Hand holding tablet and shield protect icon showing security updates for smart devices

Smart Devices Adding Security Updates to Combat Vulnerabilities, but EU Consumers Remain Unimpressed

After years of neglect, there has been some recent security improvement in the world of smart devices. Much of that has been driven by European Union mandates that require security updates for a “reasonable” period of device life. Unfortunately, new research shows that these improvements are still falling short of consumer expectations as it remains unclear how long they can expect devices to be covered.

Consumers hesitant on purchase of smart devices as long-term safety status remains unclear

At one time, it was common for smart devices to ship without passwords, or with a stock manufacturer password that could not be changed. The idea of regular security updates was laughable in this market, but the targeting of smart devices as the primary weak link in network security has gradually been changing things. The global market still has no shortage of poorly secured smart devices, but those sold in the EU must have minimum protections and must also offer security updates for at least some period of reasonable expected product shelf life.

EU consumers remain wary of smart devices even with these legal guarantees, however, due primarily to fuzziness about exactly how long devices are required to be covered by security updates. New research from Privacy International shows that consumers expect most of the lifetime of the device to be covered, but in most cases the device manufacturers are only providing security updates for no more than two years from the product’s original launch. Late adopters of a device might only see updates for a few months after purchase, if at all.

For all types of smart devices, about 30 to 40% of consumers are expecting security updates for a period of two to ten years. Only about 18 to 22% expect devices to be protected for less than two years; consumers have a higher tolerance for short protection periods with their smartphones, which are often upgraded every two to three years anyway, than they do with products with longer expected life cycles such as video game consoles (which usually have a formal support cycle of 10 years) or televisions (which consumers also generally keep for close to a decade).

However, the research finds that a number of manufacturers are not providing security updates for smart devices for nearly as long as their expected life cycles. In addition, manufacturers often do not specify exactly how long they plan to support security updates. In some cases, they link to an unrelated item such as a manufacturer’s warranty meant to cover defects, which may give consumers the wrong impression that their smart devices will also receive security updates for that same period.

The “reasonably expect” language in the EU rules means consumers really have no firm idea of how long security updates will be supported, and unless the manufacturer clarifies it with a printed commitment (which appears to be rare) they could see their smart devices lose vital security support at any time.

Regulators push for mandatory security updates period

EU regulators have some new rules on the table that could protect certain types of smart devices. Smartphones are being addressed with European Commission draft rules that propose a mandatory five years of security updates for each new phone, along with three years of OS updates and five years of availability of spare parts. OS updates would also be required to not negatively impact the performance or battery life of the device. The draft rules are currently in a feedback period and could be adopted in 2023.

Privacy International has also recently released a set of proposed amendments to a different European Commission directive covering long-term transition to green energy sources, calling for a requirement for device manufacturers to publish clear information on how long smart devices will be supported by software and security updates. The proposal calls for this information to be decoupled from information on functionality updates for easier consumer access.

Smart device security is becoming less of an afterthought as more and more applications are added to homes. A home that is fully kitted out with poorly secured smart devices could be subject to hackers spying via cameras and microphones, unlocking doors, and controlling lights and appliances. If the devices are hooked up to computer networks, it is also possible in some cases for the attacker to use this as an entry point.

Unfortunately, outside of the EU there is not much legal force pushing manufacturers to improve security. Several nations have made smaller moves, however. Singapore requires “security labels” on smart devices that more quickly inform consumers what sorts of potentially sensitive data they handle, how security updates are handled, and whether or not data is encrypted. The United States began implementing its own version of this system in 2021, and the standard is set to go into legal effect in early 2023.