LACyber: Cyber Security Blog

cyber security buffalo western new york
a division of Lincoln Archives Inc.


Can Your Smart Speaker "Hear" You?

by Kathryn Turner

While millions of people use Bluetooth smart devices and software every day to ask the weather, play music, and remember a shopping list, many more are reluctant to use these devices let alone allow them in their homes. For fear that there is someone on the other end listening.

Now we know that sometimes, someone is listening.

There are thousands of people employed at Amazon, with the sole responsibility of improving functionality of the Echo speakers. In order to do that, sometimes they need to listen to voice recordings captured in Echo owners’ homes and offices. These recordings are said to be recorded and transcribed in order to eliminate gaps in the Alexa’s understanding of human speech and allow the software to be more responsive to human speech.

Bloomberg highlighted the topic after speaking to Amazon staff who "reviewed" Alexa recordings. They say voice recordings are occasionally reviewed to improve speech recognition.

But many customers are still unaware that humans may be listening.

Amazon refers to Alexa as “living in the cloud” and “always getting smarter.”

But like many software tools built to learn from experience, humans are doing some of the teaching.

Amazon's voice recordings are associated with an account number, the customer's first name and the serial number of the Echo device used. Some of the workers have even admitted to sharing clips people would rather stay private- bad shower singing, little kids screaming etc., and they shared them amongst themselves in an internal chat room. All in the name of improving functionality.

But what was Amazon’s response to this?

In a statement, Amazon said it took security and privacy seriously and only looked at "an extremely small sample of Alexa voice recordings".

"This information helps us train our speech recognition and natural language understanding systems, so Alexa can better understand your requests, and ensure the service works well for everyone," it said in a statement.

They boast very strict technical and operational safeguards and have a “zero tolerance policy for the abuse of our system. Employees do not have direct access to information that can identify the person or account as part of this workflow."

The terms and conditions for Amazon's Alexa service state that voice recordings are used only to "answer your questions, fulfil your requests, and improve your experience and our services". But once again, human reviewers are not explicitly mentioned when you bring an Alexa into your home.

 

But Amazon is not the only player in this field, forces such as Google and Apple are big contributors as well. They too rely on human intervention to improve the efficiency and usability of their smart speakers.

Apple also has human reviewers who make sure its voice assistant Siri is interpreting requests correctly. Siri records voice commands given through the iPhone and HomePod smart speaker.

According to Apple's security policy, voice recordings are not personally identifiable and are linked to a random ID number, which is reset every time Siri is switched off. Any voice recordings kept after six months are stored without the random ID number.

What about Google?

Google said human reviewers could listen to audio clips from its Assistant, which is embedded in most Android phones and the Home speaker.

It said clips were not associated with personally identifiable information and the company also distorted the audio to disguise the customer's voice.

But are smart speakers recording all my conversations? Should we be worried that smart speakers are secretly recording everything that is said while we’re at home?

While these smart speakers are technically always able to hear us, very rarely are they actually listening to our daily lives. They’re simply waiting on “wake up” words such as Alexa, Ok Google or Hey Siri.

If the wake-up word isn’t heard, then the device won’t activate. However, once a wake-up word is heard the rest of the conversation is “listened to”.

While these tech giants are all clinging to the security and helpful nature of their machines, it’s important to stay diligent. Are they being completely transparent with how information is recorded? That’s yet to be known, but all we can say for certainty is there is someone at the other end of smart speakers. The only question know is how much do they actually hear?

LACyber is a division of Lincoln Archives providing comprehensive Data Breach Defense Services. Lincoln Archives and LACyber are proud to be a part of Lincoln Family of Companies serving the Western New York Community since 1914.

Return to Blog Menu

Contact Information:


LACyber
155 Great Arrow
Buffalo, New York
14207
(716) 871-7040
Email: info@LincolnArchives.com

Recent Blog Posts:

Is Tape Back Up Still Relevant?
As the years go on, tape is not going away. In fact, the technology behind tapes is improving! The question is: are there enough discussions taking place about this data back-up method?
Author: Sally Rozumalski - Date: 2019-06-13
Data Destruction, What is the Big Deal?
Ensuring the secure destruction of private data not only gives you piece of mind, but also could potentially save you thousands if not millions of dollars in data breach fines.
Author: Sally Rozumalski - Date: 2019-04-19
Can Your Smart Speaker "Hear" You?
Millions of people turn to their smart home devices for the weather, music or just a good laugh. But do you ever wonder if your smart device can actually hear whats being said, or where that information might go?
Author: Kathryn Turner - Date: 2019-04-12
The Gap in Risk Protection You Won’t See Coming
Your office network is a complex compilation of interconnected machines which cyber criminals seek to break into. So what part of your office is the most vulnerable to a data breach?
Author: Sally Rozumalski - Date: 2019-04-05
Ransomware and Company Closings: Could You be Next?
 Ransomware is continuing to hit businesses, will more force and impact each year. Malicious software and the infamous effects that accompany it, are starting to effect companies on a larger scale than a simple inconvenience including shutdowns, fines, and years lost.
Author: Sally Rozumalski - Date: 2019-03-29
See All Blog Posts

Contact Form




Cyber Defense Plans starting at $49.99