My girlfriend gave me an Alexa assistant as a gift with all good will, since she knows I like technology. I know in terms of privacy it is garbage, however I wonder if there is a safe way to use some functions of this device, perhaps without internet. Some way to hack it or something, do you guys know something about this?
Fast search gave me this ,replacing with open source firmware Mycroft https://hackaday.com/2021/03/22/amazon-echo-gets-open-source-brain-transplant/
Mycroft the company went bust. Not sure if you’d still want to do this with unmaintained software.
You don’t. I did a project involving Mycroft and, while functional, it was awful. Not worth any of the hassle.
Sad. I did not know that.
Although, to be honest, I was sort of expecting it would happen sooner or later. It did not look like the product was ready for mainstream users yet, and the devices at that price must have been tough to sell.
For anyone curious, this message from the CEO has more details: https://web.archive.org/web/20230822232437/https://mycroft.ai/blog/update-from-the-ceo-part-1/
Yeah, the yrice was a lot higher than anyone was expecting, and they changed the design to make them a lot uglier.
Plus they wasted their cash with legal costs fighting patent trolls.
I had a google thing which I used as a speaker for a bit. If it has Bluetooth, you could just not let it connect to the internet? As an assistant I found it useless, even without privacy concerns, but as a speaker it was alright.
It’s nice that you are trying to find a use for it though! Hopefully it works out long term and you could talk about it the privacy stuff before you get a Facebook Portal next
usually the alexa things do not have Bluetooth and can’t play audio from another device
What are you talking about? All Alexa Speakers I own or have encountered support bluetooth playback from other devices just fine, and at least the older ones also have a 3.5mm jack.
sorry maybe i confused echo dot devices with alexa speakers?
i only ever encountered echo dots and they can’t play over Bluetooth
Echo dots can also play over Bluetooth.
EDIT: I misread. I don’t know what an Amazon assistant is. I’m talking about an Amazon echo below
I have one at a cabin in the mountains that has no internet or cell service. It required internet access to sync/auth with my phone so I did it at home then moved it to the cabin. I think it needed to be auth’d to an Amazon account, despite never planning or wanting to use it with an account. It was a “prize” from work.
It is literally impossible for it to connect to the internet at its location but it is a pretty good speaker. Perhaps the loneliest IoT device ever, but I’d never use it in a connected state.
If you only want it for a speaker, you could wall it off to prevent Internet access even at home
Alexa devices aren’t great for privacy, but they’re not nearly as bad as people like to think. They’re surely not as bad as your phone, especially if you’re not installing a bunch of skills.
They don’t send any data out unless they’re activated with the wake word. Alternatively, that means everything you say after that wake word is being recorded and sent to Amazon and who knows who else after that. By far the biggest privacy concern with them is when they mistakenly hear the wake word, and start sending data out without you realizing it. If this is a concern to you, I’d suggest leaving it unplugged when you don’t plan on using it, or plugging it into a “smart outlet”. Get a reputable one because that brings its own set of security and privacy concerns, or get one of the RF ones that turn on/off with a remote.
@Morse depends on your threat model. nation states surely have alexa zero days to easily hot mic a house.
@Morse (and under FISA a 702 they don’t even need a zero day, the NSA can just compel Amazon’s covert facilitation).
Neither of those concerns are exclusive to an Alexa device though. They’d apply to any communication device (phone, tablet, computer, laptop, or any other smart/connected device).
And how can we be sure that it isnt sending data when it isn’t called by the wake word?
You can use Wireshark to sniff the packets leaving your network. I use a PiHole to see all of my network traffic.
I would configure it as privacy friendly as you can, and do some research on your own and maybe talk to ur gf