Amazon and Google: Trust us, our smart-speaker apps are carefully policed. Boffins: Yes, well, about that...
- Reference: 1596004452
- News link: https://www.theregister.co.uk/2020/07/29/amazon_google_voice_apps/
- Source link:
Computer scientists from America's Clemson University – Song Liao, Christin Wilson, Long Cheng, Hongxin Hu, and Huixing Deng – provided The Register with a pre-publication copy of research they conducted into voice assistant apps and their privacy rules.
In a paper titled, "Measuring the Effectiveness of Privacy Policies for Voice Assistant Applications," the boffins analyzed 64,720 Amazon Alexa skills and 2,201 Google Assistant actions – apps that interact with the voice-controlled mic-speaker hardware people use to bug their own homes – and found them largely lacking.
Of these 46,768 Alexa skills (72 per cent) and 234 Assistant actions (11 per cent) had no privacy policy.
The academics attributed the Google-favoring gap to Amazon's lax skill certification process, the focus of [1]previous research .
"After conducting further experiments on the skill certification, we have understood that even if a skill collects personal information, the developer can choose to not declare it during the certification stage and bypass the privacy policy requirement," the paper states.
"This is achieved by collecting personal information through the conversational interface (e.g., asking users’ names). Even though this data collection is prohibited, the certification system of Amazon Alexa doesn’t reject such skills."
The boffins also observed that of the 243 Assistant actions recorded without a privacy policy, 101 had been developed by Google.
What's more, they found 1,755 Alexa skills and 80 Google actions with broken privacy policy systems, along with various other problems like duplicate privacy policies URLs shared across different apps and privacy policies that offer descriptions inconsistent with the app's actual function.
Amazon's auditing of Alexa Skills is so good, these boffins got all 200+ rule-breaking apps past the reviewers [2]READ MORE
Worse still, Amazon and Google both offer voice assistant apps that violate their own rules. Amazon's [3]Weather skill , for example, collects location data but doesn't provide a privacy policy link in its store description.
The Clemson scientists have published [4]a summary of their findings to GitHub.
Asked why Amazon and Google haven't addressed these issues when the Clemson computer scientists can flag them with a bit of Python code, Long Cheng, assistant professor in the school of computing at Clemson University and a co-author of the research paper, speculated that it may have something to do with how new these platforms are.
"They probably focus more on implementing new features/functionalities at the current stage," he said in an email, noting that Google [5][PDF] took the issue seriously and removed the Assistant actions with missing privacy policies. The ad biz also paid a $5,000 reward for reporting the problems.
Amazon makes privacy policies mandatory only for skills that collect personal information, Long said, adding "But we found so many Alexa skills providing meaningless privacy policies."
"The presence of so many problematic privacy policies indicates that Amazon's post-certification audits still need to be improved," he said.
Those developing voice assistant apps are often not professional developers, he said, suggesting that both Amazon and Google have optimized for quantity over quality.
The research paper also describes [6]a survey of 66 Alexa and 25 Google Assistant US-based users, conducted through Amazon Mechanical Turk. The findings found that 52 per cent of respondents were unaware of the privacy policies of their voice assistant apps; 73 per cent rarely read those privacy policies; and 47 per cent don't know what kind of information their skills/actions are capable of collecting.
Also, 75 per cent of respondents said they would enable a skill intended for kids without reading its privacy policy.
The paper's authors say they've reported their findings to Amazon, Google, and the US Federal Trade Commission.
The Register asked Amazon and Google to comment on the research.
"We've been in touch with a researcher from Clemson University and appreciate their commitment to protecting consumers," a Google spokesperson said in an emailed statement. "All Actions on Google are required to follow our developer policies, and we enforce against any Action that violates these policies."
"We require developers of skills that collect personal information to provide a privacy policy, which we display on the skill’s detail page, and to collect and use that information in compliance with their privacy policy and applicable law," an Amazon spokesperson said in an emailed statement.
"We have not yet been given the opportunity to review this research paper. We will closely review it when available, and engage with the authors to understand more about their work. We appreciate the work of independent researchers who help bring potential issues to our attention."
The paper concludes with the recommendation that platform owners implement a function to briefly summarize voice app privacy policies aloud, since many people only interact with voice assistant software via voice. ®
Get our [7]Tech Resources
[1] https://www.theregister.com/2020/07/23/amazon_alexa_skills/
[2] https://www.theregister.com/2020/07/23/amazon_alexa_skills/
[3] https://www.amazon.com/Amazon-Weather/dp/B01JHLFTJO/
[4] https://github.com/voice-assistant-research/voice-assistant
[5] https://github.com/voice-assistant-research/voice-assistant/blob/master/GoogleResponse.pdf
[6] https://github.com/voice-assistant-research/voice-assistant#user-study
[7] https://whitepapers.theregister.com/
Shut Up And Take My Privacy!
Guaranteed, if someone tried to shut the door on them, at least the half the stuff would flat stop working and there'd be a backlash, privacy be damned.
Excellent article and research.
So, essentially, the privacy policies that did exist were often cut and pasted from other, unrelated, products.
I doubt there is any protection, even with a legit privacy policy, that protects us from bad actors.
If I can use an analogy, it's like there's no barn door to shut because there's no barn, just an empty plot of land in the Wild West.
The only good thing is that the Google and Amazon's focus on numbers means many users will not bother installing anything because the useful/entertaining stuff has been drowned out by all the crap.
Indeed. A colleague recently plumbed in an Alexa at the office. After regaling me with fart noises, he was very fast indeed to cancel after I asked it to order fifty sex toys...
Top tip:
If your device has a microphone, it's entirely a trust issue about what's happening to that data from that microphone.
If it does not have a microphone, then it can't record sound.
If you don't put this stuff in your living room, then it can't do things.
My phone has microphones and I carry that around everywhere.
Can you recommend a good tin foil hat?
Naah - just wrap the phone in a few layers of foil. Works just as well, and also reduces the number of idiot callers.
My phone has microphones and I carry that around everywhere.
Yes. And it is an important issue. But, as with all security, a risk assessment (even informal) is probably more useful than a tin foil hat.
It is well understood that phone microphones are always compromised at a low level (often in hardware/ROM firmware) and are accessible over the air to network operators and law enforcement. That is why in very high security environments phones are banned and are even stored in Faraday cage bags at site reception.
However, if your threat concerns do not include nation states or law enforcement, phone microphones by themselves are not much of a problem: any phone company or operator routinely tapping all its customers mics would be noticed quite quickly.
However, it is clear that all "voice assistants" (whether from device manufacturers, operators, or 3rd party apps) are always listening and retaining data. Many people have noticed that adverts reflect recent conversations held near the phone, even when the assistant has not been asked a question. The only way to avoid that is to uninstall them. In the case of built-in assistants it should be enough to use their setting to disable them -- if they claim to be disabled but in fact are still recording then they are clearly committing an offence.
But if you leave it enabled (listening for its trigger word), it will be recording and sending information back to its masters.
What's the situation these days with Smart TVs?
My TV is not specified in the user manual with a microphone, nor does it appear to have any obvious microphone mechanical structures.
That said, there is a button on the remote control that I allegedly need to push for it to interact with it using my voice.
I'm using a Samsung 4K TV, so I am basically starting from the default position, that it will be hackable by anyone who wants it. C**** thing even serves me adverts on the UI menu.
The microphone is probably in the remote.
My LG is the same
I am pleased at Google's response, actually paying attention and providing a bug bounty.
"We require developers of skills that collect personal information to provide a privacy policy, which we display on the skill’s detail page, and to collect and use that information in compliance with their privacy policy and applicable law," an Amazon spokesperson said in an emailed statement.
Nowhere do I see in that statement regarding provacy policies adjective on those policies like:
relevant
accurate
reasonable
enforceable
understandable
binding or their synonyms.
"optimized for quantity over quality"
That seems to be what the epitaph of our civilization should be.
" We require developers of skills that collect personal information to provide a privacy policy "
No you don't, you just say you do. There are 47K+ "skills" that prove that a privacy policy is not a requirement.
Very tempting to stop speaking English. That must be one of the biggest security issues.
Thinking about Welsh. Should help for a while, until I develop a completely private language. And Welsh can actually be useful in other contexts.
No surprise there
I remember a public presentation by a well known data protection consultant, who said "your privacy policy is PR". And so it seems for almost every Europe relevant privacy policy we've examined in the course of a couple of years of research. Less than 0.5% have been even broadly compliant with the GDPR and literally only a couple have essentially been fully compliant.
Home “speakers” and privacy
People gave that up when they turned their DIY wall-screens on.