9 ms·
Ask HN: Is anyone monitoring popular apps to check if they're listening?
Everyone's heard the conspiracy that Facebook and Instagram record audio from your phone's microphone and use it to recommend you advertising...
Is there any evidence of this? or are there any groups monitoring the appstore binaries to tell if they actually sending voice data over the wire?
- mikewarot 5y agoI have learned one thing, regardless of assumptions about if they are listening... never name your smart speaker "computer", the number of false triggers is frustrating as heck.
- fuzzfactor 5y agoOnly Spock was allowed to do that.
- diplodocusaur 5y agoHaven't checked but couldn't you make one that does and compare data usage volume? But "listening, on everyone" and "all the time" are not necessary assumptions.
- after_care 5y agoIf there was any evidence I’m sure the EFF would be talking about this. https://mobile.twitter.com/eff/status/1164331076375814144?lang=en https://mobile.twitter.com/eff/status/1164331076375814144?la...
- deepsun 5y agoEFF cannot monitor everything, it just protects your rights.
- after_care 5y agoSure, but if someone was monitoring and they did have evidence then the EFF would most likely publicize the findings. You can answer the question “has anyone found evidence of popular apps monitoring audio data” by searching EFF archives. It’s not exactly the same thing, but it is something of interest.
- nicolaslem 5y ago> Is there any evidence of this? There is a Reply All episode from 2017 about it. The answer was no. https://gimletmedia.com/shows/reply-all/z3hlwr https://gimletmedia.com/shows/reply-all/z3hlwr
- matt123456789 5y agoGood question. iPhones tell you when applications access the mic or camera using an indicator light along the top, and I haven’t noticed unusual hardware access patterns from any of the popular apps that I use. But like most other users, I’m not always paying attention, and I don’t keep track of every access.
- PragmaticPulp 5y agoNo, Facebook and Instagram are not monitoring conversations. Yes, many security researchers routinely examine traffic from these apps to see what’s being communicated with the servers. Recording and interpreting speech would require a lot of CPU (if done on device) or network bandwidth (if uploaded to the cloud). Enough that it would be immediately obvious if apps were trying to do this. That is, if they even could. iOS limits what apps can even do in the background and shows an icon when the microphone is in use in the background. Again, it would be obvious if apps were listening. But let’s assume that somehow they managed to avoid all of these pitfalls and they were listening to conversations, performing speech to text, and uploading your conversations. This would require communication with their servers, which isn’t difficult to extract through basic reverse engineering. Many security researchers reverse engineer these communications on a regular basis to look for bugs, some of which can be worth six figures in these companies’ bounty programs. If there was an API for uploading your secret conversations, it would be the holy grail discovery for a security researcher. Someone would have found it. The myth persists because coincidences will happen in high numbers at scale. If hundreds of millions of people are spending hours on social media each week, some number of them will see ads related to some conversation they had recently by pure random chance. Add in a general distrust for big tech companies right now and some subset of people will become convinced that their coincidences are evidence of a conspiracy.
- dylan604 5y ago>Recording and interpreting speech would require a lot of CPU (if done on device) Does this include the newer Apple Axx series units with increasing number of ML cores? Siri is supposed to run locally on device. Hardware is moving explicitly in this direction. If this is done locally, no actual voice data would need to be sent down the wire. Insstead, a small compressed bit of text on keywords could be sent whether that's immediately or saved up until user foregrounds the app. No tinfoil hat needed to see how your premise is pretty weak.
- PragmaticPulp 5y ago> Insstead, a small compressed bit of text on keywords could be sent whether that's immediately or saved up until user foregrounds the app. Which would then appear in the packet captures that can be performed on the traffic (after circumventing certificate pinning). My premise wasn’t that each step was impossible. It was that many steps would have to take place without being detected anywhere along the chain.
- smoldesu 5y agoIf this did happen, some 12-year-old with WireShark would probably make national news. In other words, Facebook and Instagram are probably 3 steps ahead of you. Whether that should scare or console us, well, that's up to you.
- mritzmann 5y ago> Is there any evidence of this? No, because this is a conspiracy. Whoever claims something like that should prove it and not the other way around.
- techbio 5y agoI think you mean a "false conspiracy theory", because if there actually were a conspiracy to monitor conversation through common apps, as other comments mentioned, it would have been found already.
- donclark 5y agoIf they are not actually listening, has someone mapped out how I get an ad related to a verbal conversation? What did they do to put the pieces together? I would imagine several different scenarios to get an actual match - but Ive wondered this at least a couple of times (too close a coincidence that is).
- np- 5y agoThey don’t need to listen to audio, which is very cumbersome and error prone, if they have your location. If your location is available, so are all of your friends’ locations. The apps can easily see who’s in the same place at the same time and generate a “friend” network. Presumably you talk to your friends about your thoughts, and they talk to their friends. All it takes is a few people to start googling something new (or looking up products in Amazon, or searching for the same tags on Instagram, etc etc) in this network for the algorithm to realize this might be something you’re ALL talking to each about, and thus advertise straight to you, giving the perfect illusion that whatever you’re talking about is advertised back to you.
- edent 5y agoIt's a mixture of things. The first is "Baader–Meinhof phenomenon" / frequency bias. Your friends talk about X, all of a sudden you notice adverts about X. Of course, you discount the thousands of adverts you see which aren't about X. Why are you and your friends talking about X? Because it's a demographically popular topic. And advertisers have noticed that $gender people of $age_range in $city are searching for X. So you get an advert. You're not as unique as you think! Or, while hanging out, you're attached to the same WiFi spot. One of you does a search for X before talking about it. So the retargetting continues. The key thing is - why are you talking about what you're talking about?
- casperc 5y agoCan all apps access information on the wifi hotspot that a user is connnected to? Seems like an information leak that should be closed by Apple/Google.
- deleted 5y ago[deleted]
- bob229 5y agoYou don’t need to monitor the Facebook app if you just delete your account like a sensible person
- _wldu 5y agoHow do Android and iOS known when you say "OK Google" or "Hey Siri" if they are not listening all the time? Or, is it accepted that they are?
- angelzen 5y agoThey are listening all the time. Presumably 'just' for the wakeword. Better yet, Alexa listens to everything you do inside your house, and the Ring Network listens to everything you do outside your house. And both of them are connected to the power outlet, so the 'but battery depletion' excuse doesn't apply.
- justusthane 5y agoThe listening for the initial keyword (e.g. “Hey Siri”) is done on hardware designed specifically for that purpose. That’s why you can’t change the keyword to whatever you want. Only when that keyword is heard does it actively listen to and process whatever follows. “Actively” listening all the time would simply consume too much CPU/bandwidth/battery.
- dylan604 5y ago>That’s why you can’t change the keyword to whatever you want. Which I feel is a huge security oversight. You should be able to choose from a list of activation keywords at least. I love being on video/voice chats with people that I know have a device and randomly say "Alexa, play Dancing Queen" or something equally obnoxious like "Alexa, turn off lights".
- angelzen 5y agoWhat exactly prevents the 'hardware designed specifically for that purpose' to include in its purpose the translation of your voice to text, with voice fingerprinting for good measure? Have you ran an electronic microscope atom layer slicing of the hardware to guarantee its complete set of functionalities?
- midasuni 5y ago
- deleted 5y ago[deleted]
- jpeter 5y agoI wonder if anyone is monitoring the apps you can get on pirate bay (windows, photoshop, etc.)
- barbarelephant 5y agoI’m also curious about this. Would be nice to have some kind of general independent service (or wiki?) similar to consumer reports for cybersecurity.
- reginold 5y agoFrom the discussion here, it appears that no one is monitoring broadly. The big apps (fb, insta) potentially are being checked as they have bug bounties and warrant research time. But for less popular apps, or pirated apps, it sounds like no one is checking.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- iJohnDoe 5y agoThere is so much misinformation in these comments about so many topics. It’s weird. Like bots or a hired damage control media agency that are meant to diffuse certain topics anytime they come up.
- bkovacev 5y agoI was at the Zurich airport while I had a connecting flight to Barcelona from Belgrade. My friend and I briefly spoke about Zlatibor (a city in Serbia), 30 seconds later I got an ad for a hotel in Zlatibor, in the middle of Zurich Airport. We never spoke about or searched for Zlatibor.