Abstract
Unsupported smart home devices can pose serious safety and security issues for consumers. However, unpatched and vulnerable devices may remain connected because consumers may not be alerted that their devices are no longer supported or do not understand the implications of using unsupported devices. To investigate the consumer perspective on loss of manufacturer support, we conducted a survey of 412 smart home users. We discovered differences based on device category and provide insights into how user perspectives may relate to perceptions of smart home update importance, security, and privacy. Based on the results, we offer suggestions to guide the efforts of the smart home community to protect consumers from potentially harmful consequences of unsupported devices.
S. M. Furman—Designated as co-first authors.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
References
ATT. End of life, unsupported IoT devices (2020). https://securityinnovation.att.com/stories/end-of-life-unsupported-devices/
Behavioral Economics Team of the Australian Government. Stay smart: Helping consumers choose cyber secure smart devices (2021). https://behaviouraleconomics.pmc.gov.au/sites/default/files/projects/beta-report-cyber-security-labels.pdf
Carnegie Mellow University. IoT security and privacy label (2020). https://iotsecurityprivacy.org/
Department for Digital, Culture, Media & Sport, United Kingdom. Consultation on the government’s regulatory proposals regarding consumer Internet of Things (IoT) security (2020). https://www.gov.uk/government/consultations/consultation-on-regulatory-proposals-on-consumer-iot-security/consultation-on-the-governments-regulatory-proposals-regarding-consumer-internet-of-things-iot-security#the-top-three-guidelines
Department for Digital, Culture, Media and Sport. Code of practice for consumer IoT security (2018). https://www.gov.uk/government/publications/code-of-practice-for-consumer-iot-security
Department of Home Affairs, Commonwealth of Australia. Code of practice: Securing the Internet of Things for consumers (2020). https://www.homeaffairs.gov.au/reports-and-pubs/files/code-of-practice.pdf
Emami-Naeini, P., Dixon, H., Agarwal, Y., Cranor, L.F.: Exploring how privacy and security factor into IoT device purchase behavior. In: CHI Conference on Human Factors in Computing Systems. ACM (2019)
ETSI. ETSI EN 303 645 V2.1.1 CYBER; cyber security for consumer Internet of Things: Baseline requirements (2020). https://www.etsi.org/deliver/etsi_en/303600_303699/303645/02.01.01_60/en_303645v020101p.pdf
Fagan, M., Khan, M.M.H., Buck, R.: A study of users’ experiences and beliefs about software update messages. Comput. Hum. Behav. 51, 504–519 (2015)
Fagan, M., Megas, K., Watrobski, P., Marron, J., Cuthill, B.: NISTIR 8425 profile of the IoT core baseline for consumer IoT products. Technical report, National Institute of Standards and Technology (2022)
Fagan, M., Megas, K.N., Scarfone, K., Smith, M.: NISTIR 8259 foundational cybersecurity activities for IoT device manufacturers (2020). https://nvlpubs.nist.gov/nistpubs/ir/2020/NIST.IR.8259.pdf
Federal Trade Commission. Internet of things privacy and security in a connected world (2015). https://www.ftc.gov/system/files/documents/reports/federal-trade-commission-staff-report-november-2013-workshop-entitled-internet-things-privacy/150127iotrpt.pdf
Federal Trade Commission. Careful connections: Keeping the internet of things secure (2020). https://www.ftc.gov/tips-advice/business-center/guidance/careful-connections-keeping-internet-things-secure
Furman, S., Haney, J.: Human factors in smart homes technologies workshop (2019). https://csrc.nist.gov/CSRC/media/Projects/usable-cybersecurity/images-media/Human%20Factors%20Smart%20Home%20Workshop%20Summary%20Report.pdf
Germain, J.M.: Unsupported IoT devices are cyber-trouble waiting to happen. Ecommerce Times (2021)
Guiltinan, J.: Creative destruction and destructive creations: environmental ethics and planned obsolescence. J. Bus. Ethics 89(1), 19–28 (2009)
Haney, J.M., Furman, S.M.: Work in progress: towards usable updates for smart home devices. In: Proceedings of the 10th International Workshop on Socio-Technical Aspects in Security, pp. 107–117 (2020)
Harris Interactive. Consumer internet of things security labelling survey research findings (2019). https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/798543/Harris_Interactive_Consumer_IoT_Security_-Labelling_Survey_Report.pdf
Ion, I., Reeder, R., Consolvo, S.: “...no one can hack my mind”: comparing expert and non-expert security practices. In: Proceedings of the 11th Symposium on Usable Privacy and Security, pp. 327–346 (2015)
Kuppelwieser, V.G., Klaus, P., Manthiou, A., Boujena, O.: Consumer responses to planned obsolescence. J. Retail. Consum. Serv. 47, 157–165 (2019)
Morgner, P., Mai, C., Koschate-Fischer, N., Freiling, F., Benenson, Z.: Security update labels: establishing economic incentives for security patching of IoT consumer products. In: Proceedings of the 2020 IEEE Symposium on Security and Privacy (SP), pp. 29–446. IEEE (2020)
National Institute of Standards and Technology. Recommended criteria for cybersecurity labeling for consumer internet of things (IoT) products (2022). https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.02042022-2.pdf
NPD Group. Half of U.S. consumers own at least one smart home device (2021). https://www.npd.com/news/press-releases/2021/half-of-u-s-consumers-own-at-least-one-smart-home-device-reports-npd/
Nurse, J.R., Creese, S., Goldsmith, M., Lamberts, K.: Trustworthy and effective communication of cybersecurity risks: a review. In: Workshop on Socio-Technical Aspects in Security and Trust (STAST), pp. 60–68 (2011)
Postscape. Closed IoT companies and devices: A directory of failed IoT startups (2019). https://www.postscapes.com/closed-iot-companies/
Powers, W.T.: Behavior: The Control of Perception, 2nd edn. Benchmark Publications Inc, California (2005)
Research on Investment. The IoT revolution: 5 industries that will change forever (2021). https://researchoninvestment.com/iot-revolution-5-industries-that-will-change-forever/
Bruce Schneier. The internet of things is wildly insecure - and often unpatchable. Wired Magazine (2014)
Statista. Smart home device household penetration in the United States in 2019 and 2021 (2021). https://www.statista.com/statistics/1247351/smart-home-device-us-household-penetration/
Tabassum, M., Kosinski, T., Lipford, H.R.: "I don’t own the data": end user perceptions of smart home device data practices and risks. In: Proceedings of the 15th Symposium on Usable Privacy and Security (2019)
Vaniea, K.E., Rader, E., Wash, R.: Betrayed by updates: How negative experiences affect future security. In: Proceedings of the 2014 SIGCHI Conference on Human Factors in Computing Systems (CHI 14), pp. 2671–2674. ACM, Toronto, Canada (2014)
Westermann, T., Moller, S., Wechsung, I.: Assessing the relationship between technical affinity, stress and notifications on smartphones. In: Proceedings of the 17th International Conference on Human-Computer Interaction with Mobile Devices and Services, pp. 652–659 (2015)
World Economic Forum. IoT for sustainable development project (2021). https://widgets.weforum.org/iot4d/index.html
Zeng, E., Mare, S., Roesner, F.: End user security and privacy concerns with smart homes. In: Proceedings of the 13th Symposium on Usable Privacy and Security (2017)
Zheng, S., Apthorpe, N., Chetty, M., Feamster, N.: User perceptions of smart home IoT privacy. ACM Hum.-Comput. Int. 2(CSCW), 1–20 (2018)
Zou, Y., Danino, S., Sun, K., Schaub, F.: YouMight’Be affected: an empirical analysis of readability and usability issues in data breach notifications. In: Proceedings of the 2019 CHI Conference on Human Factors in Computing Systems, pp. 1–14 (2019)
Acknowledgements
We would like to thank our colleagues Yee-Yin Choong and Barbara Cuthill for their comments that helped improve the paper.
Author information
Authors and Affiliations
Corresponding author
Editor information
Editors and Affiliations
Appendix A: Survey Questions
Appendix A: Survey Questions
The following are the survey questions related to the contents of this paper. These are a subset of a broader survey addressing smart home updates.
Throughout the survey, the following terms are used:
-
Smart home device is a network-connected device (connected via Wi-Fi, Bluetooth, or similar protocols) that is used to remotely and/or more effectively and efficiently control functions or physical aspects of the home.
-
Smart home device app is an application on your smartphone, computer, laptop, or tablet that is used to remotely control or access your smart home device.
-
Smart home updates are incremental changes or improvements that manufacturers make to the software or firmware of smart home devices and device apps. Updates may be automatic in which updates are installed without you having to take any action or manual in which you may have to click a button or take some other action to install the update.
-
The security of smart home devices refers to the prevention of damage to, unauthorized use of, and exploitation of smart home devices and the information they contain, in order to strengthen the confidentiality, integrity, and availability of these devices. In this survey, “security” is equivalent to “cybersecurity.” Physical security related to the home or its occupants is different and will be referred to as “home security.”
-
The privacy of smart home devices refers to the right of a party to maintain control over and be assured confidentiality of personal information that is collected, transmitted, used, and stored during the use of smart home devices.
SMART HOME DEVICES
1) Which of the following smart home devices do you own? (Select all that apply.)
- \(\square \):
-
Virtual voice assistants and smart speakers (e.g., Amazon Echo/Alexa, Google Nest Home Hub, Apple HomePod)
- \(\square \):
-
Thermostats (e.g., Nest, Ecobee)
- \(\square \):
-
Home security devices (e.g., video doorbells, cameras, door locks, garage door openers)
- \(\square \):
-
Home environment sensors (e.g., smoke and leak detectors)
- \(\square \):
-
Lighting (e.g., lightbulbs, lighting systems)
- \(\square \):
-
Appliances (e.g., refrigerators, washing machines/dryers, ovens, coffee makers/espresso machines)
- \(\square \):
-
Entertainment (e.g., TVs, streaming devices such as AppleTV or Roku)
- \(\square \):
-
Plugs or outlets (e.g., Wemo Mini, Wyze Plug)
- \(\square \):
-
Domestic robots that do household chores (e.g., robot vacuums such as iRobot Roomba, smart lawn mowers)
- \(\square \):
-
Smart home hubs (e.g., Samsung SmartThings, Hubitat Elevation)*
- \(\square \):
-
Other (e.g., smart windows solutions, smart watering system, smart pet feeder) (please specify):
2) Please indicate the number and types (including the brand) of smart home devices you own in each of the following categories.
[answer for each device category owned]
UPDATES
3) Rate your agreement with the following statement for each category of smart home device: It is important for smart home devices to be updated.
Strongly Disagree - Disagree - Neither Agree nor Disagree - Agree - Strongly Agree
[answer for each device category owned]
MANUFACTURER SUPPORT
4) Please rate your agreement with the following statement: I am concerned that the manufacturer will eventually stop supporting my smart home devices.
Strongly Disagree - Disagree - Neither Agree nor Disagree - Agree - Strongly Agree
[answer for each device category owned]
5) Which of the following would concern you if the manufacturer stopped supporting your smart home devices? (Select all that apply.)
- \(\square \):
-
My devices eventually stop working
- \(\square \):
-
Updates containing security bug fixes no longer being released
- \(\square \):
-
Updates containing non-security bug fixes no longer being released
- \(\square \):
-
New features no longer being added
- \(\square \):
-
Parts or accessories no longer being available
- \(\square \):
-
Losing online/call-in customer support from the manufacturer
- \(\square \):
-
I would not be concerned
[answer for each device category owned]
6) What would you do if your smart home devices were no longer supported by the manufacturer?
- \(\circ \):
-
Nothing - leave it as is
- \(\circ \):
-
Replace it with a new or different device as soon as possible
- \(\circ \):
-
Replace it with a new or different device eventually but not necessarily right away
- \(\circ \):
-
Throw the device out without replacing it
[answer for each device category owned]
7) What would be your preferred method of notification from the manufacturer to inform you they were no longer supporting your smart home devices?
- \(\circ \):
-
Email
- \(\circ \):
-
Message/notification sent to the device app
- \(\circ \):
-
Text message on my phone
- \(\circ \):
-
Letter/postcard in the mail
- \(\circ \):
-
I prefer not to be notified
- \(\circ \):
-
Other (please specify):
SECURITY AND PRIVACY
8) Please rate your level of concern with the security of your smart home devices for each category:
Not at all concerned - Slightly concerned - Somewhat concerned - Moderately concerned - Extremely concerned
[answer for each device category owned]
9) Please rate your level of concern with the privacy of your smart home devices for each category:
Not at all concerned - Slightly concerned - Somewhat concerned - Moderately concerned - Extremely concerned
[answer for each device category owned]
DEMOGRAPHICS
10) In which state or US territory do you live?
11) In which type of area is your home?
- \(\circ \):
-
Rural
- \(\circ \):
-
Suburban
- \(\circ \):
-
Urban
12) How long have you been using smart home devices?
- \(\circ \):
-
Less than 1 year
- \(\circ \):
-
3 - 5 years
- \(\circ \):
-
6 or more years
13) What is your age range?
- \(\circ \):
-
18 - 24
- \(\circ \):
-
25 - 34
- \(\circ \):
-
35 - 44
- \(\circ \):
-
45 - 54
- \(\circ \):
-
55 - 64
- \(\circ \):
-
65+
14) What is your gender?
- \(\circ \):
-
Male
- \(\circ \):
-
Female
- \(\circ \):
-
Prefer to self-describe
- \(\circ \):
-
Prefer not to answer
15) What is your race?
- \(\square \):
-
American Indian or Alaska Native
- \(\square \):
-
Asian
- \(\square \):
-
Black or African American
- \(\square \):
-
Native Hawaiian or Other Pacific Islander
- \(\square \):
-
White
- \(\square \):
-
Other
- \(\square \):
-
Prefer not to answer
16) What is your ethnicity?
- \(\circ \):
-
Hispanic, Latino/a, or Spanish Origin
- \(\circ \):
-
Not Hispanic, Latino/a, or Spanish Origin
- \(\circ \):
-
Prefer not to answer
17) What is your highest level of education?
- \(\circ \):
-
Less than high school degree
- \(\circ \):
-
High school degree or equivalent
- \(\circ \):
-
Some college
- \(\circ \):
-
Associate degree
- \(\circ \):
-
Bachelor’s degree
- \(\circ \):
-
Master’s degree
- \(\circ \):
-
Doctoral or Juris Doctoral degree
- \(\circ \):
-
Other:
- \(\circ \):
-
Prefer not to answer
18) Have you ever worked in a field/job related to information technology (IT) (for example, a system or network administrator, IT help desk, cybersecurity professional)?
- \(\circ \):
-
Yes
- \(\circ \):
-
No
Rights and permissions
Copyright information
© 2023 This is a U.S. government work and not under copyright protection in the U.S.; foreign copyright protection may apply
About this paper
Cite this paper
Haney, J.M., Furman, S.M. (2023). Smart Home Device Loss of Support: Consumer Perspectives and Preferences. In: Moallem, A. (eds) HCI for Cybersecurity, Privacy and Trust. HCII 2023. Lecture Notes in Computer Science, vol 14045. Springer, Cham. https://doi.org/10.1007/978-3-031-35822-7_32
Download citation
DOI: https://doi.org/10.1007/978-3-031-35822-7_32
Published:
Publisher Name: Springer, Cham
Print ISBN: 978-3-031-35821-0
Online ISBN: 978-3-031-35822-7
eBook Packages: Computer ScienceComputer Science (R0)