• PeterisBacon@lemm.ee
    link
    fedilink
    English
    arrow-up
    16
    ·
    22 days ago

    I have always told people to avoid Amazon.

    They have doorbells to watch who comes to your house and when.

    Indoor and outdoor security cameras to monitor when you go outside, for how long, and why.

    They acquired roomba, which not only maps out your house, but they have little cameras in them as well, another angle to monitor you through your house in more personal areas that indoor cameras might not see.

    They have the Alexa products meant to record you at all times for their own use and intent.

    Why do you think along with Amazon Prime subscriptions you get free cloud storage, free video streaming, free music? They are categorizing you in the most efficient and accurate way possible.

    Boycott anything Amazon touches

    • SpaceNoodle@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      22 days ago

      Off-device processing has been the default from day one. The only thing changing is the removal for local processing on certain devices, likely because the new backing AI model will no longer be able to run on that hardware.

      • 4am@lemm.ee
        link
        fedilink
        English
        arrow-up
        4
        ·
        22 days ago

        With on-device processing, they don’t need to send audio. They can just send the text, which is infinitely smaller and easier to encrypt as “telemetry”. They’ve probably got logs of conversations in every Alexa household.

          • deranger@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            2
            ·
            edit-2
            22 days ago

            Why has no security researcher published evidence of these devices with microphones uploading random conversations? Nobody working on the inside has ever leaked anything regarding this potentially massive breach of privacy? A perfectly secret conspiracy by everyone involved?

            We know more about top secret NSA programs than we do about this proposed Alexa spy mechanism. None of the people working on this at Amazon have wanted to leak anything?

            I’m not saying it’s not possible, but it seems extremely improbable to me that everyone’s microphones are listening to their conversations, they’re being uploaded somewhere to serve them better ads, and absolutely nobody has leaked anything or found any evidence.

              • catloaf@lemm.ee
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                22 days ago

                Per that article, it only happens when it thinks it’s been activated, and only when you opt in. Not much of a bombshell.

                • hungprocess@lemmy.sdf.org
                  link
                  fedilink
                  English
                  arrow-up
                  3
                  ·
                  22 days ago

                  Emphasis on “when it thinks”. Not much point to a privacy control that the device can just ignore for unspecified reasons, and they had 150+ instances of that occurring in this data set.

              • deranger@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                0
                arrow-down
                1
                ·
                edit-2
                22 days ago

                Sure, but that’s not the commonly repeated conspiracy, even by non technical normal people, that everyone’s mics are listening all the time and they’re being used to serve you ads or whatever. The scale of this is not at all comparable to what I’m talking about. Yeah, I’m sure sometimes devices are inactivated inadvertently, those responses are uploaded, and people have listened to those recordings when they didn’t have permission. That is a far cry from all devices listening nearly all the time, using some surreptitious method to upload the data, and what was being recorded being used for some nefarious purpose.

                Again, I’m not excusing these devices for being a privacy nightmare, but I just think it’s extremely implausible that Alexa, Siri, Google, etc. are always listening and nobody has discovered a device uploading.

                The real privacy nightmare is that recording your conversations is completely unnecessary to build a richly detailed profile of you and your contacts. Regular old device / browser fingerprinting and a few people in your group sharing contacts with apps is enough for that, and it’s not a top secret conspiracy.

            • takeda@lemm.ee
              link
              fedilink
              English
              arrow-up
              1
              ·
              22 days ago

              Because if they would publish it, the other security experts would say “well, duh, that’s how it works”.

              It is just the average people that are unaware of it, or don’t seem to care.

              • deranger@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                edit-2
                22 days ago

                I’m not saying it’s not possible

                There is no argument from ignorance fallacy in what I said. I am not claiming these devices never send audio without you wanting because there’s no evidence to the contrary.

                However, the idea that everyone’s microphones are always listening, and that’s why you saw an ad for whatever after talking to your friend, yet not a single person has observed a device uploading this kind of data, nor has anyone ever leaked any kind of information on this supposed system, is extremely unlikely to be true in my opinion.

                They don’t need microphones to do this. Regular tracking is plenty to do a good job at suggesting you a highly relevant ad, and frequency illusion does the rest. You’re not noticing the thousand times you see ads that are irrelevant to whatever you were talking about, but the one time you do notice really sticks out.

          • loie@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            22 days ago

            I mean… I 100% agree, and yet you and I and everyone reading this are carrying around a phone that can do the exact same shit

            • Ulrich@feddit.org
              link
              fedilink
              English
              arrow-up
              1
              ·
              22 days ago

              I am not, thank you very much. Even if I wasn’t, you can simply disable the wake word. And you can go into your account and see/listen to any recordings it has made.

    • tal@lemmy.today
      link
      fedilink
      English
      arrow-up
      4
      ·
      22 days ago

      If you look at the article, it was only ever possible to do local processing with certain devices and only in English. I assume that those are the ones with enough compute capacity to do local processing, which probably made them cost more, and that the hardware probably isn’t capable of running whatever models Amazon’s running remotely.

      I think that there’s a broader problem than Amazon and voice recognition for people who want self-hosted stuff. That is, throwing loads of parallel hardware at something isn’t cheap. It’s worse if you stick it on every device. Companies — even aside from not wanting someone to pirate their model running on the device — are going to have a hard time selling devices with big, costly, power-hungry parallel compute processors.

      What they can take advantage of is that for a lot of tasks, the compute demand is only intermittent. So if you buy a parallel compute card, the cost can be spread over many users.

      I have a fancy GPU that I got to run LLM stuff that ran about $1000. Say I’m doing AI image generation with it 3% of the time. It’d be possible to do that compute on a shared system off in the Internet, and my actual hardware costs would be about $33. That’s a heckofa big improvement.

      And the situation that they’re dealing with is even larger, since there might be multiple devices in a household that want to do parallel-compute-requiring tasks. So now you’re talking about maybe $1k in hardware for each of them, not to mention the supporting hardware like a beefy power supply.

      This isn’t specific to Amazon. Like, this is true of all devices that want to take advantage of heavyweight parallel compute.

      I think that one thing that it might be worth considering for the self-hosted world is the creation of a hardened network parallel compute node that exposes its services over the network. So, in a scenario like that, you would have one (well, or more, but could just have one) device that provides generic parallel compute services. Then your smaller, weaker, lower-power devices — phones, Alexa-type speakers, whatever — make use of it over your network, using a generic API. There are some issues that come with this. It needs to be hardened, can’t leak information from one device to another. Some tasks require storing a lot of state — like, AI image generation requires uploading a large model, and you want to cache that. If you have, say, two parallel compute cards/servers, you want to use them intelligently, keep the model loaded on one of them insofar as is reasonable, to avoid needing to reload it. Some devices are very latency-sensitive — like voice recognition — and some, like image generation, are amenable to batch use, so some kind of priority system is probably warranted. So there are some technical problems to solve.

      But otherwise, the only real option for heavy parallel compute is going to be sending your data out to the cloud.

      Having per-household self-hosted parallel compute on one node is still probably more-costly than sharing parallel compute among users. But it’s cheaper than putting parallel compute on every device.

      Linux has some highly-isolated computing environments like seccomp that might be appropriate for implementing the compute portion of such a server, though I don’t know whether it’s too-restrictive to permit running parallel compute tasks.

      In such a scenario, you’d have a “household parallel compute server”, in much the way that one might have a “household music player” hooked up to a house-wide speaker system running something like mpd or a “household media server” providing storage of media, or suchlike.

  • DirkMcCallahan@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    22 days ago

    Today: “…they will be deleted after Alexa processes your requests.”

    Some point in the not-so-distant future: “We are reaching out to let you know that your voice recordings will no longer be deleted. As we continue to expand Alexa’s capabilities, we have decided to no longer support this feature.”

  • fubarx@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    22 days ago

    So… if you own an inexpensive Alexa device, it just doesn’t have the horsepower to process your requests on-device. Your basic $35 device is just a microphone and a wifi streamer (ok, it also handles buttons and fun LED light effects). The Alexa device SDK can run on a $5 ESP-32. That’s how little it needs to work on-site.

    Everything you say is getting sent to the cloud where it is NLP processed, parsed, then turned into command intents and matched against the devices and services you’ve installed. It does a match against the phrase ‘slots’ and returns results which are then turned into voice and played back on the speaker.

    With the new LLM-based Alexa+ services, it’s all on the cloud. Very little of the processing can happen on-device. If you want to use the service, don’t be surprised the voice commands end up on the cloud. In most cases, it already was.

    If you don’t like it, look into Home Assistant. But last I checked, to keep everything local and not too laggy, you’ll need a super beefy (expensive) local home server. Otherwise, it’s shipping your audio bits out to the cloud as well. There’s no free lunch.

  • 52fighters@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    5
    ·
    22 days ago

    People are saying don’t get an echo but this is the tip of an iceberg. My coworkers’ cell phones are eavesdropping. My neighbors doorbells record every time I leave the house. Almost every new vehicle mines us for data. We can avoid some of the problem but we cannot avoid it all. We need a bigger, more aggressive solution if we are going to have a solution at all.

  • MintyFresh@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    22 days ago

    Easy fix: don’t buy this garbage to begin with. It’s terrible for the environment, terrible for your privacy, of dubious value to begin with.

    If every man is an onion, one of my deeper layers is crumudgeon. So take that into account when I say fuck all portable speakers. I’m so tired of hearing everyone’s shitty noise. Just fucking everywhere. It takes one person feeling entitled to blast the shittiest music available to ruin everyone in a 500yd radius’s day. If this is you, I hope you stub your toe on every coffee table, hit your head on every door jam, miss every bus.

  • Phoenixz@lemmy.ca
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    22 days ago

    They literally could just leave the feature on the device, but then you can’t force your users to send you all their data, voices, thoughts and first borns

    Fuck Amazon, fuck Bezos

    • PeteZa@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 days ago

      I agree. Although it’s nearly impossible at this point. Especially with Amazon running a significant portion of the internet with AWS. Each one of us most likely touches an Amazon server multiple times a day, even if we don’t have any Amazon subscriptions.

      • gamer@lemm.ee
        link
        fedilink
        English
        arrow-up
        3
        ·
        21 days ago

        That doesn’t matter. You only need to worry about boycotting things within your control, like Amazon shopping and their consumer products. AWS is profitable, but so is Amazon.com.

        Buying something at a different store is always a dub even if that store is using AWS on the backend.

    • Encrypt-Keeper@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      21 days ago

      I mean if they were doing this already there would be no point in sending this email out. They would have just happily continued letting people think it wasn’t happening while doing it anyway, while not having to deal with the backlash this will generate.

      • Teknikal@eviltoast.org
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        edit-2
        21 days ago

        My suspicion is they probably need to announce it now for some legal reason but there’s no Amazon device with the power to do this locally so it’s definitely always been sent to them.

        Now would they delete that right away or analyse it first, I kinda think they would have always done the latter.

    • bitjunkie@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      21 days ago

      The setting mentioned in the email was on by default. So they definitely were, they’re just removing the ability to turn it off.

  • Ronno@feddit.nl
    link
    fedilink
    English
    arrow-up
    2
    ·
    22 days ago

    Want to setup a more privacy friendly solution?

    Have a look at Home Assistant! It’s a great open source smart home platform that recently released a local (so not processing requests in the cloud) voice assistant. It’s pretty neat!

    • iarigby@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      22 days ago

      home assistant is amazing but it is not yet an alternative to Alexa, the assistant/voice is still in development and far from being usable. it’s impossible for me to remember the specific wording assist demands and voice to text is incorrect like nine out of ten times. And this includes giving up on terrible locally hosted models trying out their cloud which obviously is a huge privacy hole, but even then it was slow and inaccurate. It’s a mystery to me how the foss community is so behind on voice, Siri and Google Assistant started working offline years ago, and they work straight on a mobile device.

    • smiletolerantly@awful.systems
      link
      fedilink
      English
      arrow-up
      1
      ·
      22 days ago

      I have one big frustration with that: Your voice input has to be understood PERFECTLY by TTS.

      If you have a “To Do” list, and speak “Add cooking to my To Do list”, it will do it! But if the TTS system understood:

      • Todo
      • To-do
      • to do
      • ToDo
      • To-Do

      The system will say it couldn’t find that list. Same for the names of your lights, asking for the time,… and you have very little control over this.

      HA Voice Assistant either needs to find a PERFECT match, or you need to be running a full-blown LLM as the backend, which honestly works even worse in many ways.

      They recently added the option to use LLM as fallback only, but for most people’s hardware, that means that a big chunk of requests take a suuuuuuuper long time to get a response.

      I do not understand why there’s no option to just use the most similar command upon an imperfect matching, through something like the Levenshtein Distance.