20 ms·
Samsung Global Privacy Policy - SmartTV Supplement
- yaddayadda 12y agoEnglish translation: https://translate.google.com/translate?sl=auto&tl=en&js=y&prev=_t&hl=en&ie=UTF-8&u=https%3A%2F%2Fnetzpolitik.org%2F2015%2Fsamsung-warnt-bitte-achten-sie-darauf-nichts-privates-vor-unseren-smarttvs-zu-erzaehlen%2F&edit-text=&act=url https://translate.google.com/translate?sl=auto&tl=en&js=y&pr...
- stuaxo 12y agohttps://www.samsung.com/uk/info/privacy-SmartTV.html https://www.samsung.com/uk/info/privacy-SmartTV.html Here is the relevant part: "Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition." This must be a data protection violation ?
- Havoc 12y agoHas been in the news before. Voice recognition is done on a server farm meaning it needs to get sent there & possible get intercepted. Not ideal but doesn't strike me as a big risk
- aw3c2 12y agoIf you submit things from aggregators, please try to find the actual source and submit that instead. Submitted: https://netzpolitik.org/2015/samsung-warnt-bitte-achten-sie-darauf-nichts-privates-vor-unseren-smarttvs-zu-erzaehlen/ https://netzpolitik.org/2015/samsung-warnt-bitte-achten-sie-... which links to http://martingiesler.tumblr.com/post/110325577280/samsung-watch-what-you-say-in-front-of-our-tvs http://martingiesler.tumblr.com/post/110325577280/samsung-wa... which links to http://mostlysignssomeportents.tumblr.com/post/110300533107/samsung-watch-what-you-say-in-front-of-our-tvs http://mostlysignssomeportents.tumblr.com/post/110300533107/... which links to http://boingboing.net/2015/02/06/samsung-watch-what-you-say-in.html http://boingboing.net/2015/02/06/samsung-watch-what-you-say-... which links to http://www.reddit.com/r/technology/comments/2uuvdz/samsung_smarttv_privacy_policy_please_be_aware/ http://www.reddit.com/r/technology/comments/2uuvdz/samsung_s... which references https://www.samsung.com/uk/info/privacy-SmartTV.html https://www.samsung.com/uk/info/privacy-SmartTV.html On the other hand, the HN rules suggest doing things like this if you want to cherry pick a certain aspect of a page...
- sctb 12y agoThank you, we updated the URL of the submission to the original source.
- imgabe 12y ago> You may disable Voice Recognition data collection at any time by visiting the “settings” menu. However, this may prevent you from using all of the Voice Recognition features. from here: https://www.samsung.com/uk/info/privacy-SmartTV.html https://www.samsung.com/uk/info/privacy-SmartTV.html So, disable it. I don't understand everybody's fascination with voice recognition. I don't find it more convenient at all. I'd much rather just push a button. It's really not that complicated.
- maxerickson 12y agoI can think of at least a couple of situations where it could be useful. I've seen some people have an awful time using a remote in a darkened room. Also, free text search is useful when you are trying to search.
- learnstats2 12y agoIt used to be the case that a service would politely ask you whether or not they could collect data about you, and would provide the same service in both cases. This option (to minimise data collection/retention) ought to be enshrined in law. If you pay (or not) for a service, you should be able to get the service without the expectation of your personal and private data being harvested.
- vidarh 12y agoIn this case the issue is that it is not possible for them to provide the service without potentially collecting private data: The voice recognition is done on remote servers, and they have no means of preventing you from saying something private when it is recording.
- DanBC 12y agoThe TV could store a "wake up" word locally. The TV doesn't send any audio anywhere until you speak the wakeup word, at which point in beeps and a light flashes and then all audio is sent away to the cloud for processing.
- hughlomas 12y agoI think Amazon's Echo device is doing this the proper way, which "uses on-device keyword spotting to detect the wake word. When Echo detects the wake word, it lights up and streams audio to the cloud". It seems like a technical or design failure on Samsung's part to not feature similar functionality.
- ggasp 12y agoPretty much the same thing that everyone else does: "Echo uses on-device keyword spotting to detect the wake word. When Echo detects the wake word, it lights up and streams audio to the cloud, where we leverage the power of Amazon Web Services to recognize and respond to your request." The article refers to the same thing being the difference that Samsung doesn't owns the Amazon/Microsoft/Google/IBM cloud where they run all the voice-recon algorithms.
- azernik 12y agoAlso Google Now (for devices that are always listening for the "trigger word"), where your phone will make a very distinctive noise and pop up a screen to indicate that it's listening.
- teapowered 12y agoIt's about targeted advertising - arguing with your spouse? Next ad break we show you adverts for lawers.
- lotu 12y agoI don't think anyone actually wants to do that. I work in advertising with video and the people I've talked don't appear to think this is a good idea.
- _asummers 12y agoAs far as networking is concerned, what should I google for separating a device like this onto its own internal private network? I have devices that I want to whitelist traffic for while not affecting other devices in my home.
- thirsteh 12y agoWhy not just disconnect it from the network?
- _asummers 12y agoSure, that's one solution. But let's take the Samsung example. What happens when the device needs to update firmware? I want to allow traffic of that sort, while disallowing things such as the voice communication.
- jimbobimbo 12y agoI device is disconnected from the network, it doesn't know that it "needs to update firmware".
- teacup50 12y agoWhy does your device need to update firmware? It's an appliance. Its advertised features should work, and should continue to work.
- _asummers 12y agoSecurity vulnerabilities. Performance increases. All the devices that were vulnerable to Heartbleed (as an example) with no ability to update themselves are still vulnerable. One could argue that simply disconnecting the device would be sufficient, but this ignores the possibility of internet features being useful; I wasn't limiting the discussion to TVs.
- thirsteh 12y ago
- amluto 12y agoIt seems to me that, if you have one of these, you live in a two-party consent state (e.g. California), and you invite a guest who hasn't clicked the EULA over, then someone is committing felony wiretapping. I would love to see a TV vendor prosecuted for this.
- amelius 12y agoSo how about if somebody in California replies to an e-mail which was sent from gmail.com?
- jneal 12y agoIMO there is no expectation of privacy with email. Maybe only false expectation. If you go into someone's home and take part in private discussions, you probably don't anticipate being recording in any manner.
- threatofrain 12y agoI actually think there is a reasonable expectation to privacy, and that most people, from senators to elementary school teachers, believe that email is technically secure, meaning that "normal people" could not read their email even if they wanted to, at least not without resorting to "hacking" or "spying". In fact, one might say that email is more secure than normal mail, because normal mail doesn't have a password and is default delivered to a publicly accessible mailbox. If a neighbor wishes to invade your privacy via your email, how do they do so? Probably by entering your password somehow. If that person wants to steal your physical mail, how do they do so? By walking up to your mailbox when nobody is looking. Also, email at least has a very plausible chance of being encrypted; even if you don't know what that means, your workplace may be doing it for you. But companies, including financial or accountancy firms, don't encrypt physical email to their customers. I think most reasonable people have the belief that email is safer than mail, and in 2015 I think they might be right.
- Spooky23 12y ago
- brianpetro_ 12y agoThis immediately brought to mind Orwell's telescreens. http://en.wikipedia.org/wiki/Telescreen http://en.wikipedia.org/wiki/Telescreen
- 0942v8653 12y agoHere's an article actually comparing the two: http://www.brennancenter.org/analysis/im-terrified-my-new-tv-why-im-scared-turn-thing http://www.brennancenter.org/analysis/im-terrified-my-new-tv...
- patcheudor 12y agoI recently collected a bug bounty from Samsung on a crypto implementation flaw I found in some of their software. The fix is still being rolled out and given the impact I'm not going to disclose right now, rather I'll let Samsung handle that when the time is right. Anyway, the team at Samsung was responsive and they seemed like they genuinely cared about security. However, based on what I've seen in their products and those from their competitors the first thing I would do is pen-test the voice recognition feature, then turn it off no matter the outcome. The fact is, if it must communicate with a back-end server to work, then it becomes incredibly hard to lock the solution down. Even if the TV is properly validating the public cert of the server when doing the TLS handshake, there's got to be a mechanism on the TV for updating the trusted root store because at the end of the day, certs need to expire and thus must be updated. On a few non Samsung smart TV's I've looked at over the years, updating the trusted root store on the TV is as "easy" as man in the middling (MitM) the network the TV is on so that web traffic goes to a site I own which has a link to the my.cer root CA that I generated and am using in my TLS MitM solution. From there I just bring up the web browser on the TV, click on the my.cer link and go through the prompts to install the root CA. After that point all traffic from the TV can be decrypted on the wire. Now it is fair to say that the attack I just described requires the ability to MitM the network and have physical access to the device, however, remember that these TV's use an IR remote & all an attacker needs is visual access to the TV. If it can be seen through a window it can be controlled through a window and these things typically don't require a password to modify the WiFi settings. Some smart TVs also have proxy settings which again, typically don't require a password to modify. Given what I just covered, think hotel. From a risk perspective that's what I'd be most worried about. I wonder how many are installing smart TVs with voice recognition? For all other scenarios basically the situation in many cases on the ground is that you are secure because no one is targeting you. In the case of a hotel, someone could be targeting everyone. Such an attack could prove valuable, especially if done in executive suites near financial centers.
- themodelplumber 12y agoWow. This combined with the fact that economic espionage has been receiving state sponsorship for a long time now is kind of unsettling. Cell phones are bad enough, but TVs...and really anything else that can use voice control (alarm clocks are my personal favorite) could be huge for spies.
- jsilence 12y agoGiven that voice recognition is possible offline on a RaspberryPi Version 1 [1] I'm wonderung why they have to send the recorded audio to the cloud in the first place. [1] https://jasperproject.github.io/ https://jasperproject.github.io/
- lotu 12y agoCloud based versions work significantly better. They are able to put perhaps 10,000 times* more processing power into recognizing what you said. They are better able to deal with different people, background noise, and tick accents. When you are making a consumer device this is critical. *I pulled this number out of the air
- sukilot 12y agoReliable local behavior is also critical in a consumer device. dragon dictate and mac os x have had voice rec for over a decade.
- nl 12y agoAndroid voice recognition can now be used offline[1]. You download the trained recognition model (which took much, much more than 10,000 times more processing power to train), and then it works without a network connection. [1] http://androidwidgetcenter.com/android-tips/how-to-use-offline-speech-recognition-in-jelly-bean/ http://androidwidgetcenter.com/android-tips/how-to-use-offli...
- shmerl 12y agoA good lesson why one shouldn't use any systems with DRM. People are so upset about mass surveillance by the government, yet they readily subject themselves to mass surveillance of DRM systems. Where is logic?
- frik 12y agoIt's not only Samsung Smart-TV but all cloud-based speech recognition products, right? (Nuance/Apple Siri, Microsoft Cortana, Google Now, IBM Watson Speech, Amazon Echo, LG-Smart TV, etc.) From a consumer perspective you want an offline speech product like Nuance Dragon NaturallySpeaking: http://en.wikipedia.org/wiki/Dragon_NaturallySpeaking http://en.wikipedia.org/wiki/Dragon_NaturallySpeaking (it's the same technology that powers Nuance cloud based products like Apple Siri, IBM Watson, etc.)
- cbr 12y agoMost of those products locally recognize an activation command: "hey siri", "ok google", "alexa", ... and then send the next phase to the cloud for interpretation. With Samsung's Smart-TV, however, it sounds like everything you say is uploaded so that they can recognize "Channel Up", "Smart Hub" etc.
- stevep98 12y agoYeh, you'd think that based on all the comments you read here. But, if anyone commenting had actually used one of the new samsung smart TV's with this feature, you'd see that this is being blown out of proportion. The TV isn't even listening for a keyword. It's waiting for you to press a button on the remote. The microphone for voice control is actually in the remote itself. Samsung Smart TV remote with Voice button: http://goo.gl/DkgWPb http://goo.gl/DkgWPb I would caveat the above by saying that the TV may also have a microphone in it, because I have noticed that when you use the built-in skype app, the camera does a cool digital/zoom to highlight whoever is speaking, which it probably does either with a microphone array, or moving-lips detection in the camera. The camera, by the way, can be physically disabled when not in use, by pushing it into the TV.
- bgruber 12y agoThe Samsung TVs do perform voice recognition through the mic on the TV as well as on the remote (well, at least mine, which is a couple years old, does). Even if you have the voice recognition setting turned off, the one on the remote still works by pressing the button. The non-remote one does use a trigger word ("hi tv" by default) and it definitely does that processing locally (I know because i disconnected my TV from the internet and tried it). Basic commands ("channel up" etc) also worked. I don't know what else to try to figure out when it goes out to the internet. I'd also add that the camera/microphone have a very visible hardware off (which I keep off, because life is too much like 1984 already). Again, this is a 2013 model.
- Animats 12y ago"Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition." "Your SmartTV is equipped with a camera that enables certain advanced features, including the ability to control and interact with your TV with gestures and to use facial recognition technology to authenticate your Samsung Account on your TV." We've come so far since Orwell's "telescreen" in "1984". "Big Brother is watching YOU."
- huxley 12y agoThe telescreens in 1984 were two-way, it was mentioned in the scene with the exercise instructor : "‘Smith!’ screamed the shrewish voice from the telescreen. ‘6079 Smith W.! Yes, YOU! Bend lower, please! You can do better than that. You’re not trying. Lower, please! THAT’S better, comrade. Now stand at ease, the whole squad, and watch me.’ A sudden hot sweat had broken out all over Winston’s body. His face remained completely inscrutable. Never show dismay! Never show resentment!"
- ChuckMcM 12y agoInteresting, there is the vocal recognition thing but the camera equipped to do facial recognition is much more worrisome. Check into a hotel room wearing a ski mask, sneak up to the TV and put tape over the camera if you can find it. Nothing like downloading the facial recognition features of Carmen San Diego into all the hotel TV's in a country to see where she is staying. License plate readers don't hold a candle to this. Now to check to see if every Samsung TV coming into the US has to go through 'special customs checking' ...
- api 12y agoWhy is the cloud required for speech to text when a four core ARM SOC is under 15 dollars? My Commodore 64 had good text to speech, and Dragon was doing speech to text on 90s PCs. I don't get the technical rationale.
- DanBC 12y agoYou needed to train Dragon and you needed to calibrate the microphone. People talking to control their tv's want to be able to iist talk. Thus, instead of training the software you offload that training to the cloud and massive computing to do it. I agree that the tv setup could include a bit of voice recognition training. But then the TV only changes channels if Ann asks it to. Bob's out of luck, he has to use the remote.
- api 12y agoAhh... that explains it a little more... though I don't see why you couldn't just share model data via the cloud instead of actually sending audio from a microphone directly out to a remote endpoint. But then again anything with an Internet connection and a mic (laptop, cell phone, etc.) is a potential spy device with the right malware installed.