Cox deletes ‘Active Listening’ ad pitch after boasting that it eavesdrops though our phones::undefined

You are viewing a single thread.
View all comments View context
37 points

Well. Wireshark would confirm that if it were true.

permalink
report
parent
reply
23 points

I’m sure it will show HTTPS traffic outbound from your TV.

permalink
report
parent
reply
25 points

I’m sure it will show no traffic whatsoever if you don’t connect your TV to your network

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
-17 points

There’s a dozen ways they could jump the air gap.

Ultrasonic to a phone or Alexa/Siri/etc, connect to an unsecured network, send data to a neighbor’s smart TV which is connected to Internet, Bluetooth or other to a phone

permalink
report
parent
reply
-4 points

And with DNS requests and timing you should be able to figure whats in those packets.

permalink
report
parent
reply
19 points

Sorry if this is a noob question, but…how?

DNS will tell you the server name and address, which would just be some server owned by the company. Nothing weird there unless they have the chutzpah to name it something telling. They could even bypass DNS entirely with hardcoded IP addresses.

Timing wouldn’t be a great indicator either if they aggregate requests.

They could slide anything nefarious in with daily software update checks or whatever other phone-homing they normally do, and without deep packet inspection or reverse engineering the software, it would be very difficult to tell.

I don’t think Wireshark can do deep packet inspection, can it? Assuming the client is using SSL and verifying certs, maybe even using cert pinning?

Size would be a big indicator if they’re sending full voice recordings, but not if they’re doing voice recognition locally and only sending transcripts, metadata, or keywords.

I’ve never actually done this kind of work in earnest, and my experience with Wireshark is at least a decade out of date. I’m just approaching this from the perspective of “if I were a corporate shitbag, how would I implement my shitbaggery?”

permalink
report
parent
reply
1 point

That’s not how that works lol

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 17K

    Monthly active users

  • 12K

    Posts

  • 556K

    Comments