IoT devices create security gaps because they collect data constantly, often with weak passwords and no way to update their software
An IoT device is anything that connects to the internet and collects or sends data — a smart doorbell, fitness tracker, connected refrigerator, security camera, or smart speaker. The risk is not that these devices will explode or fail catastrophically. The risk is that they sit in your home or on your body, gathering information about your habits and movements, and they are often easier to break into than your computer or phone.
Most IoT devices ship with a default password that is the same across thousands of units. Many cannot receive security updates at all, or the manufacturer stops sending them after a few years. A person on your home network — or someone who breaks into your network from outside — can use these devices to see when you are home, record audio or video, steal your Wi-Fi password, or use your device as a stepping stone to reach your computer or phone.
The manufacturers of these devices are often small companies that do not employ security teams. They prioritize getting the product to market quickly over building it securely. Once the device is in your home, you have limited control over what data it sends back to the company's servers, where it is stored, or who can see it.
Key Takeaways
- IoT devices often come with default passwords that are identical across thousands of units and rarely get changed by the person who owns them.
- Many IoT devices cannot receive security updates, or updates stop after a few years, leaving known vulnerabilities unfixed.
- A single compromised IoT device on your home network can give an attacker access to your Wi-Fi password and a path to your computer or phone.
- IoT manufacturers collect data about your location, habits, and movements, and that data can be sold, hacked, or subpoenaed by law enforcement.
- The risk from any single device is usually small, but the risk grows with each device you add to your home.
How attackers use IoT devices to enter your home network
Your home network is like a locked building with multiple doors. Your computer and phone are the main entrances, and you probably protect them with passwords and updates. An IoT device is often a side door with a broken lock.
When you connect a smart speaker, security camera, or fitness tracker to your Wi-Fi, it becomes part of your network. If that device has a weak or default password, an attacker can log into it from outside your home — either by guessing the password or by using a tool that tries thousands of common passwords automatically. Once inside the device, the attacker can see your Wi-Fi password, which is stored in the device's memory. With your Wi-Fi password, they can connect to your network and reach your computer, phone, or any other device connected to it.
This is not theoretical. In 2016, a botnet called Mirai infected hundreds of thousands of IoT devices — mostly security cameras and routers — by trying default passwords. The infected devices were then used to launch attacks that knocked major websites offline. The owners of those devices had no idea their cameras were being used as weapons.
Data collection and what happens to the information IoT devices gather
A smart speaker listens for a wake word, but it is also recording audio constantly and sending it to the company's servers to determine whether the wake word was spoken. A fitness tracker records your location, heart rate, and sleep patterns. A smart doorbell records video of everyone who approaches your door and stores it on the company's servers. A connected thermostat learns when you are home and when you are away.
This data is valuable. It tells companies when you are home, what you buy, how much you exercise, whether you have guests, and what your daily routine looks like. Some companies sell this data to advertisers, data brokers, or insurance companies. Others keep it to build a profile of you for targeted advertising. In some cases, law enforcement can subpoena this data without a warrant, depending on the company's policies and your state's laws.
You usually cannot see what data a device is sending or stop it from sending data without disconnecting the device entirely. The privacy policy that comes with the device is often dozens of pages long and written in legal language that most people do not read. Even if you do read it, the company can change the policy at any time, and you have no way to opt out except to stop using the device.
Devices that cannot be updated are devices that cannot be fixed
When a security researcher discovers a vulnerability in software — a flaw that an attacker can exploit — the company that makes the software releases an update to patch the flaw. Your computer and phone receive these updates regularly, sometimes multiple times per month. An IoT device often does not.
Many IoT devices do not have the ability to receive updates at all. The manufacturer did not build the infrastructure to push updates to devices after they left the factory. Other devices can receive updates, but the manufacturer stops sending them after a few years because supporting old devices is expensive. A security camera you bought five years ago may still be running the same software it shipped with, even though researchers have found dozens of vulnerabilities in that software since then.
This means that once a vulnerability is public, your device is vulnerable forever. An attacker does not need to trick you into clicking a link or opening an email. They can straightforward scan the internet for devices running old software and break in automatically.
The difference between a device that is hacked and a device that is straightforward insecure
When people talk about a "hacked" device, they usually mean an attacker has taken control of it. But most IoT devices are not actively hacked — they are straightforward insecure by design. The manufacturer chose to use a default password, chose not to encrypt the data the device sends, or chose not to build update capability into the device. These are not accidents. They are choices made to save money and get the product to market faster.
An insecure device is more dangerous than a hacked one in some ways, because the vulnerability is permanent. If your computer is hacked, you can wipe it and reinstall the software. If your IoT device is insecure, you cannot fix it. You can only replace it or stop using it.
What you can actually control when you own an IoT device
You cannot control whether the manufacturer uses weak security practices. You cannot control what data the device collects or where it sends that data. But you can control a few things that reduce your risk.
Change the default password on any IoT device that allows you to do so. The password should be unique — not the same password you use for other devices or accounts. Check the device's settings to see whether it offers the option to receive updates, and turn that option on if it is available. Put the device on a separate Wi-Fi network if your router supports it — many modern routers allow you to create a "guest network" that is isolated from your main network. If the IoT device is compromised, an attacker on the guest network cannot reach your computer or phone.
Read the privacy policy before you buy the device, or at least before you connect it to your network. Look for statements about what data is collected, how long it is kept, and whether it is sold to third parties. If the policy says the company can sell your data or change the policy at any time, you now know what you are agreeing to.
Consider whether you actually need the device. A smart speaker is convenient, but a regular speaker and a phone work fine. A connected thermostat learns your schedule, but a programmable thermostat does the same thing without sending data to a company's servers. The safest IoT device is the one you do not own.
How to decide which IoT devices are worth the risk
Not all IoT devices pose the same level of risk. A smart light bulb that only turns on and off is lower risk than a device with a camera or microphone. A device made by a large company with a security team is lower risk than one made by a startup. A device that receives regular updates is lower risk than one that does not.
Before you buy an IoT device, ask: Does this device have a microphone or camera? Does it know my location or my schedule? Does the manufacturer have a history of releasing security updates? Can I change the default password? Is there a way to see what data the device is sending?
If the answer to most of these questions is no, the device is probably not worth the risk. If the answers are yes, the device is still not risk-free, but you have more control over it. The goal is not to eliminate risk entirely — that is impossible — but to make an informed choice about which risks you are willing to accept.
Frequently Asked Questions
Can someone spy on me through my smart TV or security camera?
Yes, if the device has a weak or default password and the attacker can reach it from the internet. A security camera with a default password can be accessed by anyone who knows the camera's model number and tries common passwords. Smart TVs are less commonly targeted, but they can be compromised the same way. Changing the password and putting the device on a separate network reduces this risk significantly.
Is it safe to use a smart speaker if I am worried about privacy?
A smart speaker is always listening for the wake word and sending audio to the company's servers. If you are uncomfortable with that, a smart speaker is not the right device for you. If you decide to use one, change the password, turn off any features you do not use, and check the privacy settings regularly. Some speakers allow you to mute the microphone with a physical button, which is better than a software setting.
What should I do if I think my IoT device has been hacked?
Disconnect it from your network when ready. Change the password on your Wi-Fi router and on any other devices that connect to your network. If the device has a reset button, press it to restore the device to its factory settings, then change the default password before reconnecting it. If you cannot change the password or the device does not allow updates, consider replacing it with a more find model.
Do I need to worry about every IoT device in my home?
The risk depends on what the device does and how it connects to your network. A smart light bulb is lower risk than a device with a camera or microphone. A device on a separate network is lower risk than one on your main network. Start by securing the devices that collect the most sensitive information — cameras, microphones, and location trackers — and work from there.
What is the difference between a device that is encrypted and one that is not?
Encryption scrambles the data the device sends so that only the intended recipient can read it. A device that encrypts the data it sends is harder for an attacker to spy on. However, encryption does not prevent the manufacturer from collecting the data or selling it to third parties. It only prevents someone on your network or your internet service provider from seeing what data is being sent.