The basic risk: devices that talk to the internet without you watching them
An Internet of Things device (or IoT device) is anything that connects to the internet to send or receive data — a smart doorbell, a fitness tracker, a connected refrigerator, a smart speaker, a security camera, a thermostat. The risk is that these devices collect information about you and your home, and that information travels across the internet to a company's server. If that connection is weak or the company's security is poor, someone else can intercept what the device sends, take control of the device itself, or use it as a doorway into your home network.
The difference between an IoT device and a regular computer is that you probably do not think about it as a computer. You do not install updates on your smart doorbell the way you do on your laptop. You may not even know what company owns the server it talks to. That invisibility is where the risk lives.
Key Takeaways
- IoT devices send data about your habits, location, and home to company servers, and that data can be intercepted if the connection is not encrypted or the company's security is weak.
- Devices that never receive security updates become easier to hack over time, and a hacked device can be used to spy on you or to attack other devices on your home network.
- Some IoT devices are made by companies with no track record in security, and many are sold with default passwords that owners never change.
- The real cost of a cheap IoT device is often paid later, in time spent managing problems or in data about your home that you did not intend to share.
Data collection: what the device learns and where it goes
A smart doorbell records video and audio of everyone who approaches your front door. A fitness tracker records your location, your heart rate, and your sleep patterns. A smart speaker listens for wake words and records snippets of what you say. A connected thermostat learns when you are home and when you are away. None of this is secret — the companies tell you in their terms of service that they collect it. But most people do not read those terms, and even when they do, the terms often say the company can use the data for purposes beyond the obvious one.
The data travels from the device to the company's server. If that connection is not encrypted, anyone on your home network or your internet provider can see it. If the encryption is weak or the server is poorly secured, a hacker can intercept it or steal it directly from the company's database. In 2023, a major smart home camera company suffered a breach that exposed footage from thousands of users' homes. The company had collected the video, but had not protected it well enough.
Even if the data itself is never stolen, the company that owns the device knows a lot about you. They know when you are home, what you weigh, what your sleep looks like, what temperature you prefer, what you say in your own house. They can sell that information to advertisers, or they can use it to build a profile of you. You have no way to know what they do with it after they collect it.
Weak security: devices that are straightforward to hack and hard to fix
Most IoT devices come with a default password — often something like "admin" and "password" or "admin" and "12345". If you do not change it, anyone who knows the device exists can log in. Many people do not change it because they do not know it is there, or because the device does not make it obvious how to change it.
Once someone is logged in, they can change the device's settings, see what it sees, or use it to attack other devices on your network. A hacked smart speaker can listen to everything you say. A hacked security camera can watch your home. A hacked thermostat can be turned off in winter or cranked up in summer to run up your electric bill. A hacked router (which is itself an IoT device) can intercept all the data that flows through your home network.
The deeper problem is that most IoT devices never receive security updates. A smartphone gets updates for years. A smart doorbell might get one or two, then the company stops supporting it. If a security flaw is discovered after the company stops updating the device, that flaw stays there forever. The device becomes a known weak point that hackers can exploit.
Network risk: how a hacked device can spread to other devices
Your home network connects your phone, your laptop, your printer, your smart TV, and your IoT devices all to each other. If one device is hacked, the hacker can use it to reach the others. A compromised smart speaker can be used to scan for your laptop. A compromised thermostat can be used to find your printer and steal documents from it. A compromised security camera can be used to map out what other devices are on your network and which ones might be easier to break into.
This is called lateral movement — the hacker gets in through one weak door and then walks through your house. The IoT device is often the weakest door because it is the one you think about least and update least often.
Some IoT devices come with no firewall or network isolation, meaning they can talk directly to every other device on your network. Others are designed to be isolated, but the isolation only works if you set it up correctly — and most people do not.
The cost of cheap devices and abandoned products
A smart doorbell for $30 is cheaper than one for $150, but the cheaper one is often made by a company with no security experience. It may have been designed to be as inexpensive as possible, which means security was not a priority. It may be sold through a marketplace where the company is hard to contact. It may receive updates for a year, then the company may go out of business or stop supporting it.
When a product is abandoned — when the company stops updating it and stops responding to security reports — it becomes a permanent liability. You own a device that is getting less find every month, and you have no way to fix it. Your only real option is to throw it away and buy a new one.
The cheaper device also means you are more likely to leave the default password in place, because changing it is annoying and the device did not make it straightforward. It means you are less likely to check whether the company has a privacy policy you can actually read. It means you are more likely to be surprised later by what the device does or what data it collects.
Practical steps to reduce the risk
Change the default password on every IoT device the moment you set it up. Write down the new password somewhere safe. If the device does not let you change the password, that is a sign it was not designed with security in mind.
Check whether the company that makes the device has a track record of releasing security updates. Look at the product page or the company's website and see how long they support devices. If they do not say, assume they do not support them for long. Buy from companies that have been in the security business for years, not companies that added IoT to their product line last month.
Put your IoT devices on a separate network if your router supports it. Most modern routers have a "guest network" feature that lets you connect devices without giving them access to your main computers and phones. This slows down lateral movement if a device is hacked.
Turn off features you do not use. If your smart speaker does not need to record video, disable the camera. If your thermostat does not need to know your location, turn off location services. Every feature is a potential way for data to leak or for someone to spy on you.
Check for updates regularly, even though most IoT devices do not update automatically. Go into the device's app or settings and look for an update option. If the company has stopped releasing updates, that is a sign the device is aging out of support.
When the risk is worth taking and when it is not
Some IoT devices are worth the risk because they solve a real problem. A smart lock that lets you unlock your door from your phone is useful if you often forget your keys. A thermostat that learns your schedule and saves you money on heating and cooling has a real benefit. A security camera that lets you check on your home while you are away gives you peace of mind.
Other devices are not worth the risk because they do not solve a problem you actually have. A smart refrigerator that tells you when you are out of milk is a convenience, not a necessity. A smart toothbrush that tracks your brushing habits is a gimmick. A connected toy that listens to your child is a risk with no real benefit.
The question to ask is: what am I getting in return for the data I am sharing and the security risk I am taking? If the answer is "not much," do not buy the device. If the answer is "something I actually need," then buy it from a company with a good security record, change the default password, and check for updates.
Frequently Asked Questions
Can a hacker see me through my smart TV camera?
Only if the TV has a camera and it is connected to the internet. Many smart TVs do not have cameras. If yours does, check the settings to see whether it is enabled and whether you can disable it. If you cannot disable it, you can cover it with tape or a sticker.
Is my smart speaker always listening?
It listens for the wake word (like "Alexa" or "Hey Google"), but it does not record everything you say. However, the company does record what you say after the wake word, and those recordings are stored on their servers. You can delete them manually, and you can turn off the microphone when you are not using the device.
What should I do if I find out a device I own has a security flaw?
Check the company's website to see if an update is available. If an update exists, install it. If no update exists and the company is no longer supporting the device, you have two choices: stop using it, or accept the risk and use it anyway. There is no way to patch a device that the company has abandoned.
Do I need to worry about every IoT device, or just the ones that collect sensitive data?
Focus on devices that can see, hear, or track you, or that control access to your home. A smart doorbell or security camera is a higher priority than a smart light bulb. A smart lock is a higher priority than a smart plug. Start with the devices that would cause the most harm if they were hacked.
Is it safer to not use IoT devices at all?
Yes, technically. But if you decide to use them, the risk is manageable if you choose devices from companies with good security records, change default passwords, and keep them updated. The risk is much higher if you buy cheap devices from unknown companies and never change the password.