Personal Privacy within the Internet of Things: Smart Home Devices, Smart Spying?

Within the past several years, it has become increasingly apparent that modern technology has altered the ways in which we interact with our surroundings. As companies continue to develop products that go far beyond the usage and functionality of smartphones, a vast diversity of internet-connected physical devices has gained paramount popularity in recent times: from home automation systems that automatically know when to turn your kitchen lights off, to intelligent AI-driven personal assistants that can help you buy your daily needs with a single voice command.  The interconnectivity of such an environment in which physical objects have the capability to interact with other objects and people is known as the ‘internet of things’.[i] Everyday objects that we use, from smart TVs and smoke detectors, to washing machines and wearable devices, connect to each other through embedded technologies that allow them to sense, gather data and communicate with their surroundings. However, the network of the internet of things is not confined to mere personal households, as it also comprises the interconnectivity of street lights, traffic sensors, city pollution monitors and so on.

In 2007, the total number of devices connected to the internet surmounted the number of people on earth.[ii] This figure is expected to continue its rapid growth with experts estimating that there will be at least 50 million connected devices by 2020.[iii] This rising prominence of the internet of things may seem like an exciting prospect – and to a certain extent, it indeed is. With almost everything connected to the internet, trivial personal tasks in our daily lives have been considerably easier to carry out, and we have experienced unprecedented conveniences that would have been unimaginable just a decade ago. Nonetheless, the ability of everyday objects to send and receive data seamlessly has raised concerns regarding its implications towards personal privacy.  As we unsuspectingly allow technology to play a part in almost every aspect of our life, how do we ensure that our privacy and personal information is not compromised? These worries are not without valid reasoning, as internet-connected devices allow the direct collection of sensitive personal information such as precise geo-location, financial account numbers and private health information. The collection of such information may indeed be crucial for the functionality of these devices, but users and consumers are faced with the continuous risk of their personal data being hacked and misused.

One particular aspect of the internet of things that has significantly raised privacy concerns is that of smart home devices. As users allow these electronic gadgets to invade the most intimate confinements of their homes, they are giving up confidential credentials of their private lives that are unknown to outsiders. This is because many smart home devices are embedded with ‘always-on’ sensors that capture users’ offline activities in their living spaces: from sleeping patterns, exercise routines, child behaviors and even sexual activities.[iv] Information regarding such activities is then transmitted outside of the users’ homes to cloud services managed by device manufacturers. The transmission of personal data is vital in creating real-time insights and analytics, which will then be used by companies to improve the services provided by their devices. However, it is actually at this exact point where personal privacy is violated, since consumers cannot specifically regulate which information they want and do not want to be passed on to these manufacturer-controlled servers.[v]  

Privacy is not only put at risk due to the sending of data to external cloud servers. Many smart home devices are also equipped with the ability to always listen to conversations happening within their surroundings. One example of this is the Amazon Echo, an innovative voice-controlled speaker that not only plays music but also offers consumers the ability to carry out other intelligent tasks. These include setting kitchen timers, adding items to shopping lists, reading the most recent news headlines, and providing real-time information of the traffic and weather. Powered by continuously improved artificial intelligence, the Amazon Echo does these tasks by silently listening to all forms of speech within its environment. It is then activated when the word ‘Alexa’ is spoken in which the device will proceed to interact and communicate with the consumer.

The novel futurism of the device led to its success in the tech market, with sales reaching up to 15 million units since its launch in 2014.[vi] However, the Echo’s ability to listen to every dialogue that is spoken within its surroundings poses a threat to the security of the consumer’s personal information. A British researcher highlighted this risk by demonstrating how the device could easily be hacked.[vii] By installing a specific type of malware, the device could be utilized as an eavesdropping tool to listen to conversations in an owner’s house – without the owner’s consent. Furthermore, hackers could perform other functions through the device, such as installing ransomware or stealing access to the owner’s Amazon account. This highlights how owners of smart home devices that are unfamiliar with digital data protection mechanisms may very well be potential victims of criminal acts.

It is not a surprise that modern technology such as smart home devices manage to attract major success in the market. Consumers are persistently curious as to what the latest tech has to offer, and AI-powered personal assistants such as the Amazon Echo pose no difference. Nonetheless, users must be aware of the risk that they are facing when choosing to purchase such products. Sufficient knowledge on potential privacy violations must be obtained before utilizing these devices, and companies must offer better transparency as to how data collection is carried out and for what purpose. The security of these internet-connected devices must also be enhanced to prevent unwanted access and misuse of personal information.

Editors: Diah Ratna Pratiwi, MDEV; Viyasa Rahyaputra, SIP

Picture: pexels


[i] FTC Staff Report. (2015). Internet of Things: Privacy and Security in a Connected World.

[ii] Evan, Daves. (2011). ‘The Internet of Things: How the Next Evolution of the Internet is Changing Everything.’ (online). Available at http://www.cisco.com/web/about/ac79/docs/innov/IoT_IBSG_0411FINAL.pdf [Accessed 21 November 2017].

[iii] Ibid.

[iv] Apthorpe, Noah et. al. (2017). Spying on the Smart Home: Privacy Attacks and Defense on Ecrypted IoT Traffic. Cornell University Library (online). Available at https://arxiv.org/abs/1708.05044 [Accessed 23 November 2017].

[v] Paul, Deanna (2017). ‘How Smart Devices Could Violate Your Privacy’. Rolling Stone (online). Available at: http://www.rollingstone.com/culture/features/how-smart-devices-could-violate-your-privacy-w492823 [Accessed 23 November 2017].

[vi] Darrow, Barb. (2017). ‘Amazon Echo Is the King of Home Assistants. Here’s More Proof’. Fortune (online) Available at http://fortune.com/2017/09/18/amazon-sells-15m-echos/ [Accessed 24 November 2017].

[vii] Greenberg, Andy. (2017).  ‘This hack lets Amazon Echo remotely snoop on users’. Wired (online). Available at https://www.wired.co.uk/article/amazon-echo-alexa-hack [Accessed 24 November 2017].