Google is nerfing all Home Minis because mine spied on everything I said 24/7 [Upd

most viewed right now
34 comments @thotties

section   (0 bx goons and 1 bystanders) Share this on Twitter       Share this on Facebook

 1 year ago '17        #1
1798 page views

xastey01 10 heat pts10
$1,156 | Props total: 1982 1982
Google is nerfing all Home Minis because mine spied on everything I said 24/7 [Upd

Just go to the site damn quoteing is all messed up, fu*ked up the title.

visit this link http://www.androidpolice. .. hing-said-247/

When the first home a*sistants were announced, I was excited. A device I could wake up with a simple hotword that would answer my questions, set reminders, turn on the TV, and dim the lights, all without me having to get off the couch, sounded fantastic. Amazon's Echo and Echo Mini, Google's Home, and a myriad others, most recently the Home Mini, have invaded our kitchens, living rooms, and bedrooms. Heck, I put one in the bathroom.

Without fail, every time a new listening device comes to market, some tinfoil hat-wearer points out how perfect they would be as modern-day Trojan horses for any of the three-letter acronym organizations - NSA, CIA, FBI - you name it. Manufacturers, on their part, a*sure us their devices are perfectly safe and only listen when prompted. We brush the concerns off and move on with our lives, but not before granting our smart pineapples (did you know "pineapple" is the codename for Google Home?) access to the smart rice maker, smart vacuum, and smart toothbrush.

I didn't give too much thought to these privacy concerns because they all sounded theoretical and unlikely. My four Google Homes and three Echos sat quietly on their respective desks and counters, and only turned on when one of three things happened:

I called out a hotword (Alexa for Echos and Hey or OK Google for Homes).
A video I was watching or podcast I was listening to did this (I'm looking at you, Marques!)
They heard a noise or word that they thought sounded like a hotword but in reality was not. This happened once or twice every few days.
That is until last week, when a 4th case came along - 24/7 recording, transmission to Google's servers, and storing on them of pretty much everything going on around my Home Mini, which I had just received at the Made by Google October 4th launch event.

Before I describe exactly what happened and how I discovered this pretty incredible violation of privacy, I'd like to point out that it ended up being a hardware defect in my Home Mini as well as an unspecified small number of others. Google never intended for it to happen, and has reacted incredibly swiftly to rectify the situation.
So what happened?

Wednesday, October 4th

I went to the Google launch event in San Francisco that I'm sure many of you watched closely. In addition to the two new Pixels, the Pixelbook, Pixel Buds, and Google Clips, Google introduced the Home Mini, a tiny $50 version of the Home we'd expected for several months. Everyone in attendance got to take one home, and having run out of rooms to put it in, I stuck mine in the bathroom. Before you go raising your eyebrows, this is a room I spend a considerable amount of time in, listening to podcasts, music, and asking Google random questions when I get ready for the day in the morning.

Several days passed without me noticing anything wrong. In the meantime, as it turns out, the Mini was behaving very differently from all the other Homes and Echos in my home - it was waking up thousands of times a day, recording, then sending those recordings to Google. All of this was done quietly, with only the four lights on the unit I wasn't looking at flashing on and then off.

In the meantime, Android Police, along with numerous other publications, gave the Mini glowing reviews. Their units were fine. Mine, however, was not (#artemsluck as usual).

Friday, October 6th

I turned on a TV located not too far from the Mini and attempted to watch a show. I say "attempted" because during the first 10 minutes, the Mini turned iwtself on several times a minute, listened to whatever was on the TV, and attempted to respond, usually by saying it did not understand. At some point, it even somehow managed to take over my Spotify stream that was playing in the office and switched it to the bathroom:

At this point, I was ready to chuck the Mini at a wall and yell at David for not noticing the very obvious sensitivity issue that was dialed up past 11 all the way to 111.

Having freshly discovered the day prior that Google's My Activity portal on the web contained an a*sistant-specific section, I opened it up, and my jaw dropped. I saw thousands of items, each with a play button and a timestamp, all attributed to the cryptically named com.google.android.apps.chirp/mushroom/prod and a*sistant. See for yourself:

At this point, I remembered chirp was the codename for the Google Home ecosystem and realized mushroom likely referred to the Mini, since the regular Home is pineapple. After listening to a dozen audio clips that looked something like this...

... I went back to the bathroom to take a closer look at the mischievous Mini. Was I grossly misunderstanding how a*sistant works or was there something seriously wrong?

Yes, everything you tell your a*sistant is recorded and stored on Google's servers unless you explicitly disable it in My Activity, which will adversely affect the accuracy of recognition.

I turned on a nearby TV and started recording. Here's what I saw:

Just to clarify, the audio is not coming out of the speaker next to the Home Mini, but from a TV speaker a few feet away.

As you can see, the Home Mini quietly turns on, flashes its lights, then shuts off after recording every sound. When the volume increases, it actually attempts to respond to random queries. I was even able to get it to turn on just by knocking on the wall.

Friday, October 6th - 4:22pm

At this point, I realized the seriousness of the situation and contacted Google PR. I described the issue, added "urgent" to the subject, and sent it off, not expecting a response until Monday at best.


Please forward this to the Google Home team for a response. We are working on a story and will publish in the next day or so. I just discovered the issue and based on my understanding, it's quite a serious violation of privacy, specific to the Google Home Mini. Could you please confirm that the Mini's codename is "mushroom"?

Here's an example screenshot from the Google My Activity page, filtered by a*sistant. As you can see, there are thousands of triggers that record, transmit, and save the audio snippets on Google's servers. All of them say they were triggered by a hotword. It's obviously not true. I also noticed the Home Mini is extremely sensitive to nearby sounds (TV, speech, etc.) and has a lot of false positives, including ones that result in an audible response (usually that it didn't understand what was asked).


Now here's the kicker - based on Google My Activity, the onslaught of thousands of transmitted and saved a*sistant-related audio queries started on the day the Home Mini was set up (October 4). The mention of "com.google.android.apps.chirp/mushroom/prod" does not appear before then either, all pointing to the Home Mini being the culprit and not the larger Homes, Android TVs, or phones.

Needless to say, if a listening device records almost every minute of every day and stores it remotely, we're talking about a huge privacy violation. Does Google have a comment about this?

Thank you.


Friday, October 6th - 4:32pm

To my surprise, the first reply came in 10 minutes later. They were looking into it. I replied with a few more details.

Friday, October 6th - 5:58pm

Google a*sured me that this was the first time they've heard of this issue and were really interested in swapping out my unit to examine it.

Friday, October 6th 7:00pm

Google PR was on the way to my house to pick it up. Mind you, we're talking about a Friday night here. That's dedication! I wasn't home at the time, but by 9pm, the exchange was made. In fact, I was left with two replacement Google Home Minis for my trouble. I'm on to you, Google! (/s)

An engineer was driving up to Oakland to examine it that very night. It was clear how seriously they were treating the situation.

Saturday, October 7th

The next day, Google sent me its initial a*sessment that I will quote here:

We have learned of an issue impacting a small number of Google Home Minis that could cause the touch mechanism to behave incorrectly. We are rolling out a software update today that should address the issue. If you're having any additional issues, please feel free to contact Google Support at 1-855-971-9121.

I asked for some clarifications and gave them more time.

Sunday, October 8th

Further clarifications arrived. The Google Home Mini supports hotword activation through a long press on the touch panel. This method allows people to activate the Google a*sistant without saying the hotword. On a very small number of Google Home Mini devices, Google is seeing the touch panel register “phantom” touch events.

In response, the updated software disables the long press to activate the Google a*sistant feature. Once the Google Home Mini devices receive the updated software, all long press events (real or phantom) will be ignored and Google a*sistant will not be invoked accidentally.

The company also let me know that they're in the process of building a long-term fix, whatever it may be. It's too early to say if they're going to be able to deal with "phantom" touch events entirely in software or if a recall for affected units will be in order.

Monday, October 9

I followed up with some more questions.

Tuesday, October 10

The firmware I was originally running was 1.28.99351. Google says the new firmware is 1.28.100122, and the rollout has already been completed.

You can also see that the online Home Mini documentation has been updated to reflect the above:


So there you have it. Don't be surprised that the long-press to activate a*sistant functionality, described in many reviews, isn't working. My Google Home Mini was inadvertently spying on me 24/7 due to a hardware flaw. Google nerfed all Home Minis by disabling the long-press in response, and is now looking into a long-term solution.

I'd like to once again commend the company's reaction to my report and the speed at which they issued the OTA that dealt with the problem right away, giving them time to look for a proper fix.

Google has just published a support page to address the reported issue. The company a*sures pre-order customers that their units won't be affected, and the defect should be limited to the batches given out at Made by Google events, which presumably includes 4,000 Home Minis distributed at the donut pop-up events as well as the ones from the October 4th press event.

Additionally, Google has removed all existing activity generated by long pressing the top of a Mini from their servers.

It's still unclear at this point what the fate of the long-press feature is in the long term.

[Fixed issue] Google Home Mini touch controls behaving incorrectly
The Google Home team is aware of an issue impacting a small number of Google Home Mini devices that could cause the touch control mechanism to behave incorrectly. We immediately rolled out a software update on October 7 to mitigate the issue.

Who is affected: People who received an early release Google Home Mini device at recent Made by Google events. Pre-ordered Google Home Mini purchases aren’t affected.

My Activity: We take user privacy very seriously. We've removed any activity/queries that were created by long pressing the top of a Google Home Mini between October 4 and October 7, when the software update was rolled out. That information will no longer be listed on your My Activity page. You can also always go to your My Activity page and delete any past activity from your account.

Next steps: If you're still having issues, please contact Google Home Support at 1-855-971-9121 to get a replacement Google Home Mini.
visit this link http://www.androidpolice. .. hing-said-247/

Last edited by xastey01; 10-10-2017 at 07:51 PM..

7 comments for "Google is nerfing all Home Minis because mine spied on everything I said 24/7 [Upd"

 1 year ago '16        #2
Birdmans Hands 4 heat pts
avatar space
$3,309 | Props total: 7620 7620
How would it known you said Alexa to turn it on.... if it wasn't already listening.

Reminds me of the dumbasses that didn't understand that "plays back the last five seconds of voice" would require always on...

 1 year ago '17        #3
TheeMrDavid 2 heat pts
avatar space
$1,578 | Props total: 6556 6556
Its like Live Photo’s. If your camera can show you a second before you took the pic that means it’s always on.

 1 year ago '09        #5
messy marv stan 5171 heat pts5171
avatar space
$69,668 | Props total: 112498 112498
even the switch off option dont mean sh*t. the device is still listening 24/7/365 no matter what.... its just there as a legal step to fool the public into thinkin that sh*t can be switched off

 1 year ago '17        #6
arms 20 heat pts20
avatar space
$1,345 | Props total: 6108 6108
 arms said
It live steams all your conversations directly to an NSA server where a super computer on steroids analyzes it for real time threats.

All these phones, tv's, personal a*sistants, webcams, laptops, refrigerators and anything else with a mic, camera and internet connection can be used to spy on you. And anything that responds to voice commands without pushing a button is a dead fu*king giveaway. It obviously has to be listening in order to hear you ask it to do something. One way or another, we're fu*ked.

 1 year ago '17        #7
xastey01 10 heat pts10 OP
$1,156 | Props total: 1982 1982
 Birdmans Hands said
How would it known you said Alexa to turn it on.... if it wasn't already listening.

Reminds me of the dumbasses that didn't understand that "plays back the last five seconds of voice" would require always on...
 messy marv stan said
even the switch off option dont mean sh*t. the device is still listening 24/7/365 no matter what.... its just there as a legal step to fool the public into thinkin that sh*t can be switched off

The fact that Google acknowledges that its a bug shows that the "always listening" feature isn't suppose to work like this. Thats the different. Of course its always listening to pick up sh*t but the function on how it should work and what it should store wasn't working as intended. Thus google providing a fix for it.. if it was as intended then they wouldn't have say anything.. simple

Difference here is the device was uploading and saving data without the trigger word being used.

It should only upload and save when the trigger word is used.. this was auto turning on and uploading everything every couple of second or so. Big difference, the device may be always listening but what it's listening shouldn't be broadcast to google severs until a trigger word is used and it's only broadcasted from the point the trigger word is use.

Last edited by xastey01; 10-14-2017 at 07:41 AM..

 1 year ago '10        #8
kamianisan 16 heat pts16
avatar space
$3,105 | Props total: 722 722
I was wondering what was up with it. I opened mine on the 9th (got it at the free event in NYC) and the long press wasn't working



most viewed right now
+23online now  12
Sara Molina: Tekashi 6ix9ine's Guilty Plea Deal is No Prison Time by Snitching..
2 days ago
most viewed right now
+115online now  11
Image(s) inside Come Get Your Mama, Bruh...
1 day ago
most viewed right now
-55online now  9
Image(s) inside Feb 15 - The plus-size era is over before it began
2 days ago
most viewed right now
+36online now  6
NBA Jay Williams' First All-Star Party Turned Into Fight Night
1 day ago
back to top
register contact Follow BX @ Twitter Follow BX @ Facebook search BX privacy