Site navigation

Smart Devices Leave UK Households Vulnerable

Ross Kelly

,

Smart Cities Scotland

An investigation by Which? claims that smart devices are leaving British households vulnerable to massive levels of corporate surveillance, with questions raised over data collection.

Internet-enabled devices are leaving British households vulnerable to “a staggering level of corporate surveillance” according to a new Which Smart Devices report.

As Britain’s homes become increasingly interactive and connected, information collected by household appliances is being sent to a myriad of manufacturers and third-party companies; with some companies failing to keep customer information secure.

With connected home, however, comes the risk of intrusion and misuse of gathered data, and the investigation conducted by Which? found that data gathered through smart televisions, security cameras and even toothbrushes could be hacked to allow others to watch and listen to people in their own homes.

Privacy campaigners have raised concerns over the findings of this investigation, and have warned that consumers across the UK could be leaving themselves vulnerable to disturbing levels of surveillance.

Unparalleled Intrusion?

As part of its investigation, Which? set up 19 different smart products, varying from everyday gadgets such as televisions and smartphones, to more fanciful smart devices such as suitcases or even toothbrushes. This many smart devices in one home may seem excessive, however the average UK household currently owns up to 10 connected devices, and this is set to rise to around 15 by 2020.

Over the course of one month, security experts Context Information Security (Context IS) were hired to investigate the scale of data being collected and shared by smart gadgets and their associated apps. The findings of the research provides a disturbing glimpse into the level of data collection by devices in our homes, with some vacuum cleaners that request to record audio on mobile devices.

There appear to be dozens of other companies working discreetly in the background of smart devices, and during testing Which? found that more than 20 operators – including marketing companies – were involved behind the scenes as homeowners went about their daily routine. Smart televisions were of particular concern, with just 15 minutes of usage resulting in the device being connected to an incredible 700 distinct addresses on the internet.

Alex Neill, Managing Director of Home Products and Services noted that “smart home gadgets and devices can bring huge benefits to our daily lives”, however the investigation highlights a disturbing trend of intrusion into our daily lives.

Recent scandals have brought forward the debate on how companies collect and use data, with whistle blowers at Cambridge Analytica having blown the lid on a culture of misuse and abuse. Alex Neill says companies have to operate in a transparent manner and ensure that consumers are adequately informed over what their data is used for, and where it is sent. She said: “Companies should be clear about how they are collecting and using data and ensure consumers feel in control about what they are sharing – without having to trawl through impenetrable terms and conditions.”

IoT In The Spotlight

This investigation focused heavily on the Internet of Things (IoT) and its application in British households, with the question of security of such devices being raised. As part of its research, Which? looked at the HP Envy 5020 Printer, ieGeek 1080p IP Camera and the Philips Sonicare Bluetooth electric toothbrush. Conclusions of the research are as follows:

HP Envy 5020 Printer

Hewlett Packard’s Envy 5020 printer reveals considerable information, including the file name of what is being printed and also the PC username. According to Which? “anyone snooping on a network can see it”. The printer also sends details pertaining to the file size and type to HP’s servers, as well as how many pages are printed and even the ink the person is using.

HP noted that those details are sent using encryption. However, this still points toward an incredible amount of seemingly mundane data that could be used for intrusive or nefarious means. The US-based company told Which? that this data is used “to enhance our customers’ experience, provide product support and improvements, and support business operations including delivering our Instant Ink services”. It also agreed to discuss concerns over local encryption in greater details.

Philips Sonicare Bluetooth Electric Toothbrush

The idea of a smart toothbrush would likely have been laughed off decades ago. An essential item in our day-to-day lives, this product could revolutionise how we view dental care. There are however, concerns over the data being collected by Philips’ smart product as it tells Philips your brushing habits, frequency and even technique.

Philips claims this is done purely to operate the associated app and that brushing data only be shared with your dentist if you give explicit permission. Providing greater insights into dental hygiene habits is a great example of how IoT devices can improve lives, however what is concerning is that the app asks for your exact location and for permission to record audio.

Philips admitted that it did this so it can provide users with the option to find a nearby store or outlet – just in case you feel the urge to go and stock up on more of its products – and that it has since decided to stop this function. As for audio recording, Philips said this function isn’t used for any purpose; why it would choose to add this in the first place is another question entirely.

ieGeek 1080p IP Camera

In seperate tests conducted with other consumer organisations, it was found that there were significant flaws in this wireless security camera’s app, which is provided by a company called Sricam. This meant that someone could access more than 200,000 passwords and device IDs for other ieGeek cameras. Through this flaw researchers could also see live video feeds of other users, and talk to those users through the camera’s microphone.

ieGeek and Sricam fixed this flaw in late March 2018, however further investigations subsequently found and disclosed other critical security risks with both the camera and its associated app. According to Which?, Sricam “declined to discuss our report with its technical teams, and so we were unable to address this issue fully at the time of publication.”

Protecting Your Data

If you want to avoid having so much personal information and data shared across the Internet, there are several simple activities which can help protect you:

First, check your settings, all of them. Dig into menus in the app or web interface to see what privacy controls are available. Some devices enable you to control what data is collected and shared, so it’s worth taking the time to investigate. Both Android and iOS now let users control more aspects of what data apps can access, so don’t simply accept the default settings and hope for the best.

Use a secondary e-mail address, set up just for registrations, which can catch all of the spam and wherever possible, don’t connect devices or services to your social accounts.

Finally and perhaps most obviously, ask yourself, do you actually need a ‘smart’ device? With some devices such as TVs it’s actually hard to buy a non-smart model. However, before you splash out on that IoT (Internet of Things) toothbrush or robot vacuum cleaner, consider whether the extra functionality it brings is really worth the possible data trade-off.

Ross Kelly

Staff Writer & Researcher

Latest News

AI Climate Energy

AI Net Climate Impact Could Be More Negative Than We Thought

AI Cybersecurity Funding Security

Cognition Eyes £40bn Valuation as OpenAI Unveils GPT-5.6-Cyber

AI

AI IaaS Spending to Surge 96% in 2026, Gartner Says

AI Editor's Picks

Anthropic’s Claude Introduces AI Watermark to Text