‘People have no idea’: How smart devices spy on us and reveal information about our homes (2024)

The home has traditionally been the family’s most private place. But first the mobile phone and now smart devices have entered that space. Their digital conversations mean that, often without the users’ knowledge, they share intimate details about the home that were previously impossible to obtain. Until now, research on these devices focused on external risks: is it possible to access a home camera from the internet? Is a smart speaker vulnerable to eavesdropping? Today, pioneering work by several universities and research centers has discovered that beneath the superficial calm of a house, there lurk many risks.

“One of the biggest problems is the invasion of privacy,” says David Choffnes, professor at Northeastern University in Boston and one of the co-authors of the work. “These weaknesses give attackers a clear idea of what is in your home, who is there, as well as where they are moving and when. We discovered that some apps take advantage of this to collect data from homes, for purposes that have nothing to do with their function. If our homes are our most private place, it seems like a serious invasion of privacy to me,” he adds.

Choffnes and his team at Northeastern set up a “living lab/apartment with over 100 devices,” dubbed Mon(IoT)r Lab, at their university. It’s like a big party, but with devices. In the lab, researchers from the university and other centers study the entire variety of behaviors and relationships that occur between the devices, from light bulbs and refrigerators to routers and speakers, which communicate with each other. This research also studies all of their connections with apps, both those that manage these devices and others that Android users have on their mobile phones, and both those who live in that house and those who visit it. Apple’s environment is much more private.

‘People have no idea’: How smart devices spy on us and reveal information about our homes (1)

EL PAÍS has asked Google, which bought Android in 2005 and has a line of smart devices, about this study. A spokesperson responded: “We greatly appreciate the security community’s research. We are constantly improving our security protections to help keep Android users safe.” The Android environment, due to its nature and number of actors, has a lot of challenges to overcome.

“I don’t think people have the slightest idea that all devices connected to Wi-Fi talk to each other in some way. And that has implications,” says Juan Tapiador, professor at the Carlos III University and another co-author of the study.

What type of information do these devices share? They are not like the conversations or messages we send. The type of information that they share ranges from unique device addresses (MAC), serial numbers, versions of vulnerable protocols, or even names of specific devices such as “Joe’s speaker in the dining room.”

All this information, and the services to which they connect, allow many details of our lives to be inferred, and could provide a digital fingerprint of our home, which would allow targeted attacks or surveillance. “The uncontrolled exposure of this information,” says Narseo Vallina-Rodríguez, researcher at Imdea Networks and co-author, “allows advertising services or spy applications to create a digital fingerprint of your home that uniquely identifies it or can infer your income level and habits.” Not only that, if these devices scan for new information frequently “they can infer who enters and leaves the house and your social structures to monitor their activities through networks and devices,” adds the expert.

We do not fully understand the risks

Users might think that all this is not such a serious issue because the information does not seem so private. They tend to misunderstand the risks involved in gathering dozens of specific pieces of information about a home. For example, this data is captured by apps that we carry on our phones and they collect the serial number of the router or the name of the connection, which allows us to know the location (without even accessing the device’s GPS). There are pages where Wi-Fis from all over the world are mapped. If two mobile phones access the same Wi-Fi, you not only know that they are close, but also where they are. If an app on the visitor’s mobile scans how many smart devices are there, and which ones, that data can help calculate the household income of that home.

“One of the things that was most difficult for us to understand is that the informative value of technical data is sometimes difficult to predict,” says Tapiador. The SSID, which is the name of the Wi-Fi network, is a good example. When a mobile scans the available networks, the name of all those nearby can be seen. “There are many online services that provide you with geolocation information based on that name,” continues Tapiador.

A specific example of the fearsome use of the combination of information that can be gathered thanks to these devices is given by Vijay Prakash, a researcher at New York University, and co-author of the study: “If a malicious actor abuses the information that floats freely in smart home networks they can track a user across devices from multiple vendors. For example, if a malicious application takes fingerprints from several users’ smart homes, and some of them visit the home of one of the other users — let’s call her Jane — with their phone on them, the application could infer Jane’s social relationships and schedules in which other users visit her.” It must be taken into account that this would not happen just once, but continuously.

The apps analyzed in the study had millions of downloads that contained software that collects this type of information. If an app has access to location data and scans Wi-Fi networks, it already knows that those networks are in that place: “This is crowdsourcing carried out by millions of people,” Tapiador continues. “There are maps with those names from all over the world. When you tell someone, ‘hey, this light bulb is picking up the SSID or MAC address of the router’ it’s the same as saying, ‘this light bulb is picking up the location of your house.’” That is not the only problem: “The question is what other relationships they can build from there. Allowing you to have access to traffic generated by your devices can have unanticipated consequences,” he says.

Without legal permissions

Many of these examples are not legal, but the Android environment is a jungle: “These practices have many implications, since they often occur without any type of user consent, and sensitive information such as geolocation or devices and users (data protected by the General Data Protection Regulation) is also obtained,” says Vallina-Rodríguez.

This is an example of the complex dance of conversations that devices have within a home, as explained in the research: “Six [of home device] applications transmit the [unique MAC] addresses of devices to the cloud, and the recipients are their own domains [for example, Alexa] or third-party providers such as Tuya, (a [home device] platform provider, based in China), and Amplitude, which is an analytics service.”

To a human, this combination of data may seem overwhelming and unbearable. But for machines it is their daily work. Beyond hypothetical security risks, this information feeds the enormous, dark machinery of global marketing and advertising, also called “commercial surveillance.” At the moment it is not happening, but just as we receive personalized advertising on mobile phones, the industry could identify our home and tailor the advertising to our economic and family situations: what is easier than discovering when a couple has separated or how much the friend who has come to your birthday party earns?

“Just as many pages create a fingerprint of the user so they can recognize them between sessions even if they delete their cookies,” says Tapiador, “we saw that it is possible to do the same for a home using the devices. It is a theoretical observation in the sense that personalization aimed at specific homes is not permitted today, but the possibility that it can be done still exists,” he adds.

Sign up for our weekly newsletter to get more English-language news coverage from EL PAÍS USA Edition

‘People have no idea’: How smart devices spy on us and reveal information about our homes (2024)

FAQs

‘People have no idea’: How smart devices spy on us and reveal information about our homes? ›

“The uncontrolled exposure of this information,” says Narseo Vallina-Rodríguez, researcher at Imdea Networks and co-author, “allows advertising services or spy applications to create a digital fingerprint of your home that uniquely identifies it or can infer your income level and habits.” Not only that, if these ...

Are smart devices spying on us? ›

Unauthorized access to your smart home devices can result in unwarranted surveillance and privacy breaches. Furthermore, the data collected by these devices can be shared with third parties, including advertisers, raising questions about the security and ethical implications of this practice.

How do I stop smart home devices from spying on me? ›

How do I stop my smart home from spying on me? Carefully review and understand the privacy policies of each device. Utilize privacy settings to customize preferences, disable unnecessary features, and control data sharing. Regularly update device firmware to address security vulnerabilities and enhance protection.

Are smart home devices invading our privacy? ›

Surveillance Risks

Smart cameras and doorbells from Ezviz are particularly data-hungry and share user data with multiple companies. These devices pose an increased risk of data leakage, sharing information with Google, Meta, Huawei, and TikTok's business marketing unit Pangle.

Are your appliances spying on you? ›

discovered many of our favorite household appliances and gadgets share private information with tech giants like Google, Amazon, Facebook and TikTok. Surprise, these companies take far more data than they need for the device to function correctly. How cute.

Is my phone being monitored by anyone? ›

New apps that appear without your knowledge, strange messages or notifications, and a slower-running device are also potential signs. Overheating, increased data usage, unusual noises during calls, and difficulties in shutting down the phone could also indicate tracking.

Are my smart devices listening to me? ›

The short answer is yes, your smartphone is technically always listening.

How do you disable smart TV spying? ›

To turn off programming data collection, go to Settings through either the home screen or the button on the remote > Preferences > Privacy Settings. Under Privacy Settings there are options for Device Usage Data, Collect App and Over-the-Air Usage, and Interest-Based Ads.

Can someone watch me through my TV? ›

Some smart TVs have cameras and microphones which cybercriminals can use to spy on you. Cybercriminals can overhear your conversations and watch you input your login credentials to your online accounts.

How do you know if someone put a listening device in your house? ›

Turn off all of your electrical appliances. Then walk into each room of your home, standing completely still. If you hear a soft buzzing or beeping noise, you may be able to pinpoint the location of the listening device.

What is the biggest danger of the smart home? ›

Many users control their connected home through a smartphone, which makes it a very valuable database for anyone wanting to hack into your life. This creates a high risk if your phone is hacked, stolen or if someone manages to eavesdrop on your connection.

How do you stop your smart devices from listening to you? ›

On your phone
  1. Tap Apps, then scroll down and tap Assistant.
  2. Select Hey Google & Voice Match.
  3. Under This device, turn the Hey Google toggle switch off.
Feb 22, 2024

How do I protect my home from listening devices? ›

How to Block Out Listening Devices
  1. Distort the sound that reaches the device by talking quietly or speaking only when there is loud ambient noise.
  2. Use another sound to mask your voice, like white noise, blaring music, or a vacuum cleaner.
  3. Block the sound completely using an audio jammer.
Sep 13, 2023

How to stop smart devices from spying on you? ›

8 Ways to Keep Your Smart Home Devices from Spying on You
  1. Secure Your Wi-Fi Network. ...
  2. Implement Network Segmentation. ...
  3. Enable Two-Factor Authentication (2FA) ...
  4. Review Privacy Settings. ...
  5. Regularly Update Firmware and Software. ...
  6. Secure Your Smart Assistant. ...
  7. Use a VPN for Remote Access. ...
  8. Monitor Network Traffic.
Nov 25, 2023

What are signs that your house is bugged? ›

There are a few signs that may indicate that your house is bugged. These include strange noises or clicking sounds on your phone, unexpected interference on your TV or radio, and unexplained changes in your home's electrical system.

How do you know if someone is spying on you in your home? ›

A clear sign you're being spied on – new items in your home or office appear from nowhere. Beware of new items at home or in your office. If you notice anything new, like a wall clock, phone, lamp, or even a picture frame, ask where it came from.

Does the government watch us through our devices? ›

Although it's not a common practice, government authorities might be watching you through your phone. But for that, they need to introduce a specific type of surveillance program, such as malware or spyware, on your device. To avoid that, it's worth using a reliable antivirus tool, such as VeePN's Antivirus.

Do smartphones spy on us? ›

GPS tracking, microphone recording, camera surveillance, and accelerometer monitoring are just a few ways our phones collect information, and they do it without your explicit permission. Let's look at how your smartphone spies on you and collects data.

Is technology spying on you? ›

A significant number of smart devices share user data with third-party entities. This data exchange is often unbeknownst to users. It raises concerns about the extent to which companies are sharing our personal data as well as doing so without explicit consent. Voice-activated devices, like Alexa, are common.

Can a smart TV spy on you? ›

The streaming apps on your set may collect data on you, even if you don't ever sign in. And your smart TV will also collect information for its manufacturer, possibly including your location, which apps you open, and more.

Top Articles
Latest Posts
Article information

Author: Tyson Zemlak

Last Updated:

Views: 6341

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Tyson Zemlak

Birthday: 1992-03-17

Address: Apt. 662 96191 Quigley Dam, Kubview, MA 42013

Phone: +441678032891

Job: Community-Services Orchestrator

Hobby: Coffee roasting, Calligraphy, Metalworking, Fashion, Vehicle restoration, Shopping, Photography

Introduction: My name is Tyson Zemlak, I am a excited, light, sparkling, super, open, fair, magnificent person who loves writing and wants to share my knowledge and understanding with you.