The Echo That Mailed Itself

The Echo That Mailed Itself

Tech News amazon echo gdpr privacy smart-speakers

So this is the story that's been rattling around in my head all week, and it's not the one everybody else is writing about.

Yes, GDPR went live on Friday. Yes, my inbox looks like a landfill of "we've updated our privacy policy" emails from every mailing list I forgot I was ever on in 2014. I counted 31 of them by Tuesday morning and stopped counting after that because it stopped being funny. Everyone and their dog has a hot take on GDPR this week so I'm not going to add another one. What I actually want to talk about is a story out of Portland that I think says more about where we're headed than any regulation does.

Last weekend a family up there had their Amazon Echo record a private conversation in their house and then, on its own, send the audio to someone in the husband's contact list. Not a hack. Not malware. The device just did what it thought it was supposed to do. KIRO7 in Seattle broke the story and Amazon's explanation, once you read the whole thing, is somehow both completely plausible and completely insane: the Echo apparently heard something in the background conversation that sounded enough like "Alexa," then picked up something else that sounded like "send message," then read out a name from the contacts list as a confirmation, and the family just never heard any of that because who's listening to their own smart speaker mumble to itself in another room. Then it sent the recording. The contact on the other end got a call telling them to unplug their devices because they were being hacked, which, given the context, is an extremely reasonable thing to assume.

I don't think this is a hacking story and I don't think it's really even a security story. It's a design story. We put a microphone in the kitchen that's always listening for a word, and we told ourselves that's fine because it only "wakes up" when it hears that word, and this whole incident is what happens when that promise turns out to be softer than the marketing implied. The wake word isn't a hard boundary, it's a probabilistic guess, and probabilistic guesses are wrong sometimes. Usually the cost of being wrong is Alexa turning on and playing a song nobody asked for. This time the cost was a private conversation getting mailed out of the house.

I own one of these things, for what it's worth. It's a first-gen Echo Dot I got for something like $30 in a Black Friday sale two Novembers ago, and it lives in the kitchen where it mostly gets used for timers and asking what the weather's doing. After reading through the Portland story a few times I unplugged it Tuesday night and I haven't plugged it back in. Maybe I will again, I'm not being dramatic about it, but it felt like a good moment to actually sit with the fact that the box is designed to be listening constantly, by definition, or it couldn't catch the wake word at all. That's not a bug. That's the whole premise of the product. The bug is just that the rest of the pipeline downstream of "did I hear my name" isn't nearly as reliable as the pipeline upstream of it, and normally we never notice because nothing downstream ever fires.

The GDPR timing makes this almost funny in a bleak way. Here's Europe spending years building out a legal framework for consent and data control, rolling it out with a hard deadline and a wave of press, and in the same week the actual lived experience of a "smart" device in an American kitchen is that it can just decide, on its own bad judgment, to record you and mail it to a stranger. No consent form fixes that. No cookie banner fixes that. The problem isn't that nobody asked permission, it's that permission was never really the mechanism doing the work in the first place, a wake word was.

Anyway. My Dot stays unplugged for now. If your smart speaker starts making noises for no reason, maybe don't assume it's nothing.