"It did not give me an option to decline": A Longitudinal Analysis of the User Experience of Security and Privacy in Smart Home Products
Authors
Document Title
“It did not give me an option to decline”: A Longitudinal Analysis of the User Experience of Security and Privacy in Smart Home Products
Document Information
- Subject Area: Human-Computer Interaction and Smart Home Security and Privacy
- Keywords: User Experience, Security, Privacy, Smart Home, Longitudinal Study, Qualitative Research
Research Background and Problem
- Identified Issues or Challenges: Smart home products fail to deliver on their promises of convenience, energy efficiency, and security assurance. Users experience feelings of helplessness, confusion, and frustration regarding security and privacy. Additionally, there is inconsistency in managing security and privacy, particularly in granting and revoking data access permissions.
- Significance: As smart home devices become increasingly widespread and complex, they raise new privacy and security concerns, such as data misuse and surveillance. Understanding the long-term user experience of these devices is crucial for improving user experience and designing better security and privacy features.
- Motivation and Related Work: Existing research primarily investigates security and privacy issues through lab experiments and surveys, lacking long-term observation in real home environments. This study addresses the gap in long-term perspectives and explores how to better support users.
Solution
- Proposed Solution: The authors conducted a six-month ethnographic study observing six UK households as they installed and used smart home devices. They systematically analyzed users' experiences with security and privacy issues to explore user needs and propose design recommendations.
- Innovations:
- The first study to showcase the evolution of security and privacy user experiences with smart home devices through long-term ethnographic data.
- In-depth analysis of privacy and security issues arising from the repurposing of smart devices in real-world contexts (e.g., for parenting and entertainment).
- Implementation Steps and Key Techniques:
- Employed secondary data analysis methods, coding and thematically analyzing interview, diary, and field observation data from prior research.
- Analyzed detailed data from 22 participants, including device usage patterns and privacy and security management behaviors.
- Developed a coding framework and validated its reliability (Cohen’s kappa value of 0.84, indicating near-perfect agreement).
Research Findings
- Specific Findings:
- Users’ experiences with privacy and security in smart devices are inconsistent. For instance, granting data collection permissions is relatively easy, but revoking them is very difficult.
- Some devices are repurposed (e.g., for parenting and entertainment), leading to new privacy and security issues, such as intrusiveness and loss of data control.
- Users adopt physical privacy measures (e.g., covering cameras with stickers) to address privacy concerns, while relying on device design controls for security issues.
- Privacy concerns stem from media, online resources, and device usage itself, whereas security concerns are primarily influenced by external information sources.
- Advantages Compared to Existing Solutions:
- Long-term observation in real household environments reveals the dynamic and complex nature of security and privacy behaviors in daily use of smart home devices.
- Provides specific design guidance for managing the lifecycle of privacy permissions (granting, revoking, modifying).
- Highlights the issue of power imbalances among cohabitants and their impact on privacy and security.
- Experimental or Evaluation Results:
- Data from 47 interviews, 13 participant diaries, and related photo records from six households demonstrated significant shifts in privacy and security experiences. The findings also revealed users’ complex attitudes toward permission management and password fatigue.
- High coding consistency during data analysis supports the reliability of the conclusions.
- Limitations and Future Directions:
- Data is limited to UK households and may not capture privacy and security experiences of other regions or demographics.
- Secondary data analysis may not encompass all relevant dimensions of security and privacy.
- Future research could expand to more diverse populations and test the applicability of the proposed improvements globally.
Summary and Recommendations
The authors propose the following design recommendations to improve the security and privacy experience of smart home devices:
- Enhance User Authorization Experience: Design more flexible permission management interfaces (e.g., temporary authorization options) to accommodate the dynamic nature of privacy permissions over time.
- Anticipate Consequences of Repurposing Technology: Provide transparent usage logs and relevant notifications for new uses of devices, such as alerts when a camera is active.
- Increase Physical Privacy Protection Options: Offer simple and user-perceived effective privacy controls, such as physical camera covers and visual indicators for privacy settings.
- Harmonize Security Features: Standardize security terminology and interfaces across devices within the smart home ecosystem to reduce user confusion when managing the entire system.
This study provides new perspectives and guidance for designers on balancing technological advancements in smart devices with the protection of user privacy.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- In smart home devices, how do users manage data collection permissions, especially experiences when granting and revoking permissions?Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
- How does multipurpose use of smart home devices create new privacy and security problems?Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
- How do users address smart home device privacy and security concerns through physical measures and design controls?Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
Practical Problems
1- Smart home device privacy and security management is complex, leaving users feeling powerless and confused.Category: Smart Home and IoT Privacy, Security, and Developer SupportSimilar questionsarrow_forward
- 80%
Designing Interactive Privacy Labels for Advanced Smart Home Device Configuration Options
DIS '24· Privacy by Design & User Control +2
- 75%
Informing the Design of Privacy-Empowering Tools for the Connected Home
CHI '20· Privacy by Design & User Control +1
- 75%
Investigating Tangible Privacy-Preserving Mechanisms for Future Smart Homes
CHI '23· Privacy by Design & User Control +1
- 75%
Home Is Where the Smart Is: Development and Validation of the Cybersecurity Self-Efficacy in Smart Homes (CySESH) Scale
CHI '23· Privacy by Design & User Control +1
- 67%
Wearable Microphone Jamming
CHI '20· Privacy by Design & User Control +2
- 60%
Overlooking context: How do Defaults and Framing Reduce Deliberation in Smart Home Privacy Decision-Making?
CHI '21· Privacy by Design & User Control +1
- 60%
Decide Yourself or Delegate - User Preferences Regarding the Autonomy of Personal Privacy Assistants in Private IoT-Equipped Environments
CHI '24· Privacy by Design & User Control +3
- 60%
Towards Understanding Family Privacy and Security Literacy Conversations at Home: Design Implications for Privacy Literacy Interfaces
CHI '24· Privacy by Design & User Control +1
- 60%
PrivacyHub: A Functional Tangible and Digital Ecosystem for Interoperable Smart Home Privacy Awareness and Control
CHI '25· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)