The Sunday Telegraph

Is your phone listening in on you?

At first, thought he was imagining it. But it turned out his smartphone really was monitoring his conversati­ons...

- Terms of Service: Social Media and the Price of Constant Connection. The Daily Telegraph

It started as a rumour two years ago on a Reddit chat room when one user, who worked in a store that had Mumford and Sons on loop, flipped open his smartphone on the way home and found Google Play had recommende­d he buy a Mumford and Sons song. “I’ve never mentioned this song on social media or Google,” he said. “Is Google listening to my phone 24/7?”

Over the next few months, more and more people noticed similar things – leaving your smartphone on the sofa while a foreign film played meant you started receiving ads in Spanish, chatting about books meant they popped up in a ‘recommende­d for you’. One woman was doing some ironing when her mum told her a family friend had been killed in a road accident in Thailand. Her phone was on the worktop behind her – and the next time she used the search engine, up came the name of her friend and the words, “Motorbike accident, Thailand” in the suggested text below the search box.

It’s something that I’ve wondered about frequently over the past six months – and when I posted my worries on Facebook there were many comments from friends saying they thought the same thing happened to them. People had been discussing holidays or even headaches and found ads waiting when they fired up their phone.

And it isn’t just our phones either. Last week, WikiLeaks revealed that the CIA’s Weeping Angel programme provided agency hackers with access to Samsung Smart TVs, allowing a television’s built-in voice control microphone to be remotely enabled while the TV was switched off.

“The problem with this method is that it required implanting a TV with malware – and it has to be done in person, meaning the CIA are in your house if they want to do that,” explains Dr Gus Hosein, executive director at rights watchdog Privacy Internatio­nal. “Spooks have been breaking into people’s houses to film and record them for ages. It’s not right but it’s nothing new. What is new is that Samsung itself can – and has been caught – listening to everything you say if you’re in the room with one of its smart TVs.”

Personal assistants like Apple’s Siri and Amazon’s Alexa are designed to listen out for keywords to switch on. Although both companies insist your voice is not recorded, in March 2017 police in Arkansas collected a murder victim’s Echo speaker (which works with Alexa) as they believed it captured fragments of audio from the murder scene while listening for commands.

“Are companies recording what we say? The simple answer is yes,” says Jacob Silverman, author of

“Always-on, internet-connected devices could be recording us at almost any time. We simply don’t know what data is collected, where it goes, how it’s passed on, or to whom it’s sold.” Mike Gilkes, senior electronic­s editor at US consumer organizati­on Consumer Reports, points out: “The sticking point – what makes smartphone­s smart is because they do know a lot about you. It knows where’s the local eatery, where’s the traffic jam, it knows you’re late and it knows who you call frequently. But the apps that bring this to you ask for privileges that some people don’t deem necessary.”

The range of apps that ask access to our microphone and camera, for instance, is surprising. Twitter and Instagram request access to your wifi informatio­n, your camera and mic, your photos, your SMS, your location, your contacts and your calendar – meaning the apps can take photos, videos and use your mic, access everyone you know, read your messages, remove accounts and track your every movement. Facebook requests all of the above plus device ID and call info, your identity and device and app history.

Facebook has issued a firm online rebuttal to accusation­s that it listens to its users’ conversati­ons – and referred

to that statement. “Facebook does not use your phone’s microphone to inform ads or to change what you see in News Feed,” it states. “We only access your microphone if you have given our app permission and if you are actively using a specific feature that requires audio.”

Which may well be true, says Renate Samson, CEO at Big Brother Watch, but “we know companies sell your data to data brokers in a fraction of a second. These faceless data brokers sit in the background – we think when we engage online only Amazon and our credit card company know what we’re doing. But data brokers know everything you’ve bought and, with identity data, what sort of person you are. They can figure out who we are and what we’re doing, which is profoundly disturbing.”

This is even more alarming when it comes to smart home devices and wearable accessorie­s connected online. This year, Samsung debuted its Family Hub fridge that can play music from Spotify and become a TV screen, all operated by voice control, while Ford announced it would equip cars with Amazon’s Alexa. There’s voice controlled smart functional­ity in everything from baby monitors to door locks and heating controls.

In May 2016, however, researcher­s at the University of Michigan discovered they could pull off disturbing tricks with these devices – from triggering a smoke detector to planting a backdoor PIN code in a digital lock that offers silent access to your home.

“If these apps are controllin­g non-essential things like window shades, I’d be fine with that. But users need to consider whether they’re giving up control of safety-critical devices,” says Earlence Fernandes, one of the University of Michigan researcher­s. “The worst case scenario is that an attacker can enter your home at any time he wants, completely nullifying the idea of a lock.”

And intimate informatio­n is also at stake. Health wearables are a booming market – and with these devices recording sleeping patterns, heartbeat, body temperatur­e and health informatio­n you’d want to hope the data was being kept safe.

In September 2015, however, researcher­s at Imperial College London and Ecole Polytechni­que CNRS, France, subjected 79 health apps to security checks and found that around a third were sending personal details about health and lifestyle – such as body-weight – over the internet with no encryption.

In February 2016, Canadian-based Citizen Lab and the Munk School of Global Affairs examined eight popular fitness wearables and found seven leaked personal data while giving themselves broad rights to use – and in some cases, sell – consumer’s health data. One in six also sent informatio­n to third parties such as advertiser­s, despite privacy policies not mentioning this could happen.

“I worry about what happens when these devices “understand” almost everything we’re saying,” Silverman adds.

“When automated systems can understand what you’re saying at all times, and potentiall­y nudge you with all sorts of offers and suggestion­s, how can we feel in control?”

 ??  ??
 ??  ?? Amazon’s Echo speaker: did it collect audio from a crime scene?
Amazon’s Echo speaker: did it collect audio from a crime scene?
 ??  ??

Newspapers in English

Newspapers from United Kingdom