Part II · Chapter 19
The Smart Home as Informant
A smart home never has to be hacked to become an informant: its account answers to whoever owns it, not whoever is safe — and on the documented record, legal ownership has overridden a restraining order.
The devices examined in this chapter were never hidden, never covertly installed, never marketed as anything other than what they appear to be: a thermostat, a lock, a doorbell camera, a speaker that answers questions. None of them needs to be secretly repurposed to become a surveillance tool. The failure sits somewhere else entirely — in a question almost no one asks when they set up a smart home for the first time: who does the account actually answer to, and does the system have any way of telling a dangerous answer from a safe one?
The clearest account comes from a 2018 New York Times investigation by Nellie Bowles, built on more than thirty interviews with domestic-abuse victims, their lawyers, shelter workers, and emergency responders. It documented a consistent pattern: internet-connected locks, speakers, thermostats, lights, and cameras, purchased for convenience, used by an abusive partner via a smartphone app to remotely monitor, harass, confuse, or frighten someone still living in the home. The finding that matters most is structural, not any single incident: even after an abuser moved out of the shared home, the devices very often stayed installed, and stayed under his account. Leaving the relationship did not end his access to the house.1
Two connected-car cases make the mechanism unusually concrete: in both, nothing was hacked; the technology performed exactly as designed. Christine Dowdall fled her Louisiana home in a Mercedes-Benz after leaving her husband, a DEA agent, and discovered he was tracking her location through the car’s own “mbrace” connected service. She called Mercedes to have his access removed — with a restraining order already in place and sole use of the vehicle awarded to her in the divorce — and was told he could keep it because he remained listed on the loan and the title. The company’s account model tracked financial ownership, not who was safe to have location access to a specific human being, and it said so plainly when asked.2 A separate San Francisco case saw a man use his continued remote access to a jointly owned Tesla to harass his ex-wife after separation — activating the lights and horn, adjusting the cabin temperature, and using the car’s location-finding feature to identify her new address. The FCC subsequently sent letters to nine major automakers asking whether their connected-car apps had any safeguard for exactly this situation.3
This ownership-model problem is distinct from a second, more familiar failure: plain insecurity. In 2016, the Mirai botnet scanned the internet for connected devices still running factory-default credentials — a list of just sixty-two common username-password pairs was sufficient to compromise hundreds of thousands of routers and cameras — and used them to launch some of the largest distributed denial-of-service attacks on record, including the October 2016 attack on the DNS provider Dyn that took GitHub, Twitter, Reddit, Netflix, and Airbnb offline across large parts of the United States.4 Mirai established, at industry scale, just how low the security floor for consumer IoT devices actually was. Individual vendors have supplied their own, more targeted versions of the same failure. TRENDnet’s internet-connected security cameras, in a case that became the FTC’s first-ever IoT enforcement action in 2013, transmitted and stored login credentials in plain, unencrypted text; a hacker exploited this and published live feeds from roughly seven hundred customers’ cameras, including babies asleep in cribs.5 A decade later, the FTC’s 2023 complaint against Ring — settled for $5.8 million — found that the company had given employees and hundreds of third-party contractors based in Ukraine broad, unrestricted access to customers’ private video, including footage from cameras placed in bedrooms and bathrooms, with one employee documented viewing thousands of recordings from at least eighty-one female users’ cameras over a three-month span in 2017, specifically seeking out footage from bathrooms and bedrooms.6 California’s SB-327, effective in 2020 and the first law of its kind in the country, addresses the Mirai-style problem directly by requiring connected devices sold in the state to ship with either a unique password per unit or a forced password change on first use.7 It addresses nothing about the ownership-model problem the Mercedes and Tesla cases describe, because no engineering fix touches that failure. That one requires a company to choose, as policy, to honor a restraining order over a loan document — which Mercedes, on the account documented in the Boston 25 News investigation, chose not to do.
Nowhere does this ownership problem surface more starkly than in the case of Ferial Nijem, reported by Digital Trends, the CBC, and Refinery29. Her American home had a built-in, whole-house automation system controlling the lights, heating, blinds, sound system, and security cameras from a single app. During and after her relationship, her ex-partner used that single point of control to monitor her remotely through her own home’s security cameras from thousands of miles away, seize control of the audio system to blast music in the middle of the night, and switch the lights and television on and off repeatedly, disturbing her and her dogs at will. She could not simply disable his access, because the system offered no way to remove one user’s control without shutting down the entire house’s power and lighting along with it — in her own words, “shutting down the system meant shutting down the house.” When she went to local police, she was told nothing could be done, because her ex-partner was the sole listed owner of the home. Law enforcement treated the smart-home account’s ownership structure as legally equivalent to property ownership, and declined to intervene on that basis alone. She eventually found help through a women’s shelter and now shares her story with domestic-violence organizations directly.8 It is the sharpest version of this mechanism: the ownership-equals-control logic reaching not just into a company’s customer-service policy, as with Mercedes, but into a police officer’s own judgment about whether a crime was even occurring.
A separate mechanic operates alongside the ownership problem: plain technical vulnerability requiring no legitimate access at all. Security researchers have documented serious flaws in multiple consumer and commercial smart-home hubs, where unauthenticated access to the hub’s own web interface lets anyone with mere physical proximity to the home network seize control of every device connected to it, no credentials required.9 It is the mirror image of Nijem’s case: where her ex-partner needed no exploit because the account’s own logic entitled him to control, this class needs no entitlement, only proximity. Google’s own Home app offers a partial answer to at least the ownership half of this problem, distinguishing an Admin role from a Member role. That structure at least creates the possibility of a household member holding meaningfully limited rather than zero standing — the alternative design Nijem’s all-or-nothing system never offered her at all.10
Smart speakers add a further wrinkle: the same always-listening microphone that makes these devices a surveillance risk is, mechanically, the identical reason they have twice become central to a murder investigation. In Arkansas, prosecutors sought recordings from an Amazon Echo present the night Victor Collins was found dead in James Bates’s hot tub; Amazon fought the request for months on privacy grounds before Bates himself consented to the release, and charges were ultimately dropped for reasons unrelated to what the device had captured: the prosecutor moved to dismiss on the ground that the evidence supported more than one reasonable explanation of the death, saying he could not ask a jury to convict beyond a reasonable doubt when he held a reasonable doubt himself.11 In New Hampshire, a double-murder prosecution went further: a Strafford County Superior Court judge ordered Amazon to turn over two days of Echo recordings after finding probable cause that the device had captured audio of the attack itself.12 Amazon’s stated position in both cases was consistent — it would not release recordings without a valid, properly served legal demand, which is exactly the process the courts then supplied. These two cases are the forensic-reconstruction mirror of every surveillance risk described here: the same hardware that can be turned against a household can, under the right legal process, become the one witness in a room where no human witness survived to testify. Beneath both possibilities sits an ordinary account-visibility feature, not a security flaw at all. Amazon’s own product documentation confirms that whoever controls a household’s Alexa account can view voice-command history filtered by specific device and even by which household member’s voice was recognized — a feature Amazon itself recommends for “managing different household members’ privacy.”13 It is the same admin-knows- everything logic this chapter has already traced through cars, hubs, and cameras, simply applied here to the record of who spoke to the speaker, and when.
Cameras carry further, independently documented failure modes. Foscam baby-monitor cameras shipped with “admin” and “admin” as a factory-default username and password that a large share of buyers never changed, and in 2013 a Houston couple discovered a stranger had taken over their daughter’s monitor, addressing their sleeping two-year-old by name with obscenities before swiveling the camera to face the parents when they entered the room — a vulnerability that, once disclosed, was found to affect an estimated forty thousand other Foscam users.14 A third and entirely different actor enters through Ring’s Neighbors app, which for years let police departments post public requests for footage and let Ring itself supply recordings to law enforcement without a warrant or the device owner’s consent under circumstances the company defined unilaterally — a partnership that, at its peak, extended to roughly one in every ten police departments in the United States, and that the Electronic Frontier Foundation documented disproportionately increasing scrutiny of people of color in the neighborhoods where it operated. This is one of the rare cases here with an actual resolution: sustained public and advocacy pressure led Amazon to end the Request for Assistance tool entirely in January 2024.15
Even devices with no obvious surveillance function have produced documented privacy failures at real scale. Vizio was found by the FTC to have secretly captured second-by-second viewing data from eleven million smart televisions starting in 2014, appending specific demographic details (sex, age, income, marital status, household size, home value) to each viewing record without consumers’ knowledge, settling for $2.2 million and a requirement to obtain affirmative consent going forward.16 Samsung’s smart TVs, by contrast, disclosed their voice-capture practice openly in a privacy policy, stating plainly that spoken words containing personal information would be transmitted to a third-party voice-to-text company, and it became a scandal anyway, compounded when an independent researcher found Samsung had failed to encrypt all of the conversations it was transmitting.17 Samsung’s case cuts against the comforting assumption that disclosure solves the problem: a privacy policy that technically covers a capability does not functionally inform anyone living with the device. It is the same gap this chapter has traced through ownership models, admin permissions, and account visibility — a capability being disclosed, permitted, or even legally owned by the right party is not the same as anyone in the household actually understanding, in practice, what the device in their living room can do to them.
That same gap, though, cuts both ways once a case is being built. The account model that hands an abuser control also keeps the record of it: access logs showing which account viewed a camera and when, voice-command histories filterable by device and by speaker, a smart lock’s own entry log, and — as the Arkansas and New Hampshire cases established — the recordings themselves, all reachable under proper legal process. What that record cannot fix is the policy failure underneath the Mercedes and Nijem cases — a company or a police officer choosing ownership over safety — which no subpoena reaches, because it was never a technical problem to begin with.
Notes
Bowles, Nellie, “Thermostats, Locks and Lights: Digital Tools of Domestic Abuse,” New York Times, June 23, 2018 — based on 30+ interviews with domestic-abuse victims, their lawyers, shelter workers, and emergency responders; documented that devices often stayed installed and under an abuser’s account control even after he moved out. https://www.benton.org/headlines/thermostats-locks-and-lights-digital-tools-domestic-abuse↑
Christine Dowdall (Louisiana) fled her home in a Mercedes-Benz C300 after leaving her husband, a DEA agent, and discovered he was tracking her location via Mercedes’ “mbrace” connected service; Mercedes told her he could keep his access because he remained listed on the loan and title, despite a restraining order and sole vehicle use awarded to her in the divorce proceedings. Reported by Samantha Manning, “‘Horrible feeling’: Domestic violence survivor says connected car was used to track her,” Boston 25 News / Cox Media Group, May 6, 2024. https://www.wftv.com/news/local/horrible-feeling-domestic-violence-survivor-says-connected-car-was-used-track-her/FEJWOTAMOZDL5GDZHIEAV2WF4Y/↑
A San Francisco man used continued remote access to a jointly owned Tesla Model X to harass his ex-wife post-separation — activating lights and horn, controlling cabin temperature, and using the location-finding feature to identify her new residence; the FCC subsequently sent letters to nine major automakers asking about safeguards. Per Kashmir Hill, “Your Car Is Tracking You. Abusive Partners May Be, Too.,” New York Times, December 31, 2023 — the same connected-car investigation cited at [^2].↑
The 2016 Mirai botnet scanned the internet for IoT devices running factory-default credentials (a list of 62 common username/password pairs was sufficient to compromise hundreds of thousands of devices) and used them for DDoS attacks including the October 21, 2016 attack on DNS provider Dyn, which made GitHub, Twitter, Reddit, Netflix, and Airbnb inaccessible across large parts of the US. Manos Antonakakis et al., “Understanding the Mirai Botnet,” USENIX Security Symposium (2017); the botnet’s authors pleaded guilty in United States v. Jha et al. (D. Alaska, 2017).↑
TRENDnet’s internet-connected security cameras transmitted and stored login credentials in plain, unencrypted text; a hacker exploited this and published live feeds from ~700 customers’ cameras. FTC settlement, September 2013 — the FTC’s first-ever IoT enforcement action. https://www.ftc.gov/news-events/news/press-releases/2013/09/marketer-internet-connected-home-security-video-cameras-settles-ftc-charges-it-failed-protect↑
FTC v. Ring, LLC, settled May 2023 for $5.8M: Ring gave employees and hundreds of Ukraine-based third-party contractors broad, unrestricted access to customers’ private video, including bedroom and bathroom footage; one employee viewed thousands of recordings from at least 81 female users between June and August 2017. https://www.ftc.gov/news-events/news/press-releases/2023/05/ftc-says-ring-employees-illegally-surveilled-customers-failed-stop-hackers-taking-control-users↑
California SB-327 (“Information privacy: connected devices”), effective January 1, 2020 — the first US state law requiring baseline cybersecurity for connected devices, mandating either a unique preprogrammed password per device or a forced password change on first use. https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB327↑
Ferial Nijem, whose case has been reported by Digital Trends, CBC, and Refinery29: her US home’s whole-house automation system was used by her ex-partner to monitor her via security cameras remotely, take over the audio system, and control lights, after their relationship ended; she could not disable his access without shutting down the whole house’s power, and police declined to intervene because he was the sole listed homeowner. https://www.digitaltrends.com/home/woman-stalked-by-abusive-ex-using-smart-home-tech/; https://www.cbc.ca/news/science/tech-abuse-domestic-abuse-technology-marketplace-1.4864443; https://www.refinery29.com/en-ca/2019/01/220847/domestic-abuse-violence-harassment-smart-home-monitoring↑
Security researchers have documented serious vulnerabilities in multiple consumer/commercial smart-home hubs — including Fibaro Home Center Lite, Homematic Central Control Unit (CCU2), and eLAN-RF-003 — where unauthenticated access to the hub’s web interface allows anyone with local network access to take control of the hub and every connected device, no credentials required. https://www.welivesecurity.com/2020/04/22/serious-flaws-smart-home-hubs-is-your-device-among-them/↑
Google Home app’s permission structure distinguishes Admin from Member roles; admins can grant or revoke a member’s ability to control devices, change settings, or view activity data including camera history. https://support.google.com/googlehome/answer/9155535?hl=en↑
State of Arkansas v. James Bates (2015–2017): Victor Collins was found dead in Bates’s hot tub in November 2015; prosecutors sought Echo device recordings, and Amazon fought the request for months on First Amendment and customer-privacy grounds before Bates himself consented to release in March 2017; prosecutors dropped all charges in November 2017, stating the evidence “could support more than one reasonable explanation.” https://www.npr.org/sections/thetwo-way/2017/11/29/567305812/arkansas-prosecutors-drop-murder-case-that-hinged-on-evidence-from-amazon-echo↑
A New Hampshire prosecution arising from the January 2017 killings of Christine Sullivan and Jenna Pellegrini: in November 2018 a Strafford County Superior Court justice ordered Amazon to turn over two days of Echo recordings after finding probable cause the device had captured audio of the attack itself. The defendant is not named here; the case is cited for what the court ordered of Amazon, and this book takes no view on charges a court had not then resolved. https://www.cbsnews.com/news/amazon-echo-judge-orders-company-produce-alexa-recordings-double-murder-case-2018-11-12/↑
Amazon’s own product documentation: the Alexa app lets whoever controls the account view voice-command history filterable by specific device and by “Voice ID,” recommended by Amazon for managing different household members’ privacy. https://www.howtogeek.com/what-does-alexa-and-echo-know-about-you-how-to-review-your-voice-history-and-data/↑
In Houston, 2013, a couple discovered a stranger had taken over their Foscam baby monitor, addressing their sleeping two-year-old by name with obscenities before swiveling the camera to face the parents; the camera’s factory-default “admin”/“admin” credentials were listed in the manufacturer’s own FAQ, and the vulnerability was found to affect an estimated 40,000 other Foscam users. https://www.forbes.com/sites/kashmirhill/2013/08/13/how-a-creep-hacked-a-baby-monitor-to-say-lewd-things-to-a-2-year-old/; https://www.forbes.com/sites/kashmirhill/2013/08/27/baby-monitor-hack-could-happen-to-40000-other-foscam-users/↑
Ring’s Neighbors app let police departments post public “Request for Assistance” notices, and Ring separately admitted providing footage to police without a warrant or owner consent under circumstances it defined itself; the partnership extended to roughly 1 in 10 US police departments at its peak, and EFF documented disproportionately increased scrutiny of people of color in participating neighborhoods. Amazon ended the Request for Assistance tool in January 2024 after sustained public and EFF pressure. https://www.eff.org/deeplinks/2022/07/ring-reveals-they-give-videos-police-without-user-consent-or-warrant; https://www.eff.org/deeplinks/2024/01/ring-announces-it-will-no-longer-facilitate-police-requests-footage-users↑
FTC/New Jersey v. Vizio, settled February 2017: Vizio captured second-by-second viewing data from 11 million smart TVs starting February 2014, appending demographic data (sex, age, income, marital status, household size, home value) without consumer knowledge; settled for $2.2 million with a requirement for affirmative express consent going forward. https://www.ftc.gov/news-events/news/press-releases/2017/02/vizio-pay-22-million-ftc-state-new-jersey-settle-charges-it-collected-viewing-histories-11-million↑
Samsung’s Smart TV privacy policy (February 2015) disclosed that spoken words containing personal information would be transmitted to third-party voice-to-text company Nuance; an independent researcher found Samsung had not encrypted all of the conversations transmitted, and EPIC filed a formal FTC complaint alleging deceptive disclosure. https://www.npr.org/sections/thetwo-way/2015/02/09/385001258/samsungs-privacy-policy-warns-customers-their-smart-tvs-are-listening; https://epic.org/documents/samsung-smarttv-complaint/↑
From The Machinery of Compliance by Willow Whitman · edition 1.0.2, · free under CC BY-NC-ND 4.0 · corrections