TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google listening in to your room shows importance of privacy defense in depth

178 点作者 arto将近 10 年前

21 条评论

metric10将近 10 年前
Has anyone actually confirmed that Chrome is continuously sending audio back to Google? I <i>highly</i> doubt that this is the case. Instead, the plug in knows how to recognize &quot;OK Google&quot; all by itself. Once activated, then it starts sending audio data.<p><i>IF</i> it where really listening even when inactive, then people would be complaining about it sucking up bandwidth and data allotments.
评论 #9739042 未加载
评论 #9738998 未加载
评论 #9738929 未加载
评论 #9738870 未加载
评论 #9739379 未加载
评论 #9740030 未加载
评论 #9739382 未加载
评论 #9742647 未加载
评论 #9738932 未加载
评论 #9740219 未加载
Mithaldu将近 10 年前
This is pretty funny. He complains that Chromium managed to &quot;bypass this audit-then-build process&quot;, by downloading stuff afterwards, while ignoring that this happening already shows that the audit process is completely useless since it failed to recognize and reject the code that would do this.<p>There&#x27;s a TSA joke somewhere in this.
评论 #9738768 未加载
jmnicolas将近 10 年前
I think this is the last straw for me : enough is enough.<p>I need to sit and reflect a bit on this, but I&#x27;m contemplating abandoning every bit of non free software I currently use (and there&#x27;s a lot of it since I&#x27;m using Windows and Android).
评论 #9739979 未加载
评论 #9738913 未加载
bhauer将近 10 年前
I want my desktop operating system to offer fairly fine-grained control of permissions I selectively grant to processes&#x2F;applications. I would like the ability to easily revoke Chrome&#x27;s ability to use my audio inputs, and then—if the use case comes up, such as a WebRTC conference—I can grant permission either on a one-time basis or until I revoke. This would be the operating system controlling the application&#x27;s capability.<p>I&#x27;m guessing a rough approximation is possible on some operating systems. Given the sprawling management infrastructure in Windows, I wouldn&#x27;t be surprised if it has some &quot;policy&quot; framework in place that allows devices to be declared off-limits at a process granularity. The missing piece, then, is a viable user interface on top of that.<p>I&#x27;m not asking for something akin to the simplified permissions model of mainstream sandboxed mobile operating systems. Not set-and-forget; and certainly not all-or-nothing (&quot;accept these required permissions or don&#x27;t install the app.&quot;) Rather, something quite a bit finer grained and with the necessary infrastructure to have the OS prompt for privileged access if the application wants something I&#x27;ve disallowed, in a manner akin to Windows UAC prompts for admin credentials.<p>Imagine starting Chrome one day to have your operating system prompt you, &quot;Chrome would like access to audio input 1 (microphone). Allow for now, permanently, or deny?&quot;
评论 #9739583 未加载
turk-将近 10 年前
How does he know Chrome is transmitting ALL conversations that it hears? His arguments aren&#x27;t valid:<p>&quot;(Ok, so how does it know to start listening just before I’m about to say ‘Ok, Google?’)&quot;<p>This could easily be achieved offline.<p>The same argument could be made for Siri, a wiretapping device which you carry with you all the time. In fact wiretapping your phone would be much more effective then wiretapping a computer browser application.<p>Before making such accusations he should present some solid data, like network traffic from an idle chrome application during conversations (with and without saying &quot;Okay Google&quot;). If an idle chrome application was always transmitting data to google, he would have a solid argument.
评论 #9739597 未加载
评论 #9739129 未加载
neumino将近 10 年前
&gt; When you’re installing a version of GNU&#x2F;Linux like Debian or Ubuntu onto a fresh computer, thousands of really smart people have analyzed every line of human-readable source code<p>If this was true, Debian would have not build&#x2F;release this version of Chromium. The author is living in the past or in another dimension. Some projects are complex, and it&#x27;s hard&#x2F;impossible to read&#x2F;understand everything for a single human being.
uptown将近 10 年前
Type this into your Chrome address bar to see the extension status: chrome:&#x2F;&#x2F;voicesearch&#x2F;
评论 #9738400 未加载
评论 #9738980 未加载
jimhefferon将近 10 年前
This is why there needs to be a switch on all computers to <i>physically</i> turn the microphone off.<p>How is that hard?
评论 #9740310 未加载
评论 #9740102 未加载
评论 #9743710 未加载
ape4将近 10 年前
I always assumed the purpose of Chrome was to spy on us. So I don&#x27;t use it.
rasz_pl将近 10 年前
I wonder if European Commission would be interested in adding this to their investigation, couple of hundred million dollars should be enough penalty for violating users privacy.
评论 #9738783 未加载
评论 #9739732 未加载
评论 #9738867 未加载
jonstokes将近 10 年前
Not surprised. I was a die-hard android user, but I kept having stuff like this happen to me, over and over again: <a href="http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;technology&#x2F;comments&#x2F;2kwbl2&#x2F;im_convinced_my_android_phone_listens_to_me_and&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;technology&#x2F;comments&#x2F;2kwbl2&#x2F;im_convin...</a><p>It also happens to my android-using friends. I&#x27;ve become convinced that Android phones are listening all the time so that they can figure out what we&#x27;re about to search for and what to advertise to us.<p>Given that this has been my (admittedly anecdotal) experience with Android, I wouldn&#x27;t be surprised at all if Google was trying to take this type of thing to the desktop with Chrome.<p>I love Google and have historically just not cared about my privacy as far as they&#x27;re concerned, but I&#x27;m getting more creeped out as this kind of stuff becomes more pervasive.
评论 #9740062 未加载
评论 #9739205 未加载
评论 #9740410 未加载
Oletros将近 10 年前
has the author really tested if Chromium is listening?<p>Downloading a binary blob is very bad, but the accusations that author makes wihouth a single proof is more FUD than anything
评论 #9739994 未加载
anaptdemise将近 10 年前
There is also a bug report from a year ago. <a href="https:&#x2F;&#x2F;code.google.com&#x2F;p&#x2F;chromium&#x2F;issues&#x2F;detail?id=381747" rel="nofollow">https:&#x2F;&#x2F;code.google.com&#x2F;p&#x2F;chromium&#x2F;issues&#x2F;detail?id=381747</a>
feld将近 10 年前
Is there a GPO to control this setting in Windows?<p>edit:<p>This might work<p><a href="http:&#x2F;&#x2F;www.chromium.org&#x2F;administrators&#x2F;policy-list-3#AudioCaptureAllowed" rel="nofollow">http:&#x2F;&#x2F;www.chromium.org&#x2F;administrators&#x2F;policy-list-3#AudioCa...</a>
izzydata将近 10 年前
My only audio recording device is my webcam and it is incapable of being in use without the light being on as far as I am aware. So how would it send them audio data without the audio device realize it is being used?
评论 #9740286 未加载
w8rbt将近 10 年前
One thing to keep in mind. If your friend has a Google device using Chrome, and you are close to them (in the same room) it hears your voice as well.
评论 #9740441 未加载
zobzu将近 10 年前
Note that all android phones have that issue. Also all windows phones and soon windows 10.<p>Oh and smart tvs. it is a real problem though
评论 #9740210 未加载
lfender6445将近 10 年前
if you goto chrome:&#x2F;&#x2F;settings&#x2F;content it appears you can disable mic + camera access for all pages
评论 #9738546 未加载
评论 #9738735 未加载
spdustin将近 10 年前
Okay, I&#x27;m going to put on my tin foil hat for a bit here.<p>Think of the corporate boardrooms with Chromebox for meetings, listening in even when not actively used for meetings. An exec at the Better Business Bureau [0] who chose Chromebox because they were excited to, &quot;[reduce] the time [they spend] ... worrying about security concerns,&quot; is discussing the growing complaints the BBB has received about a competitor to a company owned by Google. He says, &quot;Ok, Google owns their primary competitor, and they may have insight to offer us.&quot;<p>Wait, that&#x27;s just my tin foil beanie. Let me put on the tin foil balaclava.<p>The U.S. Department of State [1] is in an all-hands-on-deck crisis meeting over a deeply divisive political situation involving a first-world ally. Chrome is updated with the eavesdropping feature (remember, it&#x27;s just my tin foil that&#x27;s making me choose that word, I know it&#x27;s hyperbole), and it&#x27;s already been &quot;deployed to production immediately, bypassing cumbersome testing.&quot; Someone in the meeting says, &quot;OK, Google News has been trending a lot of stories about this issue.&quot; Sensitive things are then said about this ally, things that are now being heard by an enemy of the state, because they were able to use their previously embedded network sniffers to capture and forward interesting network traffic.<p>It&#x27;s frightening that a feature is enabled by default, and difficult to disable, that could capture sensitive conversations without the knowledge of the parties speaking because they innocently started a sentence with, &quot;OK, Google.&quot; Certainly this violates wiretapping laws?<p>Let&#x27;s pile on. Hospitals and medical centers are using this too, according to the Chrome for Work pages. A doctor says, &quot;Ok, Google had a lot of results about new HLA-B27 research,&quot; when discussing a patient&#x27;s arthritic concerns, while proceeding to outline the patient&#x27;s symptoms and how treatment should proceed and now we&#x27;re looking at a potential HIPAA Privacy Rule violation.<p>As I type this, I look over at my Amazon Echo, and I&#x27;m reminded of something I heard once. If you&#x27;re not paying, you&#x27;re not the customer, you&#x27;re the product. Is that hypocritical of me to accept my Amazon Echo but not the behavior of Google Chrome?<p>[0]: <a href="https:&#x2F;&#x2F;www.google.com&#x2F;work&#x2F;chrome&#x2F;resources&#x2F;customer-stories&#x2F;better-business-bureau&#x2F;index.html" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;work&#x2F;chrome&#x2F;resources&#x2F;customer-storie...</a><p>[1]: <a href="https:&#x2F;&#x2F;www.google.com&#x2F;work&#x2F;chrome&#x2F;resources&#x2F;customer-stories&#x2F;us-state-department&#x2F;index.html" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;work&#x2F;chrome&#x2F;resources&#x2F;customer-storie...</a>
评论 #9740005 未加载
wslh将近 10 年前
What happen if you play an audio file saying &quot;Ok Google&quot; ?
derptron将近 10 年前
Wow, is there really no way to disable this? I guess I&#x27;m going back to Firefox.
评论 #9739102 未加载