Is it true that the Amazon Echo records everything I’m saying to it and that someone has figured out how to hack it?
This question was answered on August 3, 2017. Much of the information contained herein may have changed since posting.
The popularity of ‘smart speakers’ that are voice controlled has grown to over 35 million users and Amazon’s Echo is far and away the most popular.
The small cylinder with a seven-microphone array is powered by the Alexa intelligent personal assistant so users can interact with it via voice commands to control a wide variety of services ranging from music to smart home devices.
Is My Echo Storing My Voice Commands?
Just about any device that you use via voice commands (Echo, Siri, Google Asisstant, etc.) may retain your interactions as a way of identifying you and improving its comprehension of your commands.
Both the device and a remote web server will likely have your recorded commands as a means of personalizing your interactions.
Humans communicate in all types of accents, clarity and tone, so the audio data that is collected is useful in improving the accuracy of the ongoing interactions.
What is Actually Being Stored?
Most voice-controlled systems are pretty much always listening to you waiting for you to say the ‘magic word’ but not recording anything.
Once you use the wake word such as ‘Alexa’ (which can be changed to Amazon, Echo or Computer in the Alexa app) the Echo knows that you’re giving it a command and it stores every command that you’ve ever given it by default.
The stored recordings actually include a brief moment just before the wake word, so this means that it’s possible that your recorded command includes small bits of a conversation preceding your use of the wake word.
How Can I Hear What’s Been Recorded?
Amazon makes it pretty easy to hear and manage what the Echo has recorded through their Alexa app (https://goo.gl/7jASW9).
Just tap into the ‘Settings’ menu and scroll down to the ‘History’ option to see everything in reverse chronological order – the most recent commands will be at the top.
When you tap on any entry in the History, you will be able to see the date and time of the command along with a play button if you want to hear it. If you want to delete the recording, simply tap the ‘Delete Voice Recordings’ bar and it’s gone.
Every command also has the question: ‘Did Alexa do what you wanted?’ which when you respond, will help the system get better at recognizing your way of speaking.
Hacking the Echo
A recent report by a British security researcher detailed a method of modifying older versions of the Echo by physically interacting with it.
This ‘proof of concept’ hack required that they be in physical possession of the device so they could disassemble it, solder in a connector and insert code via an SD card and this only worked on pre-2017 models.
These requirements eliminate the possibility of a random remote Internet hacker turning your Echo into a snooping device, but it does underscore that buying a used pre-2017 Echo from a stranger isn’t such a good idea.
About the author
Posted by Ken Colburn of Data Doctors on August 3, 2017