Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> With enhanced noise cancellation, Echo can hear you ask a question even while it's playing music.

I read: "Our cloud servers can hear you, no matter what."

It's a killer idea. It's too bad privacy concerns might lead it to an early grave.



I grow tired of this pathetic baseless fear mongering every single time anything is posted with voice control.

You people completely ignore the mode of operation and start making idiotic claims about "well NSA!"

In this case, as the website makes clear, you have to say the word "Alexa" for it to start listening. If you had been paying attention to the mobile scene even a little bit you'd know that this is on-chip listening for the term, rather than in the cloud.

So, no, you're in fact wrong. Nothing will be transmitted to the cloud unless it is the word "Alexa" or sounds similar enough to the term.


> you have to say the word "Alexa" for it to start listening

Incorrect. The device is always listening, waiting for you to say "Alexa" so that it can start acting upon your commands.

I'd take Amazon's claim that no data is transmitted or stored without the wake word "Alexa" purely at face value. There have been enough examples of devices and corporations collecting/sending data they weren't meant to in the past few years for us to deny any new closed-source device the benefit of doubt.

So no, this isn't "pathetic baseless fear mongering".


If you have a smartphone with Siri or the equiv app on it (Android, Windows) your device is already 'always listening.' I fail to see the difference.

People carry around a GPS tracking device with a mic and camera built-in. They use it to post their entire lives on social networks. And they're worried about privacy.

Hilarious.


> People carry around a GPS tracking device with a mic and camera built-in. They use it to post their entire lives on social networks. And they're worried about privacy.

i think people who are worried about privacy are not the people who are broadcasting their entire lives on social networks


You are correct. And those few people NOT having their lives online are decidedly not the target audience to begin with.


By that argument, those people won't buy the Amazon Echo either, so what's the problem?


> so what's the problem?

I think that's a fairly naive point of view. Consider the simple fact that these devices are not to be used in isolation - e.g. you come to someone's home, etc. If you think this is too alarmist a mindset, maybe you'll remember how quite a few folk were outraged about facebook's new app which was to actively listen via your mobile's mic (so it can e.g. recognize music and add "while listening/watching" etc. info to status updates and so on.)

The problem in that case was not (just) the actively-listening part ("don't use it if you don't like it"), but rather that people (in)voluntarily become the dreaded dragnet surveillance infrastructure.

"Such future hope for decentralization." Ha! :)


And this is also true for cellphones. Siri is always listening for you to say her name, which means that anyone you talk to with an iphone is always recording.

Not everyone has the same level of concern over "priacy" that you do, deal with it. It's 2014, everything is being recorded now and will be even more so in the future.


If you don't trust your friends, there are much worse ways they could betray you.


The people who don't broadcast their lives on social media are also concerned about what happens to the people who do.

Because they are not psycopaths.

well, generally speaking.


Converting other people to your religion "because you care". How nice of you.


Well as a very simple example:

I don't let people eat poisoned food because they didn't know it was poisoned.

You'd resent me if I let you do that, wouldn't you?

Now if you turned to me and said "I don't believe you." Should I forcibly stop you?b If you turned to me and said "I know", what then?


No, Siri only takes commands when you activate it.

There's an "always listening" feature, but this is off by default and only works when you are plugged into external power.


Someone else said this:

"Yes, it's possible the technology respects your privacy."

If you can suggest that Amazon Echo is potentially listening and transmitting the data to Amazon even when you don't explicitly say anything, the same can be said of Apple and Siri.


How do you know that it's actually off?


> How do you know that it's actually off?

I take your meaning, in the sense that there's no inherent reason to trust one but not the other; but I think that it's fair to say that there's a big difference between:

    Hey, wouldn't it be handy for our users if we started storing and pre-processing audio *before* hearing 'Alexa', so that we're ready to respond instantly?  Let's quietly take down the text that says that we don't do that.
(which is a plausible reasoning process somewhere down the line) on the one (Echo) hand, and

    Hey, wouldn't it be a good idea if we ignored our users' explicit election to turn off a feature?
on the other (Siri) hand.


Unless you expect random or targeted surveillance, if it generally listened and sent packets all the time back to Apple, even if you didn't tell it to, that someone would have discovered this by now.


Not everyone is like that. I personally have a build of Android with most of Google stripped out and the rest semi-disabled and it should have a minimum amount of tracking. I also don't install social networking apps, or at least deny them access to my personal data on Android.

Yes, people carry smartphones, use social networks. However that doesn't automatically disallow them from worrying about privacy, as they simply don't have an option. And no, sometimes not using a smartphone or a social network is not an option for a lot of people.

What they should do is advocate for privacy and try to change the situation.


Maybe my point was unclear.

Anyone who elects to put their personal information in a public forum or any kind has willingly surrendered that information. They made a choice to make private information public.

How then, can they be concerned about privacy?


I think you're (either willfully or out of ignorance) ignoring the most imporant aspect of privacy: it's about CHOOSING what to share.

I CHOOSE what to share on a social network. Devices spying on me rob me of that choice and my ability of filtering what public knows about me.


No, I agree with you.

>No, what I'm saying is, what you choose to share is public. People share so much every day, nobody needs to spy on you at all. Everyone thinks the govt./bigco is out to get them. If they are, they don't even need to do any actual work, people give the information away hand over fist. [1]

[1]https://news.ycombinator.com/item?id=8570568


So, for you this is an all or nothing thing. If I made some things public through Facebook then I'm automatically OK with Echo possibly sending data to Amazon about the things I didn't want to make public?

Perhaps I want to be in charge of what can and can't be known about my personal life. I know, a radical thought... Maybe I want other people to know some things and not others. Why so many people seem OK with notion of corporations doing whatever they want with the data they collect without accountability?

They even blame the victims: "You bought a device with the things that 99% of devices in that category bring and can be used to collect information about you. So it's your fault, you could have bought that very difficult to get (or obsolete) device that doesn't have them, or none at all. Of course, neither corporations nor security agencies can be blamed for their sociopathic behaviour. It surely has something to do with business or security that's entirely reasonable even though they kept it in secret."


No, what I'm saying is, what you choose to share is public. People share so much every day, nobody needs to spy on you at all.

Everyone thinks the govt./bigco is out to get them. If they are, they don't even need to do any actual work, people give the information away hand over fist.


Exactly. I don't actually carry a phone these days and people think I'm crazy. Personally I just don't want to be available all the time but it has certain privacy advantages.


How do you possibly live?

I joke! In all seriousness, did you find your concentration improved as you didn't feel the desire to constantly check for text messages or emails?


Well I was in emotional, physical pain and panic like (I assume) a crack addict for a couple of weeks. It was horrid.

Then I was sitting down reading a book (Speaker for the Dead by Orson Scott Card) and realised I'd blown 4 hours on it rather than doing any work. Rushed and grabbed the laptop and nothing was broken, on fire and no one had emailed me. Then I did a two hour coding binge. Did more on that day than any other and it has just got better and better.

Concentration has improved as has tolerance and patience. I also read a lot more because I have the time to.

I'm only posting on here because I'm waiting for compile cycles :)


I don't care about my location information, I don't use social networks.

I care about the content of my private communications w/ other people. Including in-person conversations.


> I don't care about my location information, I don't use social networks.

> I care about the content of my private communications w/ other people. Including in-person conversations.

A widely accepted security fundamental is that metadata, such as where, when, and with whom you interact, is as valuable as the content of those communications. People in the surveillance business (from security agencies to businesses who track users) value metadata for a reason.

Think about it this way: If you wanted to spy on someone what would be more valuable?: Recording everywhere they go and everyone they talk to, or recording the content of those communications?


I'm a private citizen. Spying on me is only productive for corporations and its the content, not the list of contacts, that would be useful.

Knowing I talk to Vendor X is worthless because soooooooooo many people talk to Vendor X. Knowing I'm buying 1000Y from X is more useful, eh?


So your worried Amazon will be specifically listening in to your conversations and use the content to...what? Blackmail you? Share clips of your conversation on the Internet? Inform your wife/husband you're having an affair?


Well they already go to my suppliers they know about and try to buy from them? So what do you think I'm worried about?


> Incorrect. The device is always listening, waiting for you to say "Alexa" so that it can start acting upon your commands.

You say "incorrect" then re-phase exactly what I said in a different way but retain exactly the same meaning.

The detection of the key word is on-chip. That's all that matters. Until the chip signals that it was spoken nothing is transmitted.

> So no, this isn't "pathetic baseless fear mongering".

Sure it is. If you know that on-chip keyword detection is a "thing" (which you do by your own admission) then you know also that claiming that everything you say in a room is sent to the cloud is entirely "pathetic baseless fear mongering."

You fully admit you know that that isn't the case here, but yet continue on like it /could/ be the case. Pathetic.


Yes, it's possible the technology respects your privacy.

But it's not open source. Therefore it's technically possible that Echo waits until you make a request, and then bursts a transcript of everything ELSE you've said, as well. Or maybe the device only does that if Amazon receives a valid Search Warrant, and they flag your device to enter "transcript mode." Or even "live, continuous broadcast."

People have a right to be concerned about their privacy. They have a right to ask questions. They have a right to boycott a product unless they feel satisfied their concerns are addressed. They have a right to worry that their government (maybe not even the US) could force Amazon to violate their privacy.

You calling them "pathetic" is not remotely constructive. You don't share their concerns, is all.


This sort of exchange is unfortunately the dominant mode of discourse--not just online either.

Both sides loudly proclaim the foolishness of the other without ever having an opportunity to establish some reasonable grounds on which an actual discussion could proceed.


As an aside, I have most assuredly been guilt of this on HN and elsewhere but have been making an effort to curtail it. We'll see how that goes.


"Never argue with a fool, onlookers may not be able to tell the difference."

-- Mark Twain

Pro-tip, when people make such outlandish comments and call people idiots en-masse, (which I am amazed hasn't been flagged away), just ignore them. :-)


I hear you.

...but I feel like it's an important topic, and this conversation thread was ALMOST worth trying to redeem... I thought I could maybe shine a bit of light where there was a lot of heat...

But yeah, I hear ya.


What you are saying is technologically correct, possible and prevalent but I couldn't find Amazon saying it anywhere on their page. Can you point me to the part where Amazon says nothing is ever stored/transmitted unless "Alexa" is spoken?


I noticed that your profile mentioned "recording engineer" so maybe some concrete numbers related to digital audio technology will put boundaries on plausible scenarios.

We assume either of 2 engineering designs:

(#1) the trigger word "Alexa" is detected within an embedded chip. The DSP (digital signal processing) intelligence for analyzing sound waveforms is inside the device. Therefore, the words spoken after "Alexa" are then sent to the cloud.

(#2) the trigger word "Alexa" (and/or other words) are detected remotely via cloud computers. There is no "smart" DSP chip within the Echo device. That means that the device must send a constant 24/7 stream of digital waveforms to the cloud.

If we continue on the #2 scenario, we can guesstimate what data transfer volumes would look like. To be conservative, we use 8kHz 8-bit audio as the parameters which is telephone quality. (Reliable voice recognition probably requires inputs with greater audio fidelity e.g. 16-bit 32kHz but we'll keep the 8kHz-8bit as a possible lower bound.)

Using 8kHz-8bit, it means that the device would have to stream 691 megabytes a day which leads to 20.7 gigabytes a month. Likewise on the back end, the amazon infrastructure would have to scale up to constantly analyze millions of parallel 24/7 digital waveforms. The amazon datacenters would be burning up terawatts of electricity to ignore the 99.99% of digital waveforms that is not the word "Alexa".

So, are there any consumer devices out there surreptitiously uploading 691 megabytes of digital waveforms (or any data) every single day? Is it realistic that Amazon would engineer the product to work like this?

I have a router that has a fallback option to a cellular connection in case my cable is disrupted. I and others would hate to get a surprise bill from Verizon/AT&T for going over my 2GB/month transfer limit if the amazon device was designed via scenario #2.

EDIT TO ADD scenario #3:

(#3) there are unpublicized/secret list of words in addition to the documented "Alexa" within the embedded chip's "vocabulary". Such words might be "vacation" and "book" and depending on the subsequent words sent to the cloud, you'd see ads for suntan lotion or Stephen King novels on your next visit to amazon.com. The chip's vocabulary may also include listening for transient sounds like dog barks or sneezes. You'd then get ads for dog food and cold medicine. In this scenario, a constant digital waveform is not uploaded 24/7 but extra trigger keywords unknown to the consumer causes more data to be sent than he/she agreed to.


I'm glad we're now discussing our assumptions about what Echo can/does do.

You present a scenario that I certainly did not imply, namely that Echo must be performing voice recognition in the cloud. Also, you make it out as though that is the conceivable alternative possible to on-chip voice recognition, from a privacy point of view.

Let me present another scenario to you - Echo keeps "listening" to all our conversations - on-chip of course - but creates additional metadata that is stored locally and uploaded to Amazon servers periodically.

What might theis metadata be?

- Audio streams that were close enough to Echo's threshold for "Alexa", but not quite, thus got rejected (perhaps some of them were falsely rejected, so let's keep a copy to feed our algorithm).

- Data on how often Echo heard voices in the house, from which rooms and at which times. Perhaps Amazon would like to know when a household wakes up, when it likes to listen to music or when to order groceries. Why should Google Now have all the fun?

I could give many more scenarious why Echo might want to retain some data from ambient conversations, so as to make itself more "useful". It needn't store the entire audio stream in these cases, but just metadata or logs.

Such a scenario falls outside your 1 vs. 2 design options; is plausible; useful; and fairly easy to program too. I'm sure there will be many others like that.

My point is - don't implictly trust a closed-source device that is inside your house and always listening in all directions. If Amazon were so careful about the Echo user's privacy, wouldn't they have mentioned the word at least once in the entire page? So let's not rush to give them a free pass till we know they even want it, much less earn it.

P.S. My profile says I'm a "recovering" engineer, not a "recording" one :)


>Such a scenario falls outside your 1 vs. 2 design options; is plausible; useful; and fairly easy to program too. I'm sure there will be many others like that.

Yes, I went back and added scenario #3... apparently at the same time you typed your reply. I think my scenario #3 is similar in spirit to what you're warning people about.

>P.S. My profile says I'm a "recovering" engineer, not a "recording" one :)

I have several browser tabs on music recording and I definitely had a dyslexic moment there.


Any decent voice-optimized codec (CELP, CELT, Speex, hell even old GSM)can squeeze that in 1Kbyte/sec - actually even half of that but let's retain some quality. Include silence detection and you probably have less than 60 minutes/day from the average household. And storage is cheap. Oh, and Amazon has lots. S3?


This reminds me of the (just as insane) concerns that people had about Microsoft's Xbox One Kinect being likened to a 1984 telescreen. I crunched some numbers like you just did - back when the One came with a Kinect and had to be online to work, the numbers worked out to something like exabytes of data that would be getting streamed to Microsoft, every single day.

You think the ISP's are cheesed off at Netflix? You haven't seen anything yet. The screaming from a non-trivial portion of their customers suddenly uploading multiple gigabytes of data per day would be deafening.

Sarcasm aside, anyone who thinks that this is seriously some kind of government listening device needs to up their medication. The number of insane assumption that have to be made for this to be plausible are:

* This is a listening device, live transmitting everything you say, when it would be more economical to listen for a codeword on chip. (Amazon is wasting money because they are not a corporate enterprise, and we all know how much companies love spending money they don't need to)

* That the data being transmitted is being stored for long term periods of time (Amazon is wasting money on storage when it makes more sense to just process commands)

* That that literally nobody actually notices the data stream going to Amazon servers when not in active use. (Not bloody likely)

* That ISPs will not flip their collective shit at the data usage should this catch on (Hello? Netflix? And that's a company whose business is transmitting large quantities of hard to compress data.)

* That customers won't notice this data usage when their next bill comes in or when their shitty connections get saturated by the upstream

* That the sorry state of connectivity in the USA (especially with regard to upload/download asymmetry) doesn't render the entire exercise meaningless from a surveillance standpoint even if we ignore every other point above

* That the outrage angle once these things that are never noticed are noticed wouldn't be played up in the media

Fucking. Seriously?

If I were a high level NSA guy, and this was the plan that was brought before me? I'd fire the guy for rank incompetence.


You do realise that it doesn't need to be streaming 48kHz 24 bit audio back up don't you? It could be something really low, like GSM which is 13.2 kbit/s. AMR is even lower! So to stream audio at the threshold where it is still legible, it doesn't need masses and masses of data as you presume.


They have advanced speech recognition but have never heard of compression? I would be surprised if the bandwidth consumed in plan #2 was even 1/3 of what you suggest especially in a non 24/7 sound environment like the typical home.


Given the state of the average American internet connection, is #2 even possible?


"prove this doesn't happen"


Can I, as a consumer that hypothetically owns one of these, control the software that is running on it?


Can you, as a consumer control the baseband on your cellphone?


In practice, "No." to both. Which suggests that you are far more confident than you should be.

Amazon publishes the leadership principles that they demand their employees aspire to: http://www.amazon.com/Values-Careers-Homepage/b?node=2393650...

Look over those for a moment. Assume for the moment that Amazon engineers and their management take them seriously.

When Amazon employees working on this project raised concerns about privacy, do you think that they were berated? Or do you think that they were heard out? The sort of attitude that you have towards these concerns is exactly what so many people fear. It is part of the reason those guideline principles were created.


I suppose with a lot of constraints that you can, using something like OsmocomBB: http://bb.osmocom.org/trac/


so you guarantee that the system doesn't access the microphones until it gets an interrupt from that chip? I don't see why that should be mutually exclusive.


Wouldn't it be fairly simple to just monitor network connections to see how often it's sending data to Amazon's servers?

Granted - then of course you can have the argument that it's always recording, and then only sending data at the opportune time so that it's a little bit more hidden. And to that - I'd just say you can keep track of how much data should be being sent for the average command.


i would much rather have a device that i can actually control and trust instead of having to spy on a device that's most likely spying on me in ways i might not like.


And what's great is that your personal preference on these things takes absolutely nothing away from the device itself.

I don't think i'll buy one because I have Siri in my pocket at all times, but these privacy concerns aren't absolute truths. They only matter to you because you're sensitive to it.


agreed and upvoted


Then buy one of those instead.


It will be easy enough to test once it gets into someone's home who understands how to use a packet sniffer


Do you mean like 'Ok Google'? on a typical Android device? Ok, that only works on the Launcher but I'm also familiar with tech on Qualcomm devices which does the voice keyword recognition in hardware. So this isn't anything new.


"From any screen" definitely is one of the choices in Google Now settings, at least on Note II.


Ok, since everyone here is making baseless claims about privacy, why don't we just buy one for science and monitor the network traffic on it? Problem solved.

Getting really tired of HN stating obvious paranoia instead of talking about innovation these days. Yes, I get that privacy concerns exist, and this should always be kept in mind. But when more than 90% of the comments are about that, and circulating on completely theoretical claims, we've lost all value in the conversation.


I think we're in both a time and among an audience (HN readers) where privacy/surveillance issues tend to drive the conversation. I don't think that's bad, but I agree that it's a little disappointing that the main reaction among the HN crowd to the promise of ubiquitous computing is to immediately focus on all the ways it can be used for evil.

My own take, which is either naive or mercilessly pragmatic depending on how you look at it, is that it's going to be a lot more productive to start thinking about how to protect privacy -- and, bluntly, what tradeoffs we're comfortable making as a society, which may not mean "share nothing unless explicitly told otherwise" -- in an always-on, always-connected world where networking will almost certainly become so pervasive that we largely stop even thinking about "the network."


The phenomenon of the average person being surrounded by a half dozen internet-enabled cameras and microphones is a pretty recent one; I don't think we've even begun to experience the Bad Things that can result from that. Even if it's highly unlikely that Amazon would use it for evil, there's no stopping a technically savvy malfeasant from doing so. I mean, probably 1/3rd the people reading the post, including myself, are on an Apple laptop. You're staring right into the face of an internets-enabled HD camera. Is it recording? The light says no but the light can lie (https://jscholarship.library.jhu.edu/bitstream/handle/1774.2...). Is your microphone recording audio and sending it somewhere? Even you, the 1%ers of the tech savvy world, have got to admit that you would have little way of knowing this if somebody did it correctly.


You people completely ignore the mode of operation and start making idiotic claims about "well NSA!"

In this case it wasn't even the NSA I was thinking about, rather Amazon themselves.

"Hey, I'm heading to the grocery store, do you need anything?"

"Yeah, get some milk?"

<user requires milk approximately every 4 days, enter "send Amazon Fresh promo e-mail" event for 3.5 days from now>

Nothing will be transmitted to the cloud unless it is the word "Alexa" or sounds similar enough to the term.

You don't know that. This is not going to be a piece of open source software you can evaluate. It's Amazon's literal black box to do with what they wish.


Its not really a black box, you still conceivably own the network it is running on. Last I checked Wireshark was pretty good at capturing network traffic. Even if the connection is encrypted, if the device isn't sending oodles of data to Amazon when you are chatting chances are good it isn't send "every word" to them.

Granted, being able to audit this directly ourselves instead of observing it in other ways would be nice.


It's possible that the device will transcribe and record the text of everything, and then only send it upstream in batches along with the consumer-useful chatter. Over a TLS link, that would look quite innocuous.


"you have to say the word "Alexa" for it to start listening"

That means that it is ALWAYS listening. It needs to listen for that trigger word at all times.


The question is "what" is listening. For it to be responsive it's probably hardware-on-device that's doing the keyword processing. It would be simple to check though - look at network traffic.


It is always listening just like your dog is always listening. If you are not talking to it and you are not saying its name you are being (mostly) ignored.

Most of the time, it is not paying attention - the chip that is processing the sound is looking for the ONE word that will activate it. That passive audio processing is happening locally on a chip that is dedicated to the task. Once activated - the expensive processing happens and the sound gets processed, converted to text, sent to the cloud.


I understand this, and I don't happen to agree with the people who feel this type of technology should not be embraced, but, to be fair, the chip is controlled by software that is constantly connected to the cloud and updating over the air. It would take very little to update the software to disable the on-chip keyword detection and just record everything. That update could easily be done without your knowledge and in a way that would be almost undetectable since the software stack doesn't appear to be open and the server-stack is in the cloud and out of your control.


It's much easier to listen for a single word than to do the rest of the voice-recognition tasks. It would be a huge waste to upload all of the audio all the time, so usually these systems do the one-word thing on the device. They have a rolling buffer of a few seconds so that when it detects that hotword, it can send that to the cloud. It helps with noise removal. But not everything.


The website makes clear that the listen-and-answer /behavior/ isn't activated unless triggered. That's absolutely not evidence in either direction for what happens in the non-triggered case.

For example the idea that there's a debug mode that dumps the whole audio stream for troubleshooting isn't exactly tinfoil-hat paranoia.


How do you really know? How do you know that it won't be processing sound without the trigger when they get served with some government request? Is this in the terms and conditions? Is this in the privacy policy?

Yes the original post is making an assumption, but you are as well.


I think you misunderstood skorgu's post. I think you're both in agreement. He was saying Echo won't act on anything without first hearing "Alexa," (as in, perform the action you're asking it to) but that we don't know if it will be transmitting the voice data.


It is not "pathetic baseless fear mongering" when we already have evidence that governments around the world are willing to overstep their bounds in terms of monitoring their own people.

> In this case, as the website makes clear, you have to say the word "Alexa" for it to start listening.

In order for it to hear the key word 'Alexa', it has to be always listening. They're just saying that they promise not to process the audio any further until they hear Alexa. Of course the obvious question is 'Does this promise apply for every situation?' What happens when Amazon gets served with a request to procure data from a user? Do they state this in the terms and conditions or in their privacy policy?


Yes, it is. That's not relevant at all. Governments are not making these devices or forcing them in peoples' homes.


Have you not read the news in the last year? It is relevant. They don't need to manufacture anything. They can just coerce private companies to give up their customers' data in the cloud. The companies aren't even allowed to announce it.

> or forcing them in peoples' homes.

Hence my argument for holding off from buying this and other devices like it.


Unless the chip design, the firmware, the OS, the software is 100% open source, there is no way to confirm "Nothing will be transmitted to the cloud". It could be an update check, or it could be the transmission of a new voice fingerprint.

Same shit with cellphones, I have to admit.


It is certainly possible to wireshark it and know whether it is transmitting anything. You don't need anything to be open sourced.


Read this again, then you'll see what I ment:

"It could be an update check, or it could be the transmission of a new voice fingerprint."


You'll hopefully notice I deliberately said "it's too bad", "privacy concerns", and "might," all of which are key to the meaning of that sentence. My first comment was mostly in jest.

That said, it's ignorant to blindly trust or blindly distrust anything. I believe the rational concern is not what it does now, or what Amazon intends it to do, but what it could be updated or hacked to do. Hence the "can hear," not "will hear" present even in my joking.

I'm making a deliberate choice to ignore your insulting language and look for the reasoning behind it, but you could stand to make it a little easier to do so. Let's be gently rational. Something about flies, honey, and vinegar.


This is installing a general-purpose computational device with audio listening and networking. In addition, its normal use case is listening for a phrase, doing additional decoding in the cloud, and then taking an action.

It is not at all unreasonable to say "Man, that functionality sounds a lot like spying. I sure hope that nobody roots this device."

Are you 100% sure (beyond some marketing copy on a website) that this is purely on-chip voice recognition? That this chip's firmware isn't reprogrammable? That it can't decide to, once activate on-chip once, stay on continuously?

You can't. Unless the hardware and software was open-source, and then was verified on-site, you can't. That's the problem with these kind of things.

And yes, we have the same problem with cellphones, laptops, tablets, soon cars, and everything else; that doesn't somehow magically make this any better.

Also, please stop saying "pathetic". It conjures to mind some jerk swirling cheap booze in a glass saying "mmm yes how pathetic the plebes" and then waiting for their next r/atheists post to get upvoted. You just end up sounding like a pompous ass.


> Nothing will be transmitted to the cloud unless it is the word "Alexa"

You can't be certain that there's no way to activate it remotely without you knowing. Seven mikes in your lounge is an attractive nuisance.


> You can't be certain that there's no way to activate it remotely without you knowing.

Ditto with every electronic device with a microphone: Smartphones, tablets, laptops, home phones, bluetooth in your car, Microsoft's Kinect, baby monitors, etc.

And while we're on an NSA paranoia trip, let's also remember that if you bounce a laser off of one of your windows it will allow them to pick up sound from within, plus signal leakage via the electrical grid, and of course unless you're in a faraday cage tons of EM leakage from everything you use.


> Ditto with every electronic device with a microphone: Smartphones, tablets, laptops, home phones, bluetooth in your car, Microsoft's Kinect, baby monitors, etc

While there's a lot of truth to this, that is no reason to go even further down that road. If it's wrong for laptops to be used to eavesdrop then it's insanity to install a seven-microphone listening station in your lounge.

"paranoia trip" is a rather condescending and dismissive way to refer to matters of documented fact, e.g. http://news.yahoo.com/yikes-nsa-turn-iphone-camera-mic-witho....


Of course, you could be monitored by the laser bounced off your window, or by your EM leakage. But it is an order of magnitude cheaper and easier for the commercial/governmental entity to use your own voice-enabled communications device for their own purposes. The commercial/governmental data gathering dragnet has come to its current state because it works on devices and networking services that the consumers themselves have purchased.


This, a million time this. Actually reading stories like these, I wonder how big the market will be in 2020 for fully off-grid home solutions. If we proceed at the current rate with the IoT, cloud based storage of huge personal data sets, I feel that the future is brim.

I bet that market will be huge, eventually.


baseless? did you miss out on how the NSA has been recording everything you've said and making deals with companies for gathering your information?


Even so, you're basically voluntarily placing a "bug" in your house, allowing anything you say to be transmitted to someone else.

The user has no way of knowing how that data may or may not be used.


> All of this is made possible through the advanced, tightly integrated hardware and software in Snapdragon 800 processors.

https://www.qualcomm.com/news/onq/2013/02/20/snapdragon-wake...

cf. Stuxnet, BadUSB. There may not be a remote exploit for these chips yet, but I will bet my paycheck that intelligence agencies somewhere are working on doing so.


Its not baseless when stuff like this happens:

http://mediabuzz.monster.com/benefits/articles/1288-google-s...

1) Its quite possible for a firmware glitch to "accidentally" leave it on.

2) Given I interact with Amazon's APIs enough to know they have "intermittent" issues that are quite hilarious, I fully expect #1 to happen at some point.


> You people completely ignore the mode of operation and start making idiotic claims about "well NSA!"

You say that like the thing people are concerned about isn't possible.


>Echo's brain is in the cloud, running on Amazon Web Services so it continually learns and adds more functionality over time.


[deleted]


How can it "hear" the wake-word if it's not already continually working?



With a tiny little tweak to the firmware, it could be always-on. With the seven far-field microphones it would be a very nice audio surveillance device indeed. No thanks.


Right. Cellphone's baseband also. Hope you don't have any in the room with you otherwise that would be hypocritical. Most have a speakerphone which will pick up the whole room's audio.


I agree with you about the NSA-related claims dominating the discussion too much, but your tone isn't nice. May I suggest that a better way of mitigating the dominance of the NSA-related discussion would be by making some top-level posts about other interesting aspects of the product?


Likewise. I'm all for recognizing a credible threat, but there is nothing credible here.

The level to which the readership of HN abandons all pretense of critical and rational thought when a surveillance angle on a story presents itself is downright frightening.


Yeah, I was just having this conversation 4 days ago.

https://news.ycombinator.com/item?id=8545144

There's always a guy on HN who wants to warn everyone like we're all a bunch of idiots.

It's ok to be paranoid but we should file it under an FAQ.

Our time is probably better spent discussing the value of the product itself. Hopefully, we get to that today.


The value of the product is undermined by what we now know the Agencies do. Before Snowden we all thought it was an idiotic idea we'd have pervasive surveillance, now we know it happens. Before Snowden we'd buy nice to have, harmless gadgets, or use easy Google speech recognition (your reference), now we shoot them down. As an investor i'd be thinking about this kind of reaction to a product. Maybe a table-stakes feature would be privacy in a way our community had some confidence it was well thought through.


Yes, I got the part where there's an entire group of people on HN who have a problem with these types of products.

Did you get the part where there's an entirely different group of people who get tired of listening to you whine about it? I simply want to discuss the product itself.


Thanks for dragging me in to this. This is an even better example of the point I was trying to make, yet you're still doing this bland dismissal. You should really stop and think about the privacy implications of this technology for a few minutes.


Thanks, I didn't realize there were privacy implications. How did I miss that. I think I slept through the hundreds of Snowden posts to HN.

Now would it be possible not to turn every post like this into an NSA warning? I'll make my own choices from here.


> Now would it be possible not to turn every post like this into an NSA warning?

Sure, right after the need for an NSA warning on all of these things stops being necessary.


> idiots > paranoid

I don't see much difference between calling someone an "idiot", and calling them "paranoid" and dismissing their concerns to an FAQ.

> Our time is probably better spent discussing the value of the product itself.

Confidentiality has a large impact on the product's value, at least for many people. I don't see them as independent issues. If you feel, like many, that confidentiality is necessary to its value then the focus of the discussion makes sense (if it wasn't so redundant).


I didn't call anyone an idiot. I said the general HN population is treated like idiots because there's always "that guy" who feels the need to sound the alarm every time something gets sent to Google/Apple/Amazon. I got it the first 10 times it was discussed. I've been warned.


> I didn't call anyone an idiot.

I know; sorry I didn't write more clearly. I meant that them calling you "idiot" and you calling them "paranoid" is roughly equivalent.


I said "our paranoia". I wasn't trying to dismiss it but these types of conversations tend to devolve into mainly discussing our paranoia. I don't need to be warned every week. And it's my choice to decide to allow Google or Apple, for example, to get my data.


> I said "our paranoia".

Hmmm ... that's not what I see above.

Generally I can understand frustration with any issue getting too much attention and drowning out others.

> it's my choice to decide to allow Google or Apple, for example, to get my data.

It's not your choice really. It's hard to function in this society otherwise, and I don't just mean having phone service or traveling. For example, my electricity vendor insisted on installing a 'smart meter', which allows them to record what and when electrical devices are used, giving them a good view of my activities in the privacy of my home. My choice was to let them install it, get my own generator, or go without electricity.


I'd still be interested, if and only if, the "wake word" processing is done locally and it THEN sends the recording that occurred after the wake word up to the cloud. If it is the case that even the wake word processing is done in the cloud, non-starter for all the reasons you state.


I know for a fact that the wake word processing is done locally on the device. You could even check its network traffic to see that this is the case.

I'm not sure what protections you would have against a secret court order making the device always listen (via an OTA update) for select individuals, but you can at least check that they don't have such monitoring enabled for most devices.


> if and only if, the "wake word" processing is done locally

That's what it's doing.


Wake-up word is the way to go for many reasons.


Agreed. And on the idea that it's ridiculous they are listening all the time, and 1984 comparisons, it's worth knowing in 1984 they weren't continually listening, but they might be. I read this book in the 1970s at school, i think it's time to re-read.

http://www.george-orwell.org/1984/0.html quote: There was of course no way of knowing whether you were being watched at any given moment. How often, or on what system, the Thought Police plugged in on any individual wire was guesswork. It was even conceivable that they watched everybody all the time. But at any rate they could plug in your wire whenever they wanted to. You had to live -- did live, from habit that became instinct -- in the assumption that every sound you made was overheard, and, except in darkness, every movement scrutinized.


I agree completely. At least this isn't the microsoft kinnect yet, that can basically scan the room for every little detail and is always listening. The first time I saw the kinnect, I thought, hm, I wonder how other companies will get this technology into the living rooms of every family.

To me, everything these big companies do is just a play to get information on people. Putting the kinnect in my living room and always have the mic on and it connected to my cable television and my internet, and constantly listening even when the xbox is off is freaky; just like this new echo. It's scary, but I bet personal recognition features are coming to this echo soon. Also, I can imagine being like, echo order me some stuff off of amazon, and then magically it appears from a drone in the sky.


Absolute first thought was along similar lines. If it did all the processing locally and just fetched results I might be interested. But this? Not so much.


Why are you saying things you don't want the cloud to know about anyway?


Are you trolling? Do you know nothing about privacy?


I'm pretty sure that's a tongue-in-cheek reference to the pro-surveillance argument that 'if you have nothing to hide you have nothing to fear'.


yes, it'd need to be fully open hardware and open source software. What else ? :)


Opt-in to 1984 for only $199! ($99 if you belong to Amazon Prime)


That is exactly what this reminds me of, telescreens. I love the idea of being able to have a star trek like computer interface, but with all the processing being done off site it can and will be used in ways that violate our privacy.


We clearly need the Enterprise's central computer in our homes. With microcomputers getting more and more and more powerful, this should be possible (unless Moriarty turns up and takes control from the holodeck....)

In all seriousness, with Wikipedia being 22GB in textual state, it should be possible to build an offline system (that perhaps syncs online for news).


Once everybody has it, it will be easy to pinpoint the few without one as the people with something to hide.


Yes. Seeing how big Amazon has come with its web services, cloud storage etc and now with technology like this, I wonder why we haven't read about Amazon in any of the Snowden leaks. Or have I missed something?


You don't hear of Amazon but you hear of their customers. Dropbox is on AWS for example.


I agree. I wouldn't have one in my home, but for most of the non-tech savvy population, all you need to do is stick something on the box that says "100% secure" or something similar and their nerves are calmed.

This is obviously not apparent in the HN/tech worlds, but the unfortunate perception I get is that no one really cares about their online privacy (unless it comes to their finances). When I talk to my non-techy friends, most say the cliches like, "I'm not doing anything wrong, so have nothing to hide". Therefore the reason governments can get away with forcing tech companies to give up data, is because the people don't really care, or believe the bullshit in the media about stopping terrorists, and tolerate it.


Wow. New technology can be used for good or evil? This can be (and usually is!) the top comment on any interesting HN post.


Can be, usually is, and should be. As engineers, we should always consider the potential ramifications of technology that we create.

Now, we should not necessarily refuse to develop an idea because it could be abused, but we should always keep abuse in mind. Nearly everything can be abused, if only as a bludgeon, so obviously we need to have a certain level of tolerance for potential abuse. However it would be negligent to not consider the full range of ways something could be abused.

I strongly believe that engineers have an obligation to always consider and discuss the ethics of what they are building.

Even if you don't give a shit about ethics (I know many engineers don't), you must realize that many potential consumers will be concerned. Considering these possibilities is therefore just good business sense.


Well, until Amazon starts understanding Bulgarian (the language we speak at home), I'll be fine. Just imagine an Amazon Prime members' freebie next year: unlimited recording of everything you've ever said at home for free and accessible on the web or via our companion app.



Well, they will record a lot of cursing and anti-Obama talk then - big deal! :)


How is it different from installing a random program on your computer? That would also have microphone access and could in theory spy on you.


Privacy concerns not alleviated by the video, which showed the Echo in every room that the family was in.


Hey, you're that guy!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: