If you like to play along with the illusion of privacy, smart devices are a dumb idea
- Reference: 1694088667
- News link: https://www.theregister.co.uk/2023/09/07/smart_devices_privacy/
- Source link:
The consumer rights organization's analysis of a number of IoT products – from speakers and security cameras to TVs and washing machines – found that they all demand customer data above and beyond what is needed for the product to perform its function, and then distribute that information to a horde of faceless corporations.
Consumer campaign group Which? pointed out that this means consumers are not only in many cases paying thousands for the product itself, with all its "smart" connected bells and whistles, but continue to pay in the form of their personal data.
[1]
The outfit broke down what information is required to set up an account with the product manufacturers, what permissions the associated apps request, and what customer activity companies are tapping into.
[2]
[3]
Spoiler alert: it's all for ads and marketing.
Disturbingly, every single brand examined required both exact and approximate location data – as though your fancy washing machine needed to "know" where it is to clean your clothes.
[4]
And while smart speakers are only supposed to listen after being invoked with a "wake" phrase, their data collection and who they share that with may surprise. For instance, researchers found that Bose products are shuffling info off to the Meta social media empire, meaning owners are giving data to Zuckercorp regardless of whether they have a Facebook account. And if they do? Well, expect eerily targeted ads.
A profound difference was also found in the amount of data requested from smart device owners depending on whether the associated app was installed on an Android or iOS phone. "For example, Google Nest products request contacts and location on Android, but neither on Apple's iOS," Which? said. "The app functions the same on both, so the additional data collected on Android does not appear to be essential."
The consumer champ confessed it did not understand why such information was necessary, but pointed to the fact that advertising underpins Google's entire business model, while Apple is all about selling overpriced hardware. Food for thought if your phone runs on the Android operating system, the most widely used version of which is primarily developed by Google.
[5]
Of all IoT devices, smart cameras and doorbells are perhaps among the most desired because people value the additional security these may provide for their home. But what they trade for that peace of mind is having their data funneled to other companies.
Ezviz, a brand of Hikvision, which is owned by the Chinese state, was singled out as a particularly egregious offender for tracking firms, including TikTok's business marketing unit, mobile app advertising platform Pangle, Huawei, Google, and Meta. Hikvision cameras are also [6]believed to be used by the Chinese government to persecute the country's Uyghur minority – although the company denies this.
Again, Google was found to be sucking up data from every smart camera or doorbell Which? looked at, while Blink and Ring devices also beamed it back to the Amazon mothership. "Google's Nest product demands full name, email, date of birth and gender," the charity said.
[7]UK drops 'spy clause' for scanning encrypted messages, admits it's not 'feasible'
[8]Norway court upholds miniscule fine against Meta for flouting privacy rules
[9]Mozilla calls cars from 25 automakers 'data privacy nightmares on wheels'
[10]Google Chrome pushes ahead with targeted ads based on your browser history
Once more, Euly, Arlo, and Ring were demanding to know Android owners' background location. Which? observed that this is unnecessary in the event that a home security system is triggered and means that users could be tracked even when not using the app. "All permissions are activated by default. Consumers can opt out, but this requires changing the settings and could lead to aspects of the device or app no longer working," it said.
Washing machines are smart now too, apparently, and the things they want to know about their owners have nothing to do with spin cycles. For example, LG and Hoover products don't allow use of their apps without knowing how old you are. LG was the worst for prying, wanting "name, date of birth, email, phone contact book, precise location and phone number," while Hoover demanded "users' contacts and phone numbers on Android devices." For Miele products, precise location tracking is enabled by default and required to use the app.
Which? also took aim at smart TVs, which, while possessing phone-like operating systems themselves and not requiring a phone app to use, also track user behavior to flood their menus with ads. LG, Samsung, and Sony were put on blast for their "accept all" list of trackers, which otherwise requires owners to manually decline access one by one.
"Under the General Data Protection Regulations (GDPR), companies must be transparent about the data they collect and how it is processed. The data collected must also be relevant and limited to what is necessary for the processing to take place," Which? concluded.
"However, the reasons for taking information are often too broad for consumers to appreciate, with companies claiming 'legitimate interests'. While it all should be listed in a privacy policy, the reality is that when consumers come to click 'accept', unless they closely analyse the fine print, they have little to no idea what will actually happen next with their data."
Rocio Concha, Which? Director of Policy and Advocacy, commented: "Consumers have already paid for smart products, in some cases thousands of pounds, so it is excessive that they have to continue to 'pay' with their personal information.
"Firms should not collect more data than they need to provide the service that's on offer, particularly if they are going to bury this important information in lengthy terms and conditions."
She added that government data watchdogs "should consider updating guidelines to better protect consumers from accidentally giving up huge swathes of their own data without realising."
We've asked the ICO to comment.
With reference to Echo, Blink and Ring devices, a spokesperson at Amazon claimed: "We design our products to protect our customers' privacy and security to put our customers in control of their experience." The company added it "never" sells the personal data of its users.
In a rather more brief statement, Google said it "fully complies with applicable privacy laws and provides transparency to our users regarding the data we collect."
German appliance maker Miele claimed the data it collects is to "optimise qppliance usage and to offer customers additional features and functionalities". Asking punters to specify their location is to provide customers with "relevant services", it further asserted.
Samsung too claimed privacy is only ever "top-of-mind" when it is creating stuff, "our customers are given the option to view, download or delete any personal data that Samsung has stored across any product or app that requires a Samsung account."
We have asked Apple, Bose, Hoover, Hikvision, LG, Beko and Sony to comment.
Which? provides a number of tips on how to improve your data privacy, including caring about what you share, checking permissions, denying access, deleting recordings, and reading privacy policies.
But The Reg says that if you're really concerned about privacy, you'd do better to not buy these things, throw away your mobile phone, and move to a shack in the wilderness. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPnzo9U0D4IbQ-6EyPfb8QAAA5U&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPnzo9U0D4IbQ-6EyPfb8QAAA5U&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPnzo9U0D4IbQ-6EyPfb8QAAA5U&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPnzo9U0D4IbQ-6EyPfb8QAAA5U&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPnzo9U0D4IbQ-6EyPfb8QAAA5U&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/20/hikvision_surveillance_camera_commissioner_uighur_controversy/
[7] https://www.theregister.com/2023/09/07/uk_government_clause_online_safety_bill/
[8] https://www.theregister.com/2023/09/07/norway_meta_fine/
[9] https://www.theregister.com/2023/09/06/mozilla_vehicle_data_privacy/
[10] https://www.theregister.com/2023/09/06/google_privacy_popup_chrome/
[11] https://whitepapers.theregister.com/
True, but it does spend a lot of time making DNS requests to checkonline.home-assistant.io
Why would a Washing Machine require my Date of Birth ...
... in order to be able to function correctly?
Re: Why would a Washing Machine require my Date of Birth ...
The only thing I can think of, and this is quite a stretch I admit, is that it's a matter of verifying you're old enough to legally enter into a contract in whatever region you're located. Of course that kind of falls apart when you consider how many people below the legal age of majority are likely buying washing machines. It's probably a rounding error on a rounding error.
Quite
I think my next TV’s going to a nice big gaming monitor. Meanwhile, my LG’s name service is mediated by PiHole, and I have no apps installed on it. Well, apart from the shovelware that can’t be deleted. (They’re on my Apple TV, which some might say is overpriced, while others might counter that one’s ponying cash up front to replace what would otherwise have to be squeezed out of surveillance later.)
"what they trade for that peace of mind"
is the ability to get home when "smart" doorbell servers are offline.
Which is, of course, a million to one chance, so it happens nine times out of ten when you really need to get inside.
And I'm sorry, but I think there must be a mid-term between selling my personal data to all and sundry and living like a cave man.
It's called dumb terminals, dumb switches, dumb doorbells (get your fat ass off that couch and go see who's there), dumb shutters and a VPN for when you just can't help it.
Re: "what they trade for that peace of mind"
" between selling my personal data to all and sundry and living like a cave man "
Apologies, but that's a false comparison. There are about 4000 years (here in the UK at least) between the present and the 'cave man' period, and during that interval we have mostly lived at a much higher standard than it implies. Indeed, just 30-odd years ago, before all this appification took place, we were in general very comfortable.
Just for example, my washing machine is 33 years old, connects to the electric mains and the water supply only. During that time it has needed one replacement valve and one replacement pump and it does a perfect job to this day.
It's probably still possible to eschew the snoopy connectivity without going to live in a cave, just by carefully choosing kit that will work with it unplugged. My sole concern is that future kit will be designed not to work unless connected.
The doorbell is for answering the door when you're out. Or can't get to it to answer. I very much doubt many people use their phone if the bell rings when they're at home.
But that's really not the point. All these tech companies have seen an opportunity to gather data for advertising/marketing or flogging off to the marketing businesses. And they've taken it. Because no one has said they can't.
My Home Assistant app has location tacking enabled, not a default setting, and I use it to automatically turn on my lights if I arrive home when it is dark.
As far as I'm aware, the tracking information only goes to my own server.
The smart switches that the lights are connected to are from TP Link. They do come with an app, but I don't use it. I got a python script to provision them, so TP Link's cloud service doesn't get used at all.
Similarly
All this stuff is initially provisioned via the app with fake credentials entered and goes on it's own subnet.
After provisioning it is denied internet access.
As Paul Hibbert would say... HOME ASSISTANT! HOME ASSISTANT!
Enough! Eliminate the root cause
Make targeted advertising illegal. Make PII collection illegal, unless necessary for legal purposes.
Search ads would still work, since a search keyword would match an ad and user intent. Social media can f-off as easily manipulated and harmful anyway.
Not 'smart', but 'connected'. Don't fall in the marketing trap please.
"Bose products are shuffling info off to the Meta social media"
That's why people pay the Bose premium, right? To get their data slurped in just the same way as they do when they buy any cheapy Samsung mobile phone with an uninstallable Facebook app.
Re: "Bose products are shuffling info off to the Meta social media"
Wouldn't that be an undeinstallable app, which is pants.
When you see a device described as SMART, just remember that SMART means "Self-Monitoring, Analysis and Reporting Technology".
The only hard thing about avoiding all this crap is finding appliances with real buttons and dials.
I use some smart devices as I'm disabled and they help with daily living. However, I also have Pi-Hole set up and the amount of crap it blocks from devices calling home and trying to pass data to "user assessment", "ad brokers" and "market research" companies is unbelievable. Pi-Hole is, this minute, showing that 33% of outward DNS calls are blocked because they are trackers. That's 29K+ calls in the last 24 hours. The top blocked domain is amazonalexa.com with 10K+ blocked DNS calls, in just 24 hours! Devices still work perfectly, so what is it trying to send back that I'm blocking? Other domains in the top ten blocked are also Amazon related but everything still works just fine. Something called "Conveva" is second highest individual doman, at 2,000 blocked calls, providing "viewer egagement analytics" apparently. Of course, all devices on the network show a deluge of blocked calls for a wide variety of Google domains.
I've started using dumb, mechanical timers for turning lights on\off. Not only do they not snoop but they last for decades (I still have some old ones) unlike the IOT switches and lights which fail after a year of use.
Of course, the business model only works because people are daft enough to provide real data. They get away with selling it on because it has value. I've been putting nonsense into things like this for years now. If the rest of you did the same the business model would have long since been discredited and collapsed.
Recently, I visited my [retired] parents for a brief visit as a [retired] relative was visiting them while I was at work the next day. I dropped off a bit of very obscure century old bit of equipment for him, as he's an engineer and enjoys playing with things like that as it's directly connected to his interests.
The next day eBay adverts for precisely this very obscure century old bit of equipment were displayed to me. At no point had I ever searched for this online or indicated any interest in it.
It therefore follows that some smart device had (in no particular order) :-
1) Recorded our conversations.
2) Converted the speech to text and uploaded it to f*** knows where.
3) Identified the participants in the conversation by some means.
4) Picked out items mentioned repeatedly in the conversation.
5) Matched the participants of the conversations to their online accounts.
6) displayed targeted advertising to those accounts based on the above.
I personally find that considerably more 1984ish than i'm comfortable with, especially given that I don't have a single smart piece of equipment at home, meaning that all of this happened from my parents equipment.
It's rather thought provoking as to exactly how much surveillance we are actually under though, and one has to wonder about the sort of nefarious uses this could be put to by people with interests beyond advertising.
I try to do most things locally via Home Assistant so that I can at least tell myself it's private.