31/08/2022

Research digital safety, update policy, and information provision for smart devices.

The information provided to buyers of smart devices prior to purchase was found to be limited. Security updates were not always provided, even though security vulnerabilities had been identified.

How safe is the software of home automation devices on the Dutch market, and does the information provided by sellers about (among others) the update policy correspond to reality?

The text on this page was automatically translated and hence may differ from the original. No rights can be derived from this translation.

The Netherlands Authority for Consumers and Markets (ACM) and the National Inspection Digital Infrastructure (RDI) have commissioned Dialogic to conduct research on the functioning and security of smart devices. The main findings are:
  • The information provided to buyers before purchase was found to be limited. Particularly, information about the update policy was missing. Furthermore, the version of the operating system was not always specified. As a consumer, this makes it impossible to know if a specific app can control the smart device.
  • Manufacturers sometimes provided different information than sellers, causing confusion. Additionally, the information provided in physical stores was less comprehensive than online.
  • One home automation device in the sample had an exploitable security vulnerability.
  • Security updates were not always provided, even though security vulnerabilities had been identified.
This is the first time that the ACM and RDI have conducted joint research. The outcomes of the research will form the basis for both supervisory authorities in their oversight of smart devices for consumers.

Follow-up Research

The research recommends investigating over a longer period whether updates are being provided. Following this, RDI and ACM decided that RDI would investigate whether the devices had received updates after the research had ended. This follow-up research confirms the results of the initial study. Manufacturers who did not provide updates during the previous research period also did not provide updates during this follow-up period.

Read More

For more information on the research, visit the websites of the ACM and RDI: Dialogic conducted the research in collaboration with Creds (specialists in digital penetration testing). Additionally, Prof. Dr. Marco Loos (Professor of Private Law, particularly European consumer law at the University of Amsterdam) contributed to the development in the field of consumer rights. Dialogic was not involved in the follow-up research. The photo accompanying this article does not depict the products tested.