A simply trick to improve the privacy of your Alexa devices

Et cetera
4 min readJan 18, 2021

--

It’s stupid simply but why not put a smart plug under the Echo and use itself to securely cut the power/microphones to itself? …it just works and with some tips will surely improve your privacy a bit.

The background: I have some Meross smart plugs in my home, and one it was under the mosquito repellent plug-in, in order to turn it on/off before I go to sleep with an automation, in order to “clean up” the room from mosquitos :-) But now it’s winter and there isn’t any mosquito, so I was with this smart plug without know what/where place it. Thinking about it I said “ehy why not put it under the Echo Studio in order to turn it off with a simply stupid voice command when I don’t want that it can hear me and without going to press the stupid distant mic off button”? No problem:

All I have to do is said “Alexa turn off Echo” and the smart plug cut the power to it. Well the trouble obviously is when I want to turn the Echo on again, there’re two ways to do it: via the Meross app or via another Echo in the house (if you have it).

Via the Meross app is the simply way, the only trouble is that also your smart plug can mess with your privacy, for that I have searched all the requests that it makes, and I was pretty surprise in discovery that it makes almost no “call home”, only some request to the ntp servers (for setting the time) and sometime to matt.meross.com that is the domain used for the firmware updates, but very few requests are made, see this statistics compared to the other devices at home:

And here all the request it has made in the last 10/12 hours

But hey, you wanna trust a chinese company called Meross? Well, I don’t think it can retrieve very important datas, much of them are only usage stats (at least I hope, I haven’t still investigate in deep) but if you are concerned about the privacy you can improve it and still use all this nice features.

You have to block all these domains via your Pi-Hole (if you’re using it, if not, install it, I wrote a tutorial/how to with my setup: Nerdy things made nicer: Raspberry PI 4B with Pi-Hole + Unbound and Pimoroni HyperPixel 4" display)

iot.meross.commqtt-eu.meross.commqtt.meross.com

But now you would say “now it’s useless because I can’t no more turn off/on my other plugs or Echo”, well this is not true. Because all the things are inside you home/LAN and for that the app will still work, you will only receive an alert every time you open the app, because it can’t send the status on/off to Meross servers and they can’t know if your device is on or off, but is what we wanted to do! The app still works fine, just tap an icon and it will turn on/off, also with Alexa devices you will still be able to say “Alexa turn off Echo”.

The true downside is that you can’t turn any plug on/off when in 4G obviously. But this doesn’t make any problem to me, because I don’t want to turn on/off my backup, audio or Echo or desk lights when I’m not at home, they should be already off. But this is not the perfection solution for everybody, so keep this in mind:

To me looks all. Yes, not own these devices with a microphone is surely more privacy-safe but we have to live with the tech of 2020, but we can mitigate the impact of these devices on our privacy, and I hope this easy trick will help a little.

--

--

Et cetera
Et cetera

No responses yet