She tested 210 smart devices. Here's what they're hiding | IoT with Anna Maria Mandalari
Watch on YouTube →
Overview
Anna Maria Mandalari details research into the privacy and security risks of 210 Internet of Things (IoT) devices, revealing that many devices transmit data to third-party servers, even when features are opted out. Her team's experiments highlight issues with smart speakers misactivating, smart TVs collecting data via Automated Content Recognition (ACR) without consent, and generative AI browser extensions tracking sensitive information. The research also exposes vulnerabilities in smart medical devices and the ineffectiveness of many IoT safeguards.
Key takeaways
- Many IoT devices, including smart speakers and TVs, transmit sensitive data to third-party servers, often without explicit user consent or even when features are disabled.
- Automated Content Recognition (ACR) on smart TVs continuously captures viewing data, even when the user opts out, and shares it with entities like Google Analytics.
- Generative AI browser extensions pose a significant privacy risk, tracking detailed user activity, including sensitive personal and medical information, and sharing it with third parties.
- Smart medical devices using Bluetooth Low Energy are highly vulnerable to attacks that can manipulate data or disable critical functions, with potentially life-threatening consequences.
- Commercial IoT safeguards often fail to detect threats, misidentify devices, and can even introduce their own privacy issues by contacting third-party services.
- New edge-based AI solutions and upcoming regulations like the EU's cybersecurity certification aim to improve IoT privacy and security, but user awareness and technological advancements are crucial.
Chapters
- Modern objects are increasingly connected to the internet, forming the Internet of Things (IoT).
- The research aims to understand the trade-offs, specifically privacy and security, exchanged for the convenience and low cost of these devices.
- Over 210 different IoT devices, from pet feeders to smart wardrobes, were tested.
- A large-scale IoT testbed was established with over 210 devices.
- Testbeds were located in two continents: University College London (UK) and Northeastern University in Boston (US).
- Network traffic from devices was collected at the access point to capture all data packets.
- A significant portion of data from UK-based devices was sent to servers in the US or China, regions with less stringent privacy regulations.
- Popular doorbells recorded motion even when opt-out features were enabled.
- Smart TVs from LG and Samsung contacted third-party services like Netflix, Facebook, and Google without user accounts.
- Smart speakers (Alexa, Google Home) frequently misactivated, even with similar-sounding phrases.
- Smart speakers activate locally upon hearing a wake word or misactivation, then record and send audio to cloud services for processing.
- An automated methodology using video analysis and network traffic monitoring was developed to study smart speaker behavior.
- Experiments involved streaming 500+ hours of Netflix content to trigger misactivations and identify patterns.
- Devices from Microsoft, Echo 2, and Apple HomePod showed the most recordings.
- Misactivations could last up to 20 seconds, potentially capturing entire conversations.
- While wake word detection improved, misactivations still occurred, posing privacy risks.
- Recordings were sent to cloud services, often in different jurisdictions.
- Automated Content Recognition (ACR) technology, often enabled by default, tracks viewing habits.
- ACR clients take frequent snapshots or capture audio, create fingerprints, and match them against server databases.
- Samsung TVs captured screenshots every 500ms; LG TVs captured audio every 10ms.
- ACR functioned even when users opted out or used the TV as a 'dumb' display, sending data to third parties like Google Analytics.
- Generative AI extensions (e.g., Cider AI, Merlin) can capture web form inputs, screenshots, and entire conversations.
- A threat model considered these extensions as potential adversaries.
- Experiments involved creating specific user personas and prompts to test data capture and profiling.
- Extensions tracked web form inputs, including sensitive data like national security numbers and medical records, and shared this with third parties like Google Analytics.
- Wearable medical devices, particularly glucose sensors connected to insulin pumps, use Bluetooth Low Energy (BLE).
- BLE communication is vulnerable to sniffing, man-in-the-middle attacks, and denial-of-service attacks.
- With a $15 dongle, researchers could manipulate data (e.g., oxygen levels) and disable devices up to 30 meters away.
- A compromised glucose sensor could potentially lead to fatal insulin injection errors.
- Many IoT safeguards (software, boxes, router integrations) claim to enhance privacy and security but often fail.
- Testing revealed that safeguards contacted third-party tracking services and frequently failed to identify devices or detect threats.
- New technologies are being developed for edge-based AI to identify non-essential traffic and monitor power consumption for attack detection.
- Upcoming EU regulations (mandatory from Dec 2027) will require cybersecurity certification for IoT devices sold in the European market.
Summary, takeaways, and chapters were generated by AI from the video's transcript and may contain errors. The video belongs to its creator, The Royal Institution.