6 ms·
Cell phones have microphones, are closed source, connected to the Internet and carried with you into all the rooms of your home. Europeans use cell phones so wh
by madhato 8y ago
Cell phones have microphones, are closed source, connected to the Internet and carried with you into all the rooms of your home. Europeans use cell phones so why do they fear home assistants?
- krn 8y agoCell phones, unlike home assistants, are not designed to be recording anything by themselves. Their apps are. And the user controls both, what apps he installs on his device, and what permissions he gives to them.
- deleted 8y ago[deleted]
- mikeash 8y agoYou think they’re not. You really have no idea. You just have to trust that they aren’t constantly recording and sending everything back to the mothership. If you can trust that, why can’t you extend the same trust to a smart speaker?
- dingaling 8y agoDistrust of a smartphone's mic can be mitigated by epoxying the microphone, or just ripping it off the board, and it's still a functional portable computer. But to consider further: if you're in a situation where you have to worry about your smartphone grassing on you then you probably won't keep it powered on. Or will keep it in a Faraday case or whatever. In other words you'll be considering all attack vectors and behaving appropriately. Whereas Amazon or Google could flip the notional 'record all' switch on their assistant devices on a whim and you'd be none the wiser.
- mikeash 8y agoIf the commenter has disabled their smartphone mic as you say then I’ll give them a pass. I suspect they haven’t. Why can’t Google flip the “record all” switch in Android on a whim?
- umanwizard 8y agoIf someone were in a situation where it made sense to put their phone in a Faraday cage, wouldn't you expect them to do the same with their Amazon Echo?
- wvenable 8y agoThe baseband of your phone is basically an entire closed OS that runs in parallel with the OS that interact with and has complete control over all the hardware. This OS has it's own file system, programs, network access, everything. The Amazon echo isn't even that mysterious; it has low-power hardware to listen for the wake word and doesn't even power up the main CPU until that point. And you can always monitor the network traffic. The fears are massively overblown for home assistants. Mobile phones, by comparison, track your position in real time everywhere you are and send that information to paying 3rd parties all the time.
- fucking_tragedy 8y ago> And you can always monitor the network traffic. This is meaningless if the connection is encrypted. The device can wait to send data that it's collected without telling you along with data you expect it to send to Amazon, and you wouldn't be able to tell the difference.
- wvenable 8y agoYou'd be able to tell if some traffic is being sent. If my Echo is spying on me day and in out then I'd expect a pretty constant stream of traffic from it. If the Echo was ever caught intentionally spying (either through analysis or someone leaking that information) that would be the end of that product line forever.
- fucking_tragedy 8y agoIn my OP, I laid out an example in which an Echo could spy on you and waits to send data along with legitimate and expected network communications. > If the Echo was ever caught intentionally spying (either through analysis or someone leaking that information) that would be the end of that product line forever. Truthfully, I don't think many people would care.
- wvenable 8y agoSo people who do care would care and people who don't care already don't care. But trying to appeal to people who would care without any evidence is really pointless.
- dymk 8y agoThey’re a closed source, always on device with a microphone. How do you know it’s not always listening? The point is, they subject you to the same threat as an Alexa. You can’t say “Europeans don’t use Alexa because it could XYZ”, and yet they use phones which could also do XYZ.
- krn 8y ago> They’re a closed source, always on device with a microphone. How do you know it’s not always listening? Your iPhone might be closed-source, but Android devices can be compiled from source and fully inspected.
- grey-area 8y agoHow about the sim card? https://www.scmagazine.com/home/news/black-hat-mobile-carriers-react-quickly-to-major-sim-card-vulnerability/ https://www.scmagazine.com/home/news/black-hat-mobile-carrie...
- madhato 8y agoAndroid is open source but the Play Store and Play Services are closed source. If Google needed to secretly install a rootkit to listen to the microphone they could.
- mikeash 8y agoI’m pretty sure the cellular baseband in your phone is closed source. Coincidentally, it also has direct access to the microphone and to an internet connection you can’t monitor.
- jschwartzi 8y agoYeah, the baseband processor runs its own independent RTOS with full software control. Without studying, in detail, the electrical connections between the baseband and the rest of the hardware it's not possible to say that it can't record from the microphone independently of the hardware. It's easier to make that argument for the SIM card, which is actually not a SIM card but also a small ARM core that runs Java code. You can embed small programs into the SIM card which is something a lot of carriers do. The SIM card and baseband work in tight concert though and you should just assume that the connections of the baseband are available to the SIM card.
- netsharc 8y ago"Controls both"? We have an illusion of control, but do you know exactly what's going on inside the slab of black mirror? There are surely exploits for both points, most probably used by your friendly government surveillance agency against whomever they consider to be their adversaries.
- zamadatix 8y agoFor a single app device is this distinction relevant? Or are you saying most Europeans don't install any Google, Amazon, or Facebook apps?
- CharlesW 8y ago> Cell phones, unlike home assistants, are not designed to be recording anything by themselves. The assistants in phones work in exactly the same way as the assistants in home appliances, no? They start recording when they hear their voice trigger. Both classes of devices require trust that their maker won't invoke this functionality when it's not asked for, has hardened this functionality against bad actors, etc.