Connected Home
Smart devices. Always on. Always collecting.
Lesson 5 of 6 · Estimated read: 14 minutes · Level: everyone
The last lesson was about infrastructure you don’t control. This one is the opposite, and that’s good news.
Your home network is yours. You own the router, you chose the devices, you can unplug any of them. The connected home is the one place in this entire course where you hold the actual controls, which is why it’s worth understanding where the real leverage sits.
Here’s the thesis, up front: the highest-value fixes in your home are network-level, not device-level. Your smart TV has a buried settings menu. Your washing machine has none. Your neighbor’s guest who joins your Wi-Fi has none. One change at the router protects all of them at once.
In this lesson
- Smart TVs and streaming devices
- Voice assistants and smart speakers
- Wi-Fi routers and network tracking
- Smart appliances and energy use
- Security systems and doorbells
- Baby monitors and cameras
- Data sharing with manufacturers
- Tips to secure your connected home
1. Smart TVs and streaming devices
The basics
Your television is an advertising platform that happens to display shows. Modern TVs are sold at thin or negative margins because the money is in what happens after the sale: ad placement on the home screen, and data about what you watch.
The mechanism is automatic content recognition (ACR). The TV samples what’s on the screen, capturing frames or audio fingerprints many times per minute, and matches them against a reference database to identify the content.
Go deeper
- The TV platform business is genuinely more profitable than the hardware business for several major manufacturers. That’s not a cynical read; it’s in their investor materials.
- A federal enforcement action against one major TV maker established years ago that tracking viewing without clear consent was unlawful. The practice didn’t end. It became disclosed, in settings most people never open.
- Streaming sticks and boxes run the same model, with their own ad identifiers.
What most people don’t know
ACR identifies everything on the panel, not just what you stream.
This is the part that surprises even technical people. ACR reads the screen. So it captures your cable and antenna viewing, your game console, the DVD you put in, and the laptop you connected over HDMI. Anything displayed on that television can be fingerprinted and identified, regardless of which input it came from and whether the TV’s own apps are involved.
The second surprise is the naming. The setting that controls this is almost never called tracking. Depending on the brand, you’re looking for Viewing Information Services, Live Plus, Viewing Data, Smart Interactivity, or something similarly agreeable. Turning off “interest-based advertising” is a different, lesser setting. It limits ad targeting while leaving the content recognition running.
And the deepest cut: research examining smart TV network traffic has found devices contacting content and advertising services regardless of configuration. Which leads to the most reliable fix available:
Don’t connect the television to your Wi-Fi at all. Use a separate streaming device for apps. The TV becomes a screen, which is what you bought. If you’ve already connected it, you can remove the network credentials in settings.
Do this today
- Find your TV’s ACR setting under privacy or terms, looking for the agreeable-sounding names above, and turn it off. Also disable ad personalization separately.
- Better: disconnect the TV from Wi-Fi and use a streaming stick.
- Reset the ad identifier on your streaming device, and turn off “limit ad tracking” equivalents.
2. Voice assistants and smart speakers
The basics
A smart speaker listens locally for its wake word. Only after detecting it does audio stream to the company’s servers for processing. That’s the honest description, and it means the device is not transcribing your dinner conversation.
The real issue is false wakes. The detector misfires on similar sounds, and when it does, whatever you were saying gets recorded and sent.
Go deeper
- All the major assistant makers were found to be using human contractors to review voice clips for quality improvement, disclosed only vaguely. That prompted policy changes and, in some cases, opt-in requirements.
- Enforcement has followed. One company paid a substantial penalty over retaining children’s voice recordings indefinitely in violation of federal children’s privacy law. Another settled litigation over accidental Siri activations for a reported nine-figure sum.
- Voice can function as a biometric. Voice profiles that recognize individual household members are convenient and are also voiceprints.
What most people don’t know
Deleting your voice recordings doesn’t necessarily delete the transcripts, and the transcript is the durable artifact.
Audio is expensive to store and hard to search. Text is neither. So the pipeline transcribes, and the transcript, plus everything derived from it like inferred interests, is what persists and gets used. In several platforms, deleting voice recordings and deleting the associated transcripts and derived data have been separate operations, with only the first one prominently offered.
When you audit your voice history, look specifically for transcript deletion and for the broader activity log, not just the audio clips.
Also worth knowing, and a real change: the option to process voice locally rather than in the cloud has been narrowing, not expanding. At least one major platform removed a setting that had kept some voice processing on-device. If local processing matters to you, verify what your specific device currently supports rather than relying on what was true when you bought it.
Do this today
- Open your assistant’s voice history and review it, which is usually a revealing few minutes, then delete it.
- Set auto-delete to the shortest available window (often three months). This is the single most durable setting because it keeps working without you.
- Turn off human review of recordings.
- Mute the microphone physically when you want it off. The button is a hardware disconnect on most devices; the app toggle isn’t.
- If children use it, set up a child profile and check what’s retained.
3. Wi-Fi routers and network tracking
The basics
Your router sees every device on your network and every domain each one contacts. So does your internet provider, from the other side.
This is why the router is the leverage point. It’s the one place where a single change reaches devices that have no privacy settings of their own.
Go deeper
- U.S. internet providers are permitted to monetize subscriber browsing data. A federal study of major providers documented extensive collection and sharing practices, and the rules that would have restricted this were repealed by Congress in 2017.
- An ISP-supplied router is the provider’s equipment running the provider’s firmware. Buying your own generally means better security updates and no vendor telemetry.
- Routers reach end-of-support and stop receiving patches, typically years before they stop working. An unpatched router is the most consequential unpatched device in a home.
What most people don’t know
DNS is the highest-leverage privacy control in your entire house.
Every time any device wants to reach a server, it asks a DNS resolver to translate the name into an address. That means the resolver sees, and can block, essentially all outbound activity, including from devices with no settings whatsoever. Your washing machine cannot be configured. Your DNS resolver can.
Two upgrades, both configured once at the router:
- Encrypted DNS (DNS over HTTPS or TLS) stops your ISP from reading your queries.
- A filtering resolver blocks known tracking and telemetry domains for every device on the network. Options range from free public resolvers to configurable services like NextDNS or AdGuard Home, to a self-hosted Pi-hole.
One caveat that matters, and that most guides omit: some IoT devices ignore your router’s DNS setting by hardcoding a public resolver directly into their firmware, specifically so they can’t be blocked this way. Better routers let you force all DNS traffic through your resolver with a firewall rule, which closes that bypass.
Second high-leverage move: put IoT devices on a separate network. Most routers support a guest network or a second SSID. A compromised camera on an isolated segment can’t reach your laptop, your NAS, or your work files. This is the standard practice in enterprise security and it takes about ten minutes at home.
Do this today
- Change the router’s admin password from the default.
- Check whether your router still receives firmware updates. If not, replace it. This is worth actual money.
- Set encrypted, filtering DNS at the router.
- Move IoT devices to a guest or separate SSID.
- Turn off WPS and UPnP, and use WPA3 if available.
4. Smart appliances and energy use
The basics
Refrigerators, washers, dryers, ovens, and coffee makers now ship with apps and accounts. It’s worth asking directly what your dryer gains from an internet connection, because the answer is often “nothing you’d notice, and a data stream the manufacturer would.”
Go deeper
- Appliance manufacturers have been building advertising and data businesses, including ads on refrigerator and TV panels. The appliance becomes a screen with an audience.
- Firmware updates can add telemetry after purchase. The device you bought and the device you own a year later may collect different things.
- Smart features are frequently cloud-dependent, which means they stop when the company shuts down the service. This has happened repeatedly across smart home platforms: hubs, switches, and whole ecosystems bricked or degraded when a business decision was made elsewhere.
What most people don’t know
Cloud-dependent devices are a subscription you didn’t knowingly sign, and local control is the fix.
The appliance works unconnected. The app doesn’t. So the question for each device is whether the app-enabled features justify a permanent dependency on a company’s willingness to keep servers running and a policy you can’t renegotiate.
The mature answer, and where the industry is genuinely improving: local control standards. Devices supporting Matter and Thread, or Apple Home, or an open platform like Home Assistant, can operate on your network without routing through a manufacturer’s cloud. You get the automation and lose the dependency. When buying, “works locally” is a more meaningful spec than any privacy policy.
One specific setting worth checking: some device ecosystems enroll your hardware into a shared low-bandwidth neighborhood mesh network by default, using a sliver of your bandwidth to extend other people’s devices’ connectivity. It’s opt-out, it’s on unless you turned it off, and most owners have no idea.
Do this today
- For each smart appliance, ask whether you use the app. If not, don’t connect it.
- Check for and disable shared-mesh participation in your device ecosystem’s settings.
- When buying, prefer devices that work without a cloud account, and look for Matter/Thread support.
- Before buying, search the product name plus “shutdown” or “discontinued.” Cloud-dependency risk is researchable.
5. Security systems and doorbells
The basics
The irony of home security cameras is that they create a video record of your household, stored on someone else’s servers, accessible to that company’s employees, reachable by legal process, and vulnerable to whoever gets your password.
That’s a real tradeoff, not an argument against cameras. It just means the configuration matters more than for almost any other device.
Go deeper
- Federal enforcement has established that a major doorbell company gave far too many employees and contractors access to customer video, and failed to prevent account takeovers.
- Another company was found to be uploading footage to the cloud despite marketing local-only storage. Verify claims; don’t assume.
- Police access has changed. Bulk in-app footage requests were discontinued by at least one major provider, though law enforcement can still request directly or use legal process.
What most people don’t know
Your doorbell’s audio recording may violate your state’s wiretap law, and this is the risk almost nobody has considered.
Video of a public sidewalk is generally lawful. Audio is different. Roughly a dozen U.S. states require all parties to consent to recording a conversation, and a doorbell camera capturing the sidewalk records conversations of people who have no idea they’re being recorded and never consented.
This has produced actual legal consequences, including a case abroad where a homeowner’s doorbell audio was found to violate data protection and surveillance law after a neighbor dispute. In two-party-consent states, the exposure is genuine, and it runs against the camera’s owner.
Two practical implications: you can turn audio recording off while keeping video, and in many setups you can define privacy zones that black out portions of the frame covering a neighbor’s property or a shared walkway. Both take one minute and both reduce your legal and ethical exposure.
The related item: end-to-end encryption is often available and off by default. Enabling it means the company can’t view your footage, and it also disables convenient features like viewing on a smart display or sharing clips easily. That’s the real tradeoff, and it’s yours to make knowingly rather than by default.
Do this today
- Turn off audio recording, or check your state’s consent law first.
- Set privacy zones to exclude neighbors’ property and shared spaces.
- Enable end-to-end encryption if your system offers it, understanding what it disables.
- Turn on two-factor authentication and review who has shared access.
- Decide deliberately about any police footage-sharing program.
6. Baby monitors and cameras
The basics
There are two entirely different product categories sharing one name.
Non-networked monitors transmit on a dedicated radio link: no internet, no account, no app. Wi-Fi monitors are internet-connected cameras with a cloud service.
The first category cannot be accessed from the internet, because it isn’t on the internet.
Go deeper
- The recurring news story of a stranger’s voice speaking through a nursery camera is real, and it recurs.
- Enormous botnets have been assembled from internet-exposed cameras running default credentials.
- Cameras are frequently the least-updated devices in a home, running firmware from the year they were purchased.
What most people don’t know
Nearly every “hacked baby monitor” story is password reuse, not a vendor breach, which means the fix is a password manager rather than a new camera.
The mechanism is credential stuffing. An unrelated site gets breached, your email and password end up in a public list, and attackers try that pair against camera services at scale. If you reused the password, they’re in. No vulnerability was exploited, no company failed, and buying a more expensive camera changes nothing.
Two things eliminate this category of incident: a unique password per service, and two-factor authentication.
The enabling mechanism worth naming: UPnP, a router feature that lets devices open ports to the internet automatically without asking you. It’s how cameras end up publicly reachable when their owners assumed they were behind a firewall. Turning UPnP off at the router is a five-second change with real effect.
And the security-professional answer to the specific question of infant monitors: use a non-networked one. A dedicated-radio audio or video monitor has no internet attack surface at all. There’s no account to breach, no cloud to be accessed, no firmware to go unpatched. For a device whose entire job is to watch a sleeping child, eliminating the attack surface beats defending it.
Do this today
- Unique password plus two-factor on every camera account, managed in a password manager.
- Turn off UPnP at the router.
- Update camera firmware, and replace cameras that no longer receive updates.
- Consider a non-networked monitor for infants.
- Unplug or physically cover cameras in bedrooms and bathrooms when not needed.
7. Data sharing with manufacturers
The basics
Your devices talk to their makers, and their makers’ partners. Independent research measuring actual network traffic from dozens of smart home devices has consistently found that most contact third parties such as analytics providers, cloud platforms, and ad services, and that a meaningful share transmitted some data without proper encryption.
The gap between what device marketing implies and what the traffic shows is the recurring finding of this entire research area.
Go deeper
- Devices report far more than their function requires: usage patterns, timing, sometimes ambient conditions.
- Data flows to whoever acquires the company. Device data is an asset in an acquisition.
- Devices with cameras have produced the starkest incidents. In one widely reported case, images captured by robot vacuums during product development, including deeply private household scenes, circulated online after being handled by outsourced data-labeling workers. The devices were development units and participants had agreed to data collection, which is precisely the point: consent to “data collection for product improvement” does not communicate what that pipeline actually involves.
What most people don’t know
The privacy policy can change after you buy, and refusing the update costs you security patches.
This is a genuine bind with no clean answer. A device you purchased under one set of terms can be updated into a different one. Firmware updates bundle security fixes with feature and telemetry changes, and you cannot generally accept one and decline the other. So the choice is running known-vulnerable firmware or accepting new data collection.
The corollary is uncomfortable and worth stating plainly: the purchase decision is the real decision. After you’ve bought a closed device and put it on your network, your remaining options are narrow. You cannot audit its firmware, verify its claims, or hold its policy fixed. This is why “which devices do I buy, and which do I decline to buy at all” carries more weight than any setting discussed in this lesson.
Which brings the argument full circle to Section 3: since you can’t control the device, control the network it sits on. DNS filtering and segmentation work regardless of what the manufacturer decides next year.
Do this today
- Check Mozilla’s Privacy Not Included guide before buying connected devices. It’s free and researched.
- Prefer devices that function without an account.
- Verify whether deleting your account actually deletes your data, or just your access.
- Assume you’ll own each device for years under terms that may change.
8. Tips to secure your connected home
Ranked by protection per hour spent
- Encrypted, filtering DNS at the router: protects every device, including those with no settings
- Don’t connect what doesn’t need connecting, starting with the television
- Unique passwords and two-factor everywhere, in a password manager: eliminates the most common real-world compromise
- Segment IoT onto a separate network: contains a breach to one device
- Update firmware; replace end-of-support hardware, especially the router
- Turn off UPnP
- Set auto-delete on voice and video history: a setting that keeps working without you
- Kill ACR and ad tracking on the TV
- Audit what’s actually on your network using your router’s device list, or an app like Fing. Most people find something they’d forgotten
- Cover or unplug cameras and mics in private rooms
The part about other people
Your devices record people who didn’t agree to any of this: guests, housemates, cleaners, children, neighbors on the sidewalk. Two habits cover most of it: tell guests what’s recording, and don’t put cameras or always-on microphones in bedrooms, bathrooms, or guest rooms. If you’re a landlord or host, disclosure isn’t just courtesy. Undisclosed recording in a rental violates platform rules and, in some places, the law.
When you move out or sell
Factory reset every device, remove each one from your account, and deregister it. A smart lock, thermostat, or camera still linked to a previous owner’s account is a live access path. This is the same gap covered in Lesson 2 for vehicles, and it’s just as commonly missed.
The honest limits
A VPN on your router hides traffic from your ISP. It does nothing about what manufacturers collect from devices you’ve authorized, the same limitation as Lesson 1.
“Local processing” and “we don’t sell your data” are claims you can’t verify from the outside. Research has repeatedly found the traffic telling a different story than the marketing.
And the limit that governs the rest: you cannot audit a closed device on your network. Which is why declining to buy or connect it remains the strongest control available, and why the network-level protections matter most, since they’re the only ones that don’t depend on trusting the manufacturer.
Recap
- Your TV’s content recognition identifies everything on the screen, including consoles and HDMI inputs, and the setting is named something agreeable.
- The most reliable TV fix is not connecting it to Wi-Fi.
- Voice transcripts persist separately from voice recordings; delete both and set auto-delete.
- DNS at the router is the highest-leverage control in the home because it covers devices with no settings.
- Segmenting IoT onto its own network contains a compromise to one device.
- Cloud-dependent appliances are a dependency you didn’t sign; local control standards are the fix.
- Doorbell audio may violate your state’s wiretap law; turn it off or check.
- “Hacked camera” incidents are almost always password reuse; UPnP is how devices get exposed.
- A non-networked baby monitor has no internet attack surface at all.
- Privacy policies change after purchase, and declining updates costs security patches, so the purchase is the real decision.
Key terms
- ACR (automatic content recognition): screen or audio fingerprinting that identifies whatever your TV displays, on any input.
- False wake: an assistant mistakenly triggering and recording non-command audio.
- DNS filtering: blocking tracking and telemetry domains at the network level, covering all devices.
- Network segmentation: isolating IoT devices on a separate network so a compromise can’t reach your computers.
- UPnP: a router feature letting devices open internet-facing ports automatically; a common cause of exposed cameras.
- Credential stuffing: reusing breached username/password pairs against other services; the cause of most camera intrusions.
- Local control (Matter/Thread): device operation on your own network without routing through a manufacturer’s cloud.
- End-of-support: the point at which a device stops receiving security patches while continuing to function.
- Two-party consent: state laws requiring all participants to consent to audio recording.
Check your understanding
1. You never use your smart TV’s apps, and you only watch through a cable box and a game console. Does the TV collect data about your viewing? Yes, if it’s connected to the internet and content recognition is on. ACR reads the panel, so it identifies content from any input. Disconnecting the TV from Wi-Fi is the most reliable fix.
2. A stranger’s voice comes through a family’s nursery camera. What almost certainly happened? Password reuse. Their credentials appeared in an unrelated breach and were tried against the camera service. A unique password and two-factor authentication would have prevented it. A more expensive camera would not have.
3. You have twelve smart devices, several with no privacy settings at all. What’s your highest-leverage move? Change your network, not your devices. Encrypted filtering DNS at the router covers everything on the network, and moving IoT devices to a separate segment limits what a compromised one can reach.
Next lesson: Your Data — data brokers, advertising, breaches, and the data economy.