• Septimaeus@infosec.pub
    link
    fedilink
    arrow-up
    50
    arrow-down
    3
    ·
    6 months ago

    A moderately technical user can check this themselves today with basic local network traffic monitors or packet sniffing utilities, since even heavily compressed audio data will stand out no matter how it’s encrypted, streamed, chunked, etc.

    But for the sake of argument let’s assume some really clever software that allows local voice recognition, processing, inconspicuous delayed batch uploads, etc. In addition let’s assume a completely compromised device, rooted/jailbroken with all sandboxing and system integrity disabled. Even then, a phone will struggle to record and process audio impromptu without an immediately noticeable impact on energy and data use.

    I’m not saying advertising companies wouldn’t love to collect that much raw data, just that it seems like quite a challenge to do so quietly.

    • admiralteal@kbin.social
      link
      fedilink
      arrow-up
      21
      ·
      6 months ago

      There’s also a totally plausible and far more insidious answer to what’s going on with the experiences people have of the ads matching their conversations.

      That explanation is advertising works. And worse, it works subconsciously. That you’re seeing the ads and don’t even notice you’re seeing them and then they’re worming their way into your conversations at which point you become more aware of them and then start noticing the ads.

      Which does comport with the billions of dollars spent on advertising every year. It would be very weird if an entire ad industry that’s at least a century old was all a complete nonsense waste of money this whole time.

      To me, this whole narrative is just another parable about why we need to do everything possible to limit our own exposure to ads to avoid being manipulated.

      • Septimaeus@infosec.pub
        link
        fedilink
        arrow-up
        6
        ·
        edit-2
        6 months ago

        Damn, I hadn’t thought of that. The chicken egg question of spooky ad relevance. Insidious indeed.

        I feel like the idea of some person or group having enough info to psychologically manipulate or predict should be way scarier than the black helicopter stuff, especially given that it’s one of the few conspiracy theories we actually have a bunch of high quality evidence for, like marketing textbooks and statistics.

        But here we are. Government surveillance is the hot button, not the fact that marketers would happily sock puppet you given the chance.

    • WetBeardHairs@lemmy.ml
      link
      fedilink
      arrow-up
      15
      arrow-down
      2
      ·
      6 months ago

      That is glossing over how they process the data and transmit it to the cloud. The assistant wake word for “Hey Google” invokes an audio stream to an off site audio processor in order to handle the query. So that is easy to identify via traffic because it is immediate and large.

      The advertising-wake words do not get processed that way. They are limited in scope and are handled by the low power hardware audio processor used for listening for the assistant wake word. The wake word processor is an FPGA or ASIC - specifically because it allows the integration of customizable words to listen for in an extremely low power raw form. When an advertising wake word is identified, it sends an interrupt to the CPU along with an enumerated value of which word was heard. The OS then stores that value and transmits a batch of them to a server at a later time. An entire day’s worth of advertising wake word data may be less than 1 kb in size and it is sent along with other information.

      Good luck finding that on wireshark.

      • Septimaeus@infosec.pub
        link
        fedilink
        arrow-up
        7
        ·
        edit-2
        6 months ago

        Hmm, that’s outside my wheelhouse. So you’re saying phone hardware is designed to listen for not just one but multiple predefined or reprogrammable bank of wake words? I hadn’t read about that yet but it sounds more feasible than the constant livestream idea.

        The echo had the capacity for multiple wake words IIRC, but I hadn’t heard of that for mobile devices. I’m curious how many of these key words can they fit?

    • Zerush@lemmy.mlOP
      link
      fedilink
      arrow-up
      10
      arrow-down
      2
      ·
      edit-2
      6 months ago

      Smartphones by definition are Spyware, at least if you use the OS as is, because in them all aspects are controlled and logged, either by Google on Android or by Apple on iOS. Adding the default apps that cannot be uninstalled on a mobile that is not rooted. As COX alleges, they also use third-party logs and therefore can track and profile the user very well, even without using this technology that they claim to have.

      Although they feel authorized by the user’s consent to the TOS and PP, the legality depends directly on the legislation of each country. TOS and PP itself, to be a legal contract, must comply in all its points with local legislation to be applicable to the user. For this reason, I think that these practices are very different in the EU from those in the US, where legislation regarding privacy is conspicuous by its absence, that is, that US users should take these COX statements very seriously in their devices, although in the EU they must also be clear that Google and Apple know exactly what they do and where users live, although they are limited from selling this data to third parties.

      Basics:

      – READ ALWAYS TOS AND PP

      • Review the permissions of each app, leaving only the most essential ones
      • Desactivate GPS if not used
      • Review in Android every app with Exodus Privacy, maybe Lookout or MyCyberHome in iOS (Freemium apps !!!)
      • Use as less possible apps from the store
      • Be aware of discount apps from the Supermarket or Malls
      • Don’t store important data in the Phone (Banking, Medical…)
      • Septimaeus@infosec.pub
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        edit-2
        6 months ago

        Agreed, though I think it’s possible to use smart devices safely. For Android it can be difficult outside custom roms. The OEM flavors tend to have spyware baked in that takes time and root to fully undo, and even then I’m never sure I got it all. These are the most common phones, however, especially in economy price brackets, which is why I’d agree that for the average user most phones are spyware.

        Flashing is not useful advice to most. “Just root it bro” doesn’t help your nontechnical relatives who can’t stop downloading toolbars and VPN installers. But with OEM variants undermining privacy at the system level, it feels like a losing battle.

        I’d give credit to Apple for their privacy enablement, especially with E2EE, device lockdown, granular access permission control and audits. Unfortunately their devices are not as affordable and I’m not sure how to advise the average Android user beyond general opt-out vigilance.

          • Septimaeus@infosec.pub
            link
            fedilink
            arrow-up
            1
            ·
            6 months ago

            Yeah those push token systems need an overhaul. IIRC tokens are specific to app-device combinations, so invalidation that isn’t automatic should be push-button revocation. Users should have control of it like any other API on their device, if only to get apps to stop spamming coupons or whatever.

            It’s funny though: when I first saw those headlines, my first reaction was that it was a positive sign, since this was apparently news worthy even though the magnitude of impact for this sort of systemic breach is demonstrably low. (In particular, it pertains to (1) incidental high-noise data (2) associated with devices and (3) available only by request to (4) governments, who are weak compared to even the smallest data brokers WRT capacity for data mining inference and redistribution, to put it mildly.)

            Regardless, those systems need attention. Hopefully in an upcoming release.

    • Андрей Быдло@sh.itjust.works
      link
      fedilink
      arrow-up
      7
      ·
      6 months ago

      most phones will just struggle to record and process audio indeterminately without a noticeable impact on energy and data use.

      I mean, it’s still a valid concern for a commoner. Why my phone has twice the ram and twice the cores and is as slow as my previous one? I’d love to fuel this conspiracy into OS, app makers to do their fucking job.

      There’s no reason an app can weight more than 50mb on clean install*, and many socials, messengers fail to fit in. A client I use to write this is only 30+, and that’s one person doing that for donations.

      If there could be a raging theory that apps are selling your data to, like, China, there would be a push to decline it and optimize apps to fit that image.

      * I obviously exclude games, synths, editors of any kind with their textures and templates.

      • WetBeardHairs@lemmy.ml
        link
        fedilink
        arrow-up
        3
        ·
        6 months ago

        The filesize of most binaries is dominated by text strings and images. Modern applications are loaded with them. Lemmy is atypical in that it doesn’t need tons of built in images or text.

    • Cheradenine@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      6 months ago

      Fucking thank you. As I said in another reply, if this was true my firewall logs would be full, or my data cap blown in a week.

    • library_napper@monyet.cc
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      6 months ago

      What if the processing is don’t locally and the only thing they send back home is keywords for marketable products?

      • Septimaeus@infosec.pub
        link
        fedilink
        arrow-up
        4
        ·
        edit-2
        6 months ago

        Yeah they’d have to it seems, but real time transcription isn’t free. Even late model devices with better inference hardware have limited battery and energy monitoring. I imagine it’d be hard to conceal that behavior especially for an app recording in the background.

        WetBeardHairs@lemmy.ml mentioned that mobile devices use the same hardware coprocessing used for wake word behavior to target specific key phrases. I don’t know anything about that, but it’s one way they could work around the technical limitations.

        Of course, that’s a relatively bespoke hardware solution that might also be difficult to fully conceal, and it would come with its own limitations. Like in that case, there’s a preset list of high value key words that you can tally, in order to send company servers a small “score card” rather than a heavy audio clip. But the data would be far less rich than what people usually think of with these flashy headlines (your private conversations, your bowel movements, your penchant for musical theater, whatever).

    • Goun@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      6 months ago

      I agree.

      What could be possible, would be maybe send tiny bits. For example, a device could categorize some places or times, detect out of pattern behaviours and just record a couple of seconds here and there, then send it to the server when requesting something else to avoid being suspicious. Or just pretend it’s a “false positive” or whatever and say “sorry, I didn’t get that.”

      I don’t think they’re listening to everything, but they could technically get something if they wanted to target you.

      • Septimaeus@infosec.pub
        link
        fedilink
        arrow-up
        1
        ·
        edit-2
        6 months ago

        Right, I suppose cybersecurity isn’t so different than physical security in that way. Someone who really wants to get to you always can (read: why there are so many burner phones at def con).

        But for the average person, who uses consumer grade deadbolts in their home and doesn’t hire a private detail when they travel, does an iPhone fit within their acceptable risk threshold? Probably.

    • Saik0@lemmy.saik0.com
      link
      fedilink
      English
      arrow-up
      26
      arrow-down
      6
      ·
      edit-2
      6 months ago

      It’s just they’re no longer afraid of telling us they are

      They’re also lying to themselves…

      https://web.archive.org/web/20231214235444/https://www.cmglocalsolutions.com/blog/active-listening-an-overview

      Is Active Listening Legal?

      We know what you’re thinking. Is this even legal? The short answer is: yes. It is legal for phones and devices to listen to you. When a new app download or update prompts consumers with a multi-page terms of use agreement somewhere in the fine print, Active Listening is often included.

      They believe that just because the phone’s owner agrees that it’s legal. If my wife accepts a ToS that allows them to monitor her, and her phone is in my room listening to me… That’s definitely NOT legal. This really needs to hit court sooner rather than later. This is wiretapping, this is illegal REGARDLESS of the ToS/EULA nonsense they want to claim covers them.

      Edit: Even in one-party consent states this is illegal.

      • ddh@lemmy.sdf.org
        link
        fedilink
        English
        arrow-up
        15
        ·
        edit-2
        6 months ago

        Let’s also remember that these phones are sold worldwide, and it’s foolish to declare something globally legal.

    • Vinegar@kbin.social
      link
      fedilink
      arrow-up
      23
      arrow-down
      2
      ·
      6 months ago

      Companies DO analyze what you say to smart speakers, but only after you have said “ok google, siri, alexa, etc.” (or if they mistake something like “ok to go” as “ok google”). I am not aware of a single reputable source claiming smart speakers are always listening.

      The reality is that analyzing a constant stream of audio is way less efficient and accurate than simply profiling users based on information such as internet usage, purchase history, political leanings, etc. If you’re interested in online privacy device fingerprinting is a fascinating topic to start understanding how companies can determine exactly who you are based solely on information about your device. Then they use web tracking to determine what your interests are, who you associate with, how you spend your time, what your beliefs are, how you can be influenced, etc.

      Your smart speaker isn’t constantly listening because it doesn’t need to. There are far easier ways to build a more accurate profile on you.

      • ristoril_zip@lemmy.zip
        link
        fedilink
        English
        arrow-up
        5
        arrow-down
        7
        ·
        6 months ago

        It’s literally impossible for them to not be “analyzing” all the sounds they (perhaps briefly) record.

        [Sound] --> [Record] --> [Analyze for keyword] --> [Perform keyword action] OR [Delete recording]

        Literally all sounds, literally all the time. And we just trust that they delete them and don’t send them “anonymized” to be used for training the audio recognition algorithms or LLMs.

        • bdonvr@thelemmy.club
          link
          fedilink
          arrow-up
          11
          ·
          6 months ago

          It is possible to analyze the traffic leaving these devices, and AFAIK it hasn’t been shown that they are doing this.

        • Solemn@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          10
          ·
          6 months ago

          The way that “Hey Alexa” or “Hey Google” works is by, like you said, constantly analysing the sounds they said. However, this is only analyzed locally for the specific phrase, and is stored in a circular buffer of a few seconds so it can keep your whole request in memory. If the phrase is not detected, the buffer is constantly overwritten, and nothing is sent to the server. If the phrase is detected, then the whole request is sent to the server where more advanced voice recognition can be done.

          You can very easily monitor the traffic from your smart speaker to see if this is true. So far I’ve seen no evidence that this is no longer the common practice, though I’ll admit to not reading the article, so maybe this has changed recently.

          • uzay@infosec.pub
            link
            fedilink
            arrow-up
            1
            ·
            6 months ago

            If they were to listen for a set of predefined product-related keywords as well, they could take note of that and send that info inconspicuously to their servers as well without sending any audio recordings. Doesn’t have to be as precise as voice command recognition either, it’s just ad targeting.

            Not saying they do that, but I believe they could.

        • Solemn@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          10
          ·
          6 months ago

          It’s been published by multiple sources at this point that this happens because of detected proximity. Basically, they know who you hang out with based on where your phones are, and they know the entire search history of everyone you interact with. Based on this, they can build models to detect how likely you are to be interested in something your friend has looked at before.

          • NekuSoul@lemmy.nekusoul.de
            link
            fedilink
            arrow-up
            9
            ·
            edit-2
            6 months ago

            Yup. For companies it’s much safer to connect the dots with the giant amount of available metadata in the background than risk facing a huge backlash when people analyze what data you’re actively collecting.

            Which is why people need to call out the tracking that’s actually happening in the real world a lot more, because I don’t really want my search-history leaked by proxy to people in my proximity either.

        • Zeroc00l@sh.itjust.works
          link
          fedilink
          arrow-up
          10
          ·
          6 months ago

          So, you and your friend were talking about a subject you obviously are interested in, likely spend heaps of time online searching about, commenting and following on social media and you’re surprised you got an ad for it? Bonkers.

        • Chozo@kbin.social
          link
          fedilink
          arrow-up
          17
          arrow-down
          1
          ·
          6 months ago

          Following an investigation by Bloomberg, the company admitted that it had been employing third-party contractors to transcribe the audio messages that users exchanged on its Messenger app.

          So not your IRL conversations.

          There is no indication that Facebook has used the information it collected to sell ads.

          So not for ads.

          It says the opposite of the things you claimed.

        • iAmTheTot@kbin.social
          link
          fedilink
          arrow-up
          6
          ·
          6 months ago

          I generally don’t go out of my way to validate every crazy thing I read on the internet without any backing evidence supplied.

        • null@slrpnk.net
          link
          fedilink
          arrow-up
          3
          ·
          6 months ago

          There is. And the parent commenter can use it to find and share evidence for their claim.

  • Snot Flickerman@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    13
    ·
    6 months ago

    Services that “listen” for commands like Siri and Alexa have to be, by default, always listening, because otherwise they would not be able to hear the activate command. They are supposed to dump the excess data like anything that came before the activation command, but that’s just a promise. There are very few laws protecting you if that promise turns out to be a lie. The best you can get is likely small restitution through a class action lawsuit (if you didn’t waiver right to that by agreeing to the Terms of Service, which is more often than not, now).

    Of fucking course they’re listening.

    • null@slrpnk.net
      link
      fedilink
      arrow-up
      11
      arrow-down
      1
      ·
      6 months ago

      They are supposed to dump the excess data like anything that came before the activation command, but that’s just a promise.

      Where are they hiding that data locally, and how are they making it invisible in transit?