{"id":14156,"date":"2018-12-21T10:10:20","date_gmt":"2018-12-21T18:10:20","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/12\/21\/news-7922\/"},"modified":"2018-12-21T10:10:20","modified_gmt":"2018-12-21T18:10:20","slug":"news-7922","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/12\/21\/news-7922\/","title":{"rendered":"Smart speakers: Christmas treat or lump of coal?"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 21 Dec 2018 17:30:00 +0000<\/strong><\/p>\n<p>Christmas is nearly upon us, and thoughts are perhaps turning to various <a href=\"https:\/\/www.theguardian.com\/technology\/2018\/dec\/14\/drones-dna-and-data-please-dont-give-the-gift-of-privacy-invasion\" target=\"_blank\" rel=\"noopener\">digital presents of a \u201csmart\u201d nature<\/a>. Home security, hubs, speakers, cameras, and mashups of all of those and more besides.<\/p>\n<p>With regards to speakers, the most immediate pieces of your home are theoretically at your beck and call.<\/p>\n<p>There\u2019s lots of <a href=\"https:\/\/www.theguardian.com\/technology\/shortcuts\/2018\/dec\/18\/how-to-protect-your-digital-privacy-from-new-christmas-presents\" target=\"_blank\" rel=\"noopener\">good advice<\/a> out there in terms of what to do with your new devices. Untick boxes, increase security, perhaps eliminate the \u201csmart\u201d feature entirely by ripping out batteries. However, is it possible that we\u2019re taking things a little too far? Are our concerns justified? Is there, perhaps, a somewhat happy middle ground where these devices can co-exist with us minus an endless sense of panic?<\/p>\n<p>Well, probably not. But maybe we can alleviate a few fears along the way.<\/p>\n<h3>Accidents will happen<\/h3>\n<p>This is a fact of life. Nothing is 100 percent secure, and nothing is 100 percent free from errors and mishaps. While this is scant consolation if something goes disastrously wrong, accepting that nothing is perfect sometimes goes a long way.<\/p>\n<p>Many of the more \u201coh no, now what\u201d news stories about smart speaker devices involved an accident, or an unforeseen use of the technology at hand.<\/p>\n<h3>Of dollhouses, cookies, and burgers<\/h3>\n<p>Many reported incidents are about accidental interactions between users and their devices. Of particular note is the 2017 story of a child somehow managing to <a href=\"https:\/\/www.theverge.com\/2017\/1\/7\/14200210\/amazon-alexa-tech-news-anchor-order-dollhouse\" target=\"_blank\" rel=\"noopener\">place an order<\/a> for a dollhouse and cookies through Amazon\u2019s Alexa. This became even more confusing when a TV segment apparently <a href=\"https:\/\/www.theregister.co.uk\/2017\/01\/07\/tv_anchor_says_alexa_buy_me_a_dollhouse_and_she_does\/\" target=\"_blank\" rel=\"noopener\">caused chaos<\/a> with a number of additional attempted orders. It\u2019s worth noting that none of those additional attempts seem to have resulted in purchases, so either we\u2019re missing some crucial part of the child\u2019s story or something genuinely malfunctioned in their home.<\/p>\n<p>We also have <a href=\"https:\/\/voicebot.ai\/2017\/09\/14\/south-park-pulls-burger-king-sets-off-amazon-alexa-google-homes-across-america\/\" target=\"_blank\" rel=\"noopener\">South Park pranks<\/a>, and the infamous Burger King ad <a href=\"https:\/\/www.theverge.com\/2017\/4\/12\/15259400\/burger-king-google-home-ad-wikipedia\" target=\"_blank\" rel=\"noopener\">triggering Google Home<\/a> to tell their owner all about burgers via text read out aloud from Wikipedia. While this is humorous, it could have easily invited some incredibly dubious messages into the home given anyone can edit Wikipedia text. In fact, the ad text was indeed <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-39589013\" target=\"_blank\" rel=\"noopener\">sabotaged<\/a>. What a world.<\/p>\n<h3>Privacy problems<\/h3>\n<p>Accidental recordings are perhaps the biggest potential problem, and certainly most likely to cause a privacy issue. In May 2018, a series of miscues caused private conversations to be <a href=\"https:\/\/business.financialpost.com\/technology\/personal-tech\/amazons-alexa-eavesdropped-on-a-couples-conversation-and-then-sent-the-recording-to-someone-else\" target=\"_blank\" rel=\"noopener\">sent to a random contact<\/a> via an Echo speaker. This is, of course, horrendous and could easily have ended in disaster depending on context.<\/p>\n<p>It\u2019s also essential that device owners read all EULAs and privacy policies thoroughly. They\u2019re <a href=\"https:\/\/www.youtube.com\/watch?v=xnwaZRyyIio\" data-rel=\"lightbox-video-0\" target=\"_blank\" rel=\"noopener\">complicated enough<\/a> for simple mobile games, without pondering the ramifications of real world interactions. As I mentioned on Top 10 VPN\u2019s Privacy Central article about this very subject, even if you <a href=\"https:\/\/www.top10vpn.com\/privacy-central\/privacy\/hey-google-what-do-you-do-with-my-data\/\" target=\"_blank\" rel=\"noopener\">read through a lot of legal words<\/a>, there\u2019s no guarantee everything won\u2019t change while you\u2019re not looking.<\/p>\n<h3>Listen closely?<\/h3>\n<p>The potential threat of always listening devices is prone to overhyping. The biggest issue tends to be accidental activation, from adverts or background noise. It&#8217;s rare for speakers to malfunction and listen of their own accord.<\/p>\n<p>Owners may wish to disallow voice activated devices from being able to lock or unlock entry points into the house, as this is an area of deliberate activation which could cause the most harm. They certainly don&#8217;t collect everything said, and are deliberately set up to avoid it. Grabbing everything 24\/7 would mean device\u00a0manufacturers simply couldn&#8217;t cope with all the data, so it&#8217;s in their best interests to be as concise and targeted as possible.<\/p>\n<p>As evidenced by Mozilla&#8217;s recent &#8220;<a href=\"https:\/\/foundation.mozilla.org\/en\/privacynotincluded\/\" target=\"_blank\" rel=\"noopener\">Privacy not included<\/a>&#8221; list, people seem to have a strong aversion to smart speakers. Amazon and Google&#8217;s devices are currently rated &#8220;super creepy&#8221; by voters, whereas the only smart speaker to have a positive &#8220;not creepy&#8221; rating at all is the open source Mycroft Mark 1. With a lack of insight into how closed systems are operating inside the home, it perhaps makes sense that people would turn to open source devices where they can get a better understanding of what\u2019s happening instead.<\/p>\n<h3>What\u2019s the biggest area of concern?<\/h3>\n<p>As I\u2019ve mentioned previously, I believe rogue IoT devices pose the biggest threat to <a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/07\/iot-domestic-abuse-can-stop\/\" target=\"_blank\" rel=\"noopener\">victims of domestic abuse<\/a>. This is due to ease of access to devices on the part of the malicious individual. The ability to control aspects of the home down to the smallest detail is a potential nightmare scenario. There are ways to combat this, but it&#8217;s risky and we always suggest professional support and assistance wherever possible.<\/p>\n<h3>Who speaks the truth?<\/h3>\n<p>All we can do is look at the evidence on offer and make an informed decision. If you\u2019re okay with the possibility of occasional accidental misfires or mischievous triggers, you&#8217;re good to go. We can\u2019t pretend these devices won\u2019t continue to make their way into our homes. What we can do is ensure we take steps to limit harm wherever possible. Keep on top of possible threats as and when they surface, and you&#8217;ll hopefully have no problems this festive season.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/smart-speakers-christmas\/\">Smart speakers: Christmas treat or lump of coal?<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/smart-speakers-christmas\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Fri, 21 Dec 2018 17:30:00 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/smart-speakers-christmas\/' title='Smart speakers: Christmas treat or lump of coal?'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2018\/12\/shutterstock_1104615416.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>If you&#8217;re interested in buying smart speakers this Christmas, you may be wondering how much of a privacy problem they really are. We take a look at this popular holiday present and separate the hype from the real issues at hand.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/\" rel=\"category tag\">Cybercrime<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/cybercrime\/privacy\/\" rel=\"category tag\">Privacy<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/christmas\/\" rel=\"tag\">Christmas<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/eula\/\" rel=\"tag\">EULA<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/privacy\/\" rel=\"tag\">privacy<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/security\/\" rel=\"tag\">security<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/smart-speakers\/\" rel=\"tag\">smart speakers<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/smart-speakers-christmas\/' title='Smart speakers: Christmas treat or lump of coal?'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/cybercrime\/2018\/12\/smart-speakers-christmas\/\">Smart speakers: Christmas treat or lump of coal?<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[397,4503,11317,5897,714,16596],"class_list":["post-14156","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-christmas","tag-cybercrime","tag-eula","tag-privacy","tag-security","tag-smart-speakers"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14156","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=14156"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/14156\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=14156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=14156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=14156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}