SecuritylabJuly 29, 2026🇷🇺Translated from Russian

Smart Speakers Always Listen: Privacy Controls for Yandex Alice, Marusya, Salyut, Siri and Google Assistant

Smart speakers and phones keep their microphones powered even when no one is speaking to them. The only purpose of this constant listening is to catch a short wake phrase such as Yandex Alice, Marusya, Salyut, Hey Siri or OK Google. Until that phrase is detected, audio normally stays on the device and is not transmitted to the cloud.

Yandex states that Alice processes sound locally for the activation phrase only. After the wake word is heard, the request is sent to Yandex servers. The same local-detection model is used by VK Marusya and Sber Salyut. Apple applies an on-device detector for “Hey Siri,” while Google Assistant and Gemini rely on account settings and device microphone permissions.

Hardware mute options

Most dedicated speakers provide a physical button that disables microphones at the hardware level. On Yandex Station models the crossed-microphone button turns the LEDs red. VK Capsule and VK Capsule Mini show a red ring when muted. SberBoom Mini requires a two-second press of the AI-assistant button to achieve the same red state. Phones lack an equivalent global hardware switch, so users must rely on software toggles.

Recommended privacy settings

  • Disable “Listen for Hey Siri” and “Allow Siri When Locked” in iOS Settings.
  • Turn off “Web & App Activity” and “Gemini Apps Activity” at myactivity.google.com.
  • Revoke microphone access for unused apps in Android and iOS permission menus.
  • Switch off the “Help Alice improve” toggle inside Yandex ID.
  • Delete stored voice histories through each provider’s data-management portal.

Even with these steps, the microphone itself remains the only reliable way to guarantee silence. Security-conscious users are advised to mute devices during meetings, medical calls or any discussion involving financial or personal data.

Related articles

AntiMalwarePrivacy & Surveillance

Apple Updates Find My in iOS 27 to Automatically Switch Location Source to Apple Watch

Apple is enhancing the Find My application in the upcoming iOS 27 release to intelligently switch the source of a user's location data between devices. The current system relies on a single selected device, typically the iPhone, which causes inaccurate location reporting when the user leaves the phone at home. In iOS 27, the app will detect when paired Apple Watch devices move far from the iPhone and automatically begin transmitting coordinates from the watch instead. The feature supports both standard Apple Watch models and cellular variants, with LTE-equipped watches providing more reliable updates without depending on Wi-Fi or nearby iPhones. watchOS 27 will also consolidate the separate Find People, Find Devices, and Find Items apps into a single unified Locator application featuring a full-screen map and Digital Crown navigation. Both iOS 27 and watchOS 27 are currently in beta testing, with a public release expected in September.

AntiMalwarePrivacy & Surveillance

Russian Users Report BiP and KakaoTalk Inaccessible Without VPN, Suspecting Roskomnadzor Filtering

Russian home users have started complaining about disruptions in BiP and KakaoTalk messenger services. Messages fail to send or receive without a VPN connection, but function normally once a VPN is enabled. The issue reportedly began three days ago and affects the author, relatives, and friends according to a Pikabu post. Beeline support denied any operator-side restrictions, and Roskomnadzor has issued no official statement on blocking the services. Similar reports have emerged from other users, including those in the Volga region, with the consistent symptom that direct connections fail while VPN routes succeed. No independent technical confirmation of traffic filtering exists yet, and complaints may relate to specific operators, regions, or service infrastructure. The pattern matches previous Russian experiences with content filtering, though official confirmation of any block on BiP or KakaoTalk remains absent.

AntiMalwarePrivacy & Surveillance

One Underscore, 18 Months in Prison: Username Typo Sends Innocent Man to Jail

Brandon Klaym, a resident of Nova Scotia, spent 18 months in prison after Canadian and U.S. authorities confused two similar Kik usernames during a child exploitation investigation. Police sought records for the account fus__ro_dah but requested data for fus_ro_dah, directing them to the wrong individual. The error originated in a 2018 Wisconsin case involving 125 messages sent to a 12-year-old girl; the real suspect used a Skyrim reference that contained two underscores. Kik supplied Klaym’s subscriber information, and his IP address led investigators to Canada. Despite finding no evidence on his devices and no proof he had ever used Kik during the relevant period, prosecutors charged him with multiple child-sex offenses. He was convicted in 2023, served his full 18-month sentence, and was only exonerated in 2024 when the correct username was examined during appeal proceedings.

AntiMalwarePrivacy & Surveillance

Free VPNs Fail Within Days as Russian Filters Detect Tunnels Without Decrypting Traffic

Free VPN services promoted in Telegram now stop working after just a few days, with Instagram Reels freezing, YouTube stalling in endless loading, and Google Gemini returning 403 errors. Modern Russian content filtering systems have advanced beyond simple IP blocking and can identify proxy tunnels through indirect traffic characteristics such as packet sizes, inter-packet intervals, and TLS handshake structures. A common failure pattern involves connections succeeding initially before data transfer abruptly slows or drops after roughly 16 KB, a behavior linked to deep packet inspection recognizing proxy patterns. Users and developers counter these detections with techniques including packet fragmentation, reduced TCP segment sizes, and tools like zapret to desynchronize analyzers while preserving normal server-side flow. Services such as sing-box employ uTLS to better mimic legitimate browser TLS fingerprints, while ShadowTLS v3 and padding methods help mask connections as ordinary HTTPS sessions to allowed resources. Recommended working options include AmneziaVPN, Cloudflare WARP, Red Shield VPN, and self-hosted setups on Xray or sing-box, though some claims around hynet.cloud lack independent verification.