-words have always been a feature that Amazon loved mentioning from a security/privacy standpoint.
- penagwin 7y ago> As for whether or not they're telling the truth, I don't know; Luckily it's possible to check [0]! Although it gets a bit more complicated and can change, my understanding is that currently most people observe it increase it's network usage after it's trigger phrase, but not at other times (it uses the network for other stuff too, but audio data is typically rather large in comparison). [0] https://www.iot-tests.org/2017/06/careless-whisper-does-amazon-echo-send-data-in-silent-mode/ https://www.iot-tests.org/2017/06/careless-whisper-does-amaz... [1] 10.1007/s00779-018-1174-x <- Might want to use sci-hub
- celim307 7y agoThe pessimist in me think that a determined actor could simply capture non-trigger voice data offline, and bundle it with the rest of the traffic whenever the next trigger word occurs. But I am talking out my ass and have in no way verified any of this
- astazangasta 7y agoThis was my thought too; there doesn't seem to be a way to verify this isn't happening.
- smarkov 7y agoIf data is being buffered and only sent after the trigger words wouldn't the data transmitted vary depending on how much was said before the trigger word?
- mulmen 7y agoMaybe. All uploads could be padded with the maximum buffer size so you can't tell the difference. The buffer could flush only small amounts at a time. Some compression algorithm could be used that becomes more efficient with larger recordings. What you should be asking with any "smart" device is "can I prove this device will do no harm to me". Honestly I have never understood the value proposition of any smart device. Why would I want any of that functionality? Never once in my life have I ever wanted to talk to my TV. I'm beginning to (again) question the wisdom of carrying a smartphone.
- ColanR 7y agoIt does seem to me like Amazon worded that statement very carefully, and in a way that allowed for that kind of behavior to occur. Conversely, if they were not doing that kind of thing, they could have removed that ambiguity from what they said.
- sib 7y agoAlso see this Amazon patent related to intentionally removing PII from speech transmitted to the cloud. http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=HITOFF&d=PALL&p=1&u=%2Fnetahtml%2FPTO%2Fsrchnum.htm&r=1&f=G&l=50&s1=9922646.PN.&OS=PN/9922646&RS=PN/9922646 http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=H... In case the link doesn't work, it's US Patent 9922646.
- bduerst 7y agoDid you link the right patent? That claim is only for locating a user in a room based on multi-room voice input.
- sib 7y agoGrrr - wrong link: http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=HITOFF&p=1&u=%2Fnetahtml%2FPTO%2Fsearch-bool.html&r=11&f=G&l=50&co1=AND&d=PTXT&s1=blanksteen.INNM.&OS=IN/blanksteen&RS=IN/blanksteen http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO2&Sect2=H...
- lstamour 7y agoI’ve heard that the Echo’s mute button is a hardware off switch for the mic, though for obvious reasons you probably wouldn’t leave it on most of the time.
- IshKebab 7y agoYes of course. I don't get why that affects the privacy policy though. There are occasional false positives and you still might say something sensitive after the trigger word.
- mikeash 7y agoiOS can do voice recognition processing entirely locally for many languages. I’m sure the same is true for Android.
- gleenn 7y agoGoogle has made strides in local-only translation. I can't seem to find the Hacker News article but believe it was wired into the Google keyboard iirc.