back

by toddmorey·9y ago·view on hn ↗
The HN reaction to this device is what I expected: we're somewhere between suspicious and terrified.

I'll be really fascinated to know how the wider market reacts. I was one of those who believed consumers would look at the always-on living room microphone with suspicion. But I think the lesson was pretty clear that people will trade privacy for convenience. (Likely an overabundance of trust or a lack of understanding of all the real implications and potential for exploit.)

One bit of perspective: When I was a kid, a photo was kind of big deal. My kids take and share photos of themselves every single day. I'm not sure they consider this to be the same privacy invasion that we do.

12 comments
"(Likely an overabundance of trust or a lack of understanding of all the real implications and potential for exploit.)"

I think that's a lot of it. People aren't trading privacy for convenience... people are taking convenience. It makes a lot more sense when you think of it that way.

You can do an experiment yourself to show this; take 5 non-techie/non-HN people and explain to them exactly what this thing does and how it works. You'll find people's attitudes change, rationally or otherwise, which I present only as evidence that they haven't thought about this and incorporated it into their worldview, not that they are right or wrong. Or watch this: https://youtu.be/XEVlyP4_11M?t=24m54s John Oliver on Government Surveillance.

Perhaps ironically, mere nude photos of myself aren't really what I'm worried about. I mean, I wouldn't be happy if they got out, and since I'm not in the habit of texting them about I have questions about where they came from, but by and large, nobody would care and it would affect my life only briefly. I'm far more worried about the government scraping everybody's postings on Facebook and building up a GoodThink/BadThink database, which I know basically already exists, because our political parties (let alone our intelligence community) build voter databases that are probably at least 90% accurate on that front. A concrete list of Everyone Who Disagrees With Me, one accurate enough for someone powerful to decide the rest of the inaccuracy is acceptable collateral damage, is scary.

> building up a GoodThink/BadThink database

Yep. I'm going to London on Friday. The Mayor of London just decided that anybody who posts stuff against muslims on social networks is guilty of a hate crime. I am thinking I won't get arrested when I arrive... but it's a possibility, and I definitely won't access twitter while I'm there.

1. No he didn't.

2. Just stay home.

No he didn't.

How did you come to such a ridiculous conclusion?

GP likes posting anti-Muslim sentiment on social media. The overreaction follows logically from being that type of person.
Or you could, you know...not be an asshole...
The leaks coming out from Wikileaks over the last couple of months has been amazing. All this stuff that security people have theorized about is not only real, but in wide application, often with vendor complacence if not out and out cooperation.

Do you have a Samsung TV built in the last 5 years or so? The USG has turned _that_ into a permanent listening device, even in "off" mode.

Much better target than the Echo, which people already know is a microphone that streams out a live feed of audio from their room, and may unplug if they're feeling paranoid.

I wonder if something like Sense [0] could help ensure that an "off" device is really off.

[0] https://sense.com/

Totally off topic: Yeah so, about that 90% number... You you really think that is the best they can do?

I mean, 90% is pretty good for, like, dog food ads and car commercials, but with lives, a 90% true-positive rate is just garbage. Like, with all that terrific amount of data, are they still just doing T-tests, ANOVA, MW-U-tests? Like, what is their p-value, still 0.05? I know this is super stats-wonky for this thread, but I mean, come on, they have to have some super secret stats and mathy stuff that they are doing, right? Like, formulas and theories that are just really good. It's been, like, 15 years they have had this scale of data, and it's only growing, right? If so, nothing at all has been sent out to the academic community, which, for math theorems, is kinda hard to believe. I now signal-to-noise is super important for NatSec, but it's also super important for DrugDev.

But yeah, a camera that is meant to watch me dress and then order shit for me, that is a super no-no. It, like, actually gives me goosebumps.

"Totally off topic: Yeah so, about that 90% number... You you really think that is the best they can do?"

For the political parties specifically, yes, by the standard they care about. Remember how we're always talking about how the centrists generally end up with the deciding vote, and how the polls are oscillating around by ~10% in the several weeks leading up to the Presidential election? Those people themselves don't really know who they're voting for or whether they support the "correct" person, for any given definition of support, so it's a bit much to expect anyone else to accurately guess.

In the event of a true police state which gives you the choice of vigorous fealty or the Gulag I would expect they can go much higher and that the initial competent execution would be almost inescapable. (Over time it would decay due to various forces, but I can't put a very solid time frame on it... between 10 to 50 years to develop very serious holes in it, probably, but even 10 years is an awful long time.)

I suspect there are large numbers of fashion bloggers/instagrammers that have already ordered one.

In contrast with the HN reaction, ]the younger target audience will have no issue with sending their photos and videos into the cloud.

I've read that they won't be using them, because they generally have professional setups with proper lighting and DSLRs. They also then edit photos before posting them.
I'd put it more simply:

"Users don't care about privacy or security."

I put it in quotes because it's become a kind of catch phrase, and in practice I have found this to be largely correct. We've tried very hard to make our product secure, but users almost never ask about that. We have never been asked about the quality of our crypto by a regular user, and only once by an enterprise user. Users care about UX and cost, in roughly that order, and little else. This is even true of most enterprise users.

This is why security sucks. This is why everything spies on you. It's not a priority for anyone because it doesn't affect user buying behavior. The tiny minority who do care are not only too small to matter but also tend to be the kinds of "hackers" who like to DIY (and pirate) rather than buy things... making them doubly economically insignificant.

In the end the privacy issues around things like this will have to be fixed with legislation. We will need to effectively extend HIPAA regulations to cover all kinds of other personal data: passively recorded audio and video, location tracking data, anything more than the most superficial user logging, etc. Vendors will face a fine of $$$ per incident if this information is leaked, and sale and use of information will be strictly regulated.

As far as government surveillance goes: that horse left the barn over a decade ago, and that also can only be fixed in the legislature. The legislature must regulate intelligence agencies and police. If they don't, no amount of techno-fixing will limit the power of these agencies. They have larger budgets than you.

> I was one of those who believed consumers would look at the always-on living room microphone with suspicion. But I think the lesson was pretty clear that people will trade privacy for convenience.

I don't think it's a matter of trading privacy for convenience, as long as you believe Amazon when they say they're not sending anything when you're not using the wake word.

All evidence points towards this being the case, both my own anecdotal evidence, and the investigations people have done.

Can it be exploited? I don't know. I'm not going to speculate.

I don't see any additional trade off vs. having my cell phone on me at basically all times.

Yes. People don't see this as a device that's "always listening". They see it as a device that has a voice-activated "On" switch. Instead of pressing a button, you say a word.

Of course, with a little bit of thought, you can connect the dots and figure out that it has to be listening all the time to know if the wake word is said, but most people aren't thinking that deeply about it. When they do realize this, Amazon has assured them that the "voice switch" actually does function as advertised and that audio is not streamed until the device is "on".

Not an EE, but I wonder if it is possible to bake into the hardware an LED that activates when the camera is active.

That would at least protect users from unintentional recording

This is quite straight forward, and I'm surprised no one has done it (to my knowledge). You simply wire the camera in such a way that powering it also powers the LED. If done properly, you couldn't hack this with software.
It's the kind of feature that should honestly be required for most applications.
> But I think the lesson was pretty clear that people will trade privacy for convenience.

Not everywhere. In Germany, Amazon Echo isn't nearly as popular.

Germany has an, sometimes irrational, phobia of new technology that doesn't always have something to do with privacy concerns.
In this case, the privacy concerns are obvious.
Amazon says that my echo isn't recording me, and I just have to trust it. People have confirmed this to be true.

Google says that my phone isn't recording me, and I just have to trust it. People have confirmed this to be true.

I don't see a difference.

Google could hide proof of either statement by manipulating its search results.

I'm not suggesting this is actually happening. I'm pointing out that when you have a single distribution channel for information, users have no choice but to assume the channel hasn't been tampered with.

Of course you could have papers, conferences, and so on proving otherwise. But if they existed, you would only hear of them by word of mouth - which would rely on being in or around a professional network which took an interest in such things.

If Google decided to censor or manipulate the search results about a topic, it could become extremely hard to access reliable uncensored information.

Hypothetically, if a bad guy hacks the echo, it could only blackmail people based on their voice recording.

If he hacks the Echo Look, it could blackmail people based on some naked pictures/videos of the victims.

A camera app, or Google Backup Transport or anything else 'odd' on a phone that wants to talk to Mother can be firewalled at the kernel level.

An Echo is an opaque, indivisible blob.

> People have confirmed this to be true.

that's not something that can be proven true though.

This is a brilliant product, and right in the corner of a "brilliant product/things hackernews hates" graph.

Most people aren't that concerned by privacy and will love features like the ability to see different views and short videos. Everyone knows that feeling of catching a glance of themselves in a passing mirror and how it's a different feeling to deliberately evaluating your look in a mirror. If they can recreate that feeling, and combine it with product recommendations it will be a massive success if they market it right.

> When I was a kid, a photo was kind of big deal. My kids take and share photos of themselves every single day.

It makes me wonder - is it no longer narcissistic for people born in an age where camera sensors are ubiquitous to take selfies constantly? Can a behaviour be normalised as a result of cost, the same way listening to music in public would have been considered indulgent and neglectful of the world around you before everyone could afford a personal/portable music player?

Personally I lean towards it still being a narcissistic trait. That's not to say the behaviour isn't natural - it's no more artificial than our tendency to gorge ourselves on junk-food because of its cost and availability. But it's something that needs to be controlled.

> It makes me wonder - is it no longer narcissistic for people born in an age where camera sensors are ubiquitous to take selfies constantly? [...] Personally I lean towards it still being a narcissistic trait.

Well, people used to get 8 foot tall oil portraits of themselves done; a few extra digital photos still seems a pretty big step in the right direction.

I suspect that if commissioning an artist to make portraits of any size was as cheap and easy as taking a selfie or eating junk food, we'd be balls-deep in portraits right now. Cost & effort vs value.

The implication being that narcissism is nothing new or changing in prevalence, we just need to discourage its more overt forms so that we have a healthy and thoughtful population.

> we just need to discourage its more overt forms

I think we've done a pretty good job about this, what we're left with is people taking pictures of themselves costing $0, and perhaps posting them on free sites for people who want to view & share such things. That's just about as out-of-your-face as you can get.

It's completely not for us ("us" here being people not super into fashion, since this isn't really a fashion website), I wouldn't think, which is why we look at it cockeyed.
Yes, I have a teenager at home that would probably enjoy sending pictures of outfits to friends to check out. There has even been talk of a outfit calendar so that the same one doesn't get worn in the same couple of days|weeks|months.

I would have absolutely zero use for such a thing, but HN is a pretty small community and there are a lot of people in the world.

> But I think the lesson was pretty clear that people will trade privacy for convenience. (Likely an overabundance of trust or a lack of understanding of all the real implications and potential for exploit.)

Or perhaps more accurately, most of the people in question are members of the mainstream dominant culture and don't really have much if anything in their life that they worry about someone else finding out about.

Most people are average, by definition.

They're not, actually. Almost no one is average if you look at multiple features at once. I would guess that most people have something they wouldn't be too happy with everyone knowing about.

"In his research measuring thousands of airmen on a set of ten critical physical dimensions, Daniels realized that none of the pilots he measured was average on all ten dimensions. Not a single one. When he looked at just three dimensions, less than five percent were average. Daniels realized that by designing something for an average pilot, it was literally designed to fit nobody." [0]

[0] http://99percentinvisible.org/episode/on-average/

This is meaningless without considering the granularity of the unit of measure. Most people are of average height when measured to the nearest meter. The motivation behind the measurement determines the granularity -- for a cockpit, the seat and pedals and stick probably have to be within a couple of inches of tolerance. For a society, how racist or treacherous or murderous does a person have to be before we no longer accept them in society?

I think there are simple guidelines: first, make clear the distinction between public and private spaces. No mandatory or secret surveillance in private places. Second, informed consent and transparency: Those willing to give up privacy for convenience within private spaces must have access to (but not be forced to read) clear, understandable, honest descriptions of what their information devices are doing.

But we don't treat people by average very well. We treat them bad if they have any kind of psychological issues. We treat them bad if they have weird sexual fetishes. We treat them bad if they have the wrong kind of friends.

Just because it's "average" doesn't mean it's safe to be public knowledge

I get your point, but has the "general consumer" actually demonstrated that they will trade privacy for convenience with regard to Amazon Echo (and competitors)? This stuff is still very early days. I don't know anyone that has an Echo, even among my tech literate friends. I think it is yet to be seen if this type of technology really gets universal adoption.
I know at least a dozen non-techie types who have an Echo or Echo Dot in their kitchen. Mostly, they use it to listen to music, help with timers/conversions while cooking, and to hear the weather/news in the morning. Not one of them even thought of the privacy concerns until I brought it up.
Taking a photo of yourself is probably not a privacy intrusion like having someone else take a photo of you might be.
It's consensual or whatever, but I think the bigger factor is that people are not really aware of how much information can be gleaned from the photos and don't consider the implications of Amazon storing them forever.
Even trying to see this from an outsider perspective it seems like a stupid product. As someone else pointed out, they've replaced looking in the dang mirror with a multi-step process involving a few hundred dollars of tech at least. They made sure to throw in "cloud" and "machine learning", but the average consumer doesn't care about that.
Amazon has had great success with some of their stupid products in recent years. Maybe for you and I We just want to throw on some clothes and get out the door, but for some getting dressed is a ritual. They don't want less steps, they want more. I've had GFs who'll spend hours trying on different outfits.

And the next logical step would be a virtual dressing room, that uses an augmented reality overlay of the sort we see with Snapchat's funny faces toys for trying on virtual clothes, which would convince people to buy more shit from Amazon.

> And the next logical step would be a virtual dressing room

Hey, that was my old startup idea!

Also, I kind of wonder why this still isn't a thing; the technology for doing that cheaply has been around for at least 7 years[0], and just being able to quickly view many different outfits on yourself would be useful enough that even I (a totally fashion-oblivious guy) would consider using it.

Still, in a perfect world, such a thing would be implemented entirely locally (again, the tech required for doing that is old), with only clothes database being downloaded. This is exactly how this won't be implemented - it will instead send data to cloud for various anti-consumer, business-friendly reasons.

--

[0] - https://en.wikipedia.org/wiki/Kinect

> And the next logical step would be a virtual dressing room

Another logical step might be skin-cancer screening (surprised that, in 300-ish comments, no one seems to have thought of this), assuming the camera's resolution and/or back-end image-processing software could be made good enough to pick out moles, etc. After all, the camera could take full-body pictures of front, back and sides very easily. Then, if anything odd shows up, you could perhaps ask the user to do a close-up shot of the affected area for further examination and/or just be told to go see a dermatologist.

While fully-naked shots would be best for this -- with all the attendant privacy/HIPPA/etc. issues -- I'd expect even doing this while in underwear/bathing suit/etc. would still be a net-win since you'd be able to examine around 90% of the body and you could do it regularly. How often, after all, do people normally get any kind of dermatological exam?

(Mind you, a dedicated device for skin-scanning might be best, but, as they say, the best camera is the one you have with you -- if this sort of device becomes popular, then it might be good to make it work for this vs. letting the perfect be the enemy of the good, as they say.)

I think you may be missing the brilliance of this product from a sales perspective.

Even if this product isn't a massive success, the units they do move will have a huge potential impact to their retail clothing lines.

Now, instead of suggesting clothing items in the store based on other items you've looked at, they can now suggest clothing items in their sales material based on what you already own and look good wearing.

If I had this product and Amazon started sending me curated outfits that they knew would look great on me and matched my style, I'd probably start using Amazon exclusively to fill out my wardrobe.

As it stands now, I buy almost everything EXCEPT clothes through Amazon and prefer to let my wife buy me things she wants me to wear.

This product, on it's own, is a game changer in the fashion industry. Now Amazon has a compelling and unique product that is going to make it increasingly difficult for other retail outlets to compete in the same space.

And once we start seeing "apps" for this camera that auto-instagram/snapchat your pictures, I think we're going to see a huge demand in the teen/millennial female market for what is kind of a geeky niche product.

Put this way, I'm interested. If it could reliably figure out my size and show me clothes that it guarantees will look good on my body type - I'd probably be interested. Although I'd want to just rent it, not own it.
I'm not sure what's creepier - the privacy issues, or the fact that everyone seems to be assuming that machines can make better fashion choices than people.