Surveillance Infrastructure: Workplace Bossware & Smart Home / IoT
Reference document for institutional control infrastructure research. Covers workplace algorithmic management, employee monitoring software, and the consumer IoT surveillance ecosystem.
Contents
Reference document for institutional control infrastructure research. Covers workplace algorithmic management, employee monitoring software, and the consumer IoT surveillance ecosystem.
PART 1: WORKPLACE SURVEILLANCE / BOSSWARE
1. The COVID Remote Work Surveillance Explosion
The pandemic triggered a massive adoption spike in employee monitoring software (“bossware”), as managers scrambled to maintain oversight of newly remote workers.
Scale of adoption:
- Hubstaff reported trial signups tripled between March and May 2020.
- InterGuard’s customer base tripled or quadrupled during lockdowns.
- Time Doctor’s daily pageviews jumped from ~2M throughout 2019 to 5.9M in July 2020.
- Workpuls saw daily pageviews increase over 1,000% from 2019 to 2020.
- ActivTrak’s daily average traffic soared over 200% in the same period.
- A 2021 Digital.com survey of 1,250 business leaders found 60% were already using bossware. By 2024-2025, estimates put adoption at ~70%.
What these tools track: Keystroke logging, screenshot capture (random or timed), mouse movement and idle time, application and website usage, webcam photos, GPS/location tracking, email and chat content, clipboard contents, file transfers, and browser history. Many can be installed silently (“stealth mode”) without the employee’s knowledge.
Key clients: Hubstaff is used by Instacart, Groupon, and Ring. ActivTrak is used by over 6,500 organizations including Arizona State University, Emory University, and the cities of Denver and Malibu.
EFF coined the term “bossware” in a landmark June 2020 report documenting how these tools work. The report found that most bossware “lives on a computer or smartphone with privileges to access data about everything that happens on that device” and that companies like Teramind, Time Doctor, and StaffCop design their software to be “as difficult to detect and remove as possible.”
References:
- EFF: Inside the Invasive, Secretive “Bossware” Tracking Workers — The foundational report (June 2020)
- The Business of Business: The Bossware Boom — Market data and pageview statistics
- Computerworld: The New Normal — When WFH Means the Boss Is Watching
- Surveillance & Society: Expansive and Invasive — Mapping the “Bossware” Used to Monitor Workers — Academic study
- Privacy International: WFH — Watched from Home: Office 365 and Workplace Surveillance Creep
- State of Surveillance: Bossware 2025
2. Amazon Warehouse Algorithmic Management
Amazon’s fulfillment centers use handheld radio-frequency scanners to track every minute of every worker’s shift. The system automatically generates warnings and terminations based on productivity metrics without human review.
The “Time Off Task” (TOT) system:
- Workers are tracked via RF scanners. Any period when the scanner is inactive is logged as “time off task.”
- A written warning is issued for accumulating 30 minutes of TOT in a single day (one occurrence per rolling year).
- Termination is triggered at 120 minutes of TOT in a single day, or 30 minutes of TOT on three separate days within a one-year period.
- Workers with a final written warning can be fired for 30 minutes or more of TOT in the same 12-month period.
- Two hours of TOT in a single shift also warrants termination.
Documented cases: Internal documents submitted to the NLRB (obtained by Vice via public records request, February 2020) showed an employee at JFK8 fired for accumulating 3 hours and 57 minutes of TOT in a single day. The manager provided a minute-by-minute breakdown of every period the scanner was inactive.
Injury rates: A Strategic Organizing Center study found Amazon warehouse workers are injured at higher rates than those at rival companies, which critics attribute to the relentless pace imposed by algorithmic quotas.
Legislative responses:
- California AB 701 (2021): Requires warehouse employers to disclose productivity quotas and prohibits quotas that prevent workers from taking rest or bathroom breaks. Passed specifically targeting Amazon.
- Washington, Minnesota, New York: Similar warehouse quota disclosure laws.
- Federal: Sen. Ed Markey introduced the Warehouse Worker Protection Act (2024), the first federal attempt to regulate warehouse quotas.
References:
- Vice: Internal Documents Show Amazon’s Dystopian System for Tracking Workers Every Minute of Their Shifts — The leaked NLRB documents
- CBS News: Amazon Under Fire for Software That Recommends Firing Workers
- NPR: California Bill Gives Amazon Warehouse Workers Power to Fight Speed Quotas
- NBC News: California Passes Bill Targeting Amazon’s Productivity Quotas
- CNBC: Senator Takes Aim at Amazon’s Labor Practices with Federal Quota Bill
- The Register: Amazon’s Algorithmic Management of Warehouse Workers
- Privacy International: Amazon Tracks Warehouse Workers’ Time Off Task
3. Gig Economy Algorithmic Control
Ride-hail and delivery platforms use algorithmic systems to control worker behavior while maintaining the legal fiction that drivers are independent contractors, not employees.
Algorithmic wage discrimination: Veena Dubal — then at UC Hastings (now UC Law San Francisco), since 2023 at UC Irvine — published the landmark paper “On Algorithmic Wage Discrimination” in Columbia Law Review (Vol. 123, No. 4, 2023). Key findings:
- Platforms use granular data — individual behavior, location, historical patterns — to calculate personalized, variable pay for each worker.
- Two drivers doing the same work at the same time in the same place can receive vastly different compensation.
- A delivery driver for Uber might make $6.50 for one delivery and $4.25 for an equivalent one, based on what the algorithm knows about their willingness to accept low offers.
- This constitutes a historical rupture in wage-setting: the use of “informational capitalism” to produce unpredictable, individualized pay that undermines economic stability.
Behavioral nudges and gamification:
- Uber uses psychological inducers in the app interface — video game features, graphics, noncash rewards — to nudge drivers into working longer in less lucrative locations.
- Entire teams of economists and engineers deploy “psychological tricks” to manipulate driver behavior without the obligations of an employer-employee relationship.
- Acceptance rate pressure: Drivers who decline too many rides risk deactivation (effective firing with no appeal).
- Surge pricing display: Manipulates driver positioning and availability.
- Drivers describe the platform as a “black box” fare system where they cannot predict or verify their pay.
Surveillance infrastructure: Platforms collect real-time GPS data, driving behavior (speed, braking, acceleration), customer ratings, acceptance/cancellation rates, and time-to-pickup metrics — all fed into algorithms that determine pay, ride assignment priority, and deactivation risk.
References:
- Columbia Law Review: On Algorithmic Wage Discrimination — Veena Dubal — The foundational academic paper
- Full PDF
- CBS News: AI Enables Algorithmic Wage Discrimination for Uber Drivers, Gig Economy Workers
- Slate: Uber and Lyft — Why AI-Powered Wages May Be Coming for Your Office Job
- Marketplace: How Ride-Hail Companies Use Data to Pay Drivers Less
- Equitable Growth: How AI Uncouples Hard Work from Fair Wages Through “Surveillance Pay”
- TechPolicy.Press: The Game Behind the Gig Economy
- NELP: Uber’s Price-Gouging and What We Can Do About It
- SF Public Press: Drivers Protest Uber’s “Black Box” Fare System
4. Microsoft Productivity Score
In late 2020, Microsoft rolled out Productivity Score as part of Microsoft 365 — a dashboard that tracked individual employee activity across the entire Office suite.
What it tracked: Emails sent, meetings attended, chat messages, collaboration patterns, Yammer usage, document co-authoring, OneDrive activity. Microsoft’s own promotional video showed individual-level metrics: “Amy sent emails over 22 days, Tom used Yammer for three days.”
The backlash: Digital-rights activist Wolfie Christl called it a “full-fledged workplace surveillance tool” and the criticism went viral. Privacy International published a detailed analysis (“Watched from Home”) showing how Office 365 could enable employers to read employee emails, monitor call duration, track meeting attendance, and measure collaboration frequency — all without employees’ knowledge.
Microsoft’s response (December 2020): Microsoft announced it would remove individual user names from Productivity Score. The company reframed the tool as measuring “technology adoption” rather than individual productivity. However, the underlying data collection capabilities remain in Microsoft 365. As the feature description now states: “No one in the organisation will be able to use Productivity Score to access data about how an individual user is using apps and services.”
The deeper problem: Beyond Productivity Score, Office 365 retains extensive monitoring capabilities through admin tools, compliance features, and audit logs. Privacy International noted “there seems to be a lack of transparency for users in terms of what data is collected and for what purpose.”
References:
- The Register: Microsoft 365 Axes Per-User Productivity Monitoring After Privacy Backlash
- GeekWire: Microsoft Will Remove User Names from Productivity Score After Privacy Backlash
- BankInfoSecurity: Microsoft Backpedals Over “Productivity Score” Monitoring
- Computer Weekly: Microsoft Office 365 Has Ability to “Spy” on Workers
- Privacy International: WFH — Watched from Home
- WinBuzzer: Microsoft’s New Workplace Tracking Tools Spark New Privacy Debate
5. Call Center AI Emotional Surveillance
AI systems now monitor call center workers in real time, scoring them on tone, empathy, pace, silence duration, and script adherence — then providing live “coaching” nudges during calls.
Cogito (now owned by Verint):
- An MIT spinoff that analyzes tone, pitch, word frequency, and hundreds of other vocal signals during live calls.
- When the system detects a problem — irritated customer, bored-sounding agent, too-long pause — it displays a real-time notification telling the agent to slow down, speed up, stop talking, start talking, or “try to sound more sympathetic.”
- Deployed across more than three dozen call centers in the U.S.
- Major clients include Humana and MetLife. MetLife used Cogito to detect customer frustration in real time.
- Verint acquired Cogito in October 2024.
Observe.AI: Uses AI to analyze 100% of customer interactions, scoring agent performance, detecting sentiment, and flagging compliance issues.
CallMiner: Analyzes all customer interactions across channels, providing detailed analytics on agent performance, customer sentiment, behavior, and emotion.
The emotional labor dimension: As The Outline reported, call center work is “basically 9-to-5 emotional labor” and these AI systems “claim to make that job easier — through monitoring, surveillance, and passive-aggressive reminders to perk up or calm down.” The technology doesn’t just track productivity — it scores how well workers perform emotions.
References:
- TIME: Cogito AI Software Coaches Customer Service Workers
- MIT News: Watch Your Tone — Startup Cogito Voice Analytics
- The Outline: This Software Encourages Call Center Workers to Do More Emotional Labor — Key article on the emotional surveillance angle
- Emerj: Artificial Intelligence at MetLife — Three Use Cases
- Verint/Cogito
- CX Today: Verint Acquires Cogito, Develops a Bot That Scores Live Customer Conversations
6. Legal Landscape
Federal (United States):
Electronic Communications Privacy Act (ECPA, 1986): Prohibits unauthorized interception of wire, oral, or electronic communications — but contains two enormous exceptions:
- Business purpose exception: Employers can monitor communications conducted on employer-owned equipment for legitimate business purposes.
- Consent exception: If the employee consents (which most employment agreements require), monitoring is broadly legal.
In practice, the ECPA provides minimal protection against workplace surveillance. It was written in 1986 and has not been meaningfully updated.
State laws (United States):
Only three states currently require employers to notify employees of electronic monitoring:
- Connecticut (Conn. Gen. Stat. Section 31-48d): Requires prior written notice of electronic monitoring of telephone, email, or internet usage.
- Delaware (Del. Code tit. 19, Section 705): Requires notice to employees upon hire that they will be monitored. No workplace posting requirement.
- New York (SB S2628, signed 2021): Requires private employers to provide written or electronic notice upon hire AND display the notice conspicuously in the workplace. Employers must also obtain employees’ acknowledgment of receipt.
All other states have no specific disclosure requirements for employee monitoring.
European Union:
GDPR Article 88: Permits EU member states to adopt supplementary rules for employee data processing, requiring “suitable and specific measures” to protect employees’ fundamental rights, with particular regard to transparency, intra-group data transfers, and workplace monitoring systems.
WP29 Opinion 2/2017 on Data Processing at Work: Issued by the Article 29 Working Party (June 8, 2017). Identifies key risks including:
- Chilling effects on confidential employee communications
- Incompatible further processing of employee data
- Unjustifiable and intrusive surveillance
- Obstruction of whistleblowing
- Provides safeguarding measures across 9 practical scenarios: recruitment, employment screening, ICT monitoring, time/attendance management, video monitoring, fleet vehicles, and international data transfers.
The EU framework is substantially more protective than U.S. law, requiring proportionality, transparency, and legitimate purpose for any workplace monitoring.
References:
- CurrentWare: US Employee Monitoring Laws — ECPA & State Compliance
- EmploymentLit: Victory for Workplace Privacy — New York Passes Electronic Monitoring Law
- National Workrights Institute: Electronic Monitoring in the Workplace
- Venable LLP: The Right and Wrong Ways to Electronically Monitor Employees
- Hunton: Article 29 Working Party Releases Opinion on Data Processing at Work
- Inside Privacy: WP29 Releases GDPR Guidance on Data Processing at Work
- Oxford Academic: The Role of Article 88 GDPR in Upholding Privacy in the Workplace
- IAPP: WP29 Releases Extensive Employee-Privacy Guidance
PART 2: SMART HOME / IoT SURVEILLANCE
7. Ring Doorbell / Police Partnerships
Scale of partnerships: Ring partnered with over 2,500 law enforcement agencies, over 570 fire departments, and 12 local government agencies (as of April 2023). This represents roughly 1 in every 10 police departments in the United States.
The “Request for Assistance” tool: Allowed police departments to post requests in Ring’s Neighbors app, asking community members within a specific geographic area to share Ring footage relevant to an investigation. Police could draw a geographic boundary and request footage from all Ring users in that area.
Warrantless footage sharing (2022): Amazon admitted that during the first six months of 2022, Ring provided footage to police 11 times without owner consent or a warrant, in cases involving what the company described as “danger of death or serious physical injury.” This admission — disclosed in a letter to Sen. Ed Markey — confirmed that Ring had a backdoor allowing warrantless access.
Data request volume: Amazon received more than 3,000 legal requests for Ring data in a single recent year. Users were notified in only about 650 cases — roughly 22%.
FTC enforcement (2023): The FTC required Ring to pay $5.8 million after finding that:
- Ring employees and hundreds of Ukraine-based contractors had unrestricted access to customers’ private videos, including footage from bedrooms and bathrooms.
- One employee viewed thousands of recordings of female users over several months, focusing on cameras in intimate spaces. He wasn’t stopped until another employee reported it.
- Ring failed to implement protections against credential stuffing and brute force attacks, resulting in over 55,000 accounts compromised between January 2019 and March 2020.
- Ring was ordered to establish a data security program with regular assessments for 20 years.
Policy changes (January 2024): Ring shut down the Request for Assistance tool. Police can no longer request footage through the Neighbors app. However, law enforcement can still obtain footage via search warrants and subpoenas. And by late 2025, Ring quietly rolled out a replacement program called Community Requests in partnership with Axon (the Taser/body camera company).
References:
- FTC: Ring, LLC — Case Page
- FTC: Not Home Alone — Ring’s Lax Practices Led to Disturbing Privacy Violations
- FTC: Ring Employees Illegally Surveilled Customers
- CNBC: Amazon’s Ring Will Stop Letting Police Request Doorbell Video Footage
- TechCrunch: Amazon’s Ring to Pay $5.8M After Staff Caught Snooping on Customer Videos
- Consumer Reports: Ring Ends Request for Assistance Tool
- Consumer Reports: Ring Community Requests Lets Police Ask for User Videos (Again)
- EFF: Ring Changed How Police Request Footage — What It Means
- EFF: The FTC Forces Ring to Take User Privacy Seriously
- The Markup: How We Investigated Ring’s Crime Alert System
- NPR: Amazon to Pay Over $30 Million to Settle Ring and Alexa Privacy Claims
- PBS: Ring Will No Longer Allow Police to Request Doorbell Camera Footage
8. Alexa / Smart Speaker Recordings
The “always listening” architecture: Smart speakers maintain an always-on microphone that listens for a wake word. Amazon says the device only begins recording and transmitting audio after detecting the wake word — but the local processing required to detect the wake word means the microphone is perpetually active, and false activations are well-documented.
Criminal cases where Alexa recordings were subpoenaed:
State of Arkansas v. James Andrew Bates (2016-2017): Victor Collins was found dead in James Bates’ hot tub in Bentonville, Arkansas (November 22, 2015). Prosecutors subpoenaed Amazon Echo data, believing the device may have captured audio relevant to the death. Amazon filed a motion to quash, arguing customer privacy and that recordings were protected under the First Amendment. Amazon ultimately released the data after the defendant consented. The charges were eventually dropped.
New Hampshire double murder (2017): Christine Sullivan and Jenna Pellegrini were found stabbed to death in a home in Farmington, New Hampshire. An Amazon Echo was at the crime scene. A judge ordered Amazon to turn over two days of recordings, believing the device may have captured audio related to the attack.
Government data requests: Amazon says it receives fewer than 500 search warrants annually for Echo stored data and complies with fewer than half. Amazon has stated it has “repeatedly challenged government demands for customer information that we believed were overbroad.” The total $30M+ FTC settlement in 2023 also covered Alexa data practices.
References:
- ABA Journal: Amazon Releases Smart Speaker Data to Court
- Northern Kentucky Law Review: Is Your Smart Speaker a Snitch?
- Washington Journal of Law, Technology & Arts: Alexa — Are You Going to Testify Against Me?
- Texas Bar: Alexa, Testify
- Criminal Defense Lawyer: Can Smart Devices Be Used as Criminal Evidence?
- NPR: Amazon to Pay Over $30 Million to Settle Alexa and Ring Privacy Claims
9. Smart TV Data Collection
Automatic Content Recognition (ACR): The core surveillance technology in modern smart TVs. ACR identifies what you’re watching — across apps, cable, streaming, and even external devices — and transmits that data to the manufacturer and/or third-party data brokers. It captures everything displayed on screen, including security camera feeds, personal photo slideshows, and content cast from phones.
Vizio:
- FTC Settlement (February 2017): $2.2 million fine for installing software on 11 million smart TVs that collected viewing data without consent, starting in 2014. Vizio even retroactively installed tracking software on older models via remote update. The system captured as many as 100 billion data points per day and sold viewing histories to advertisers.
- Class Action Settlement: Separate $17 million settlement covering ~16 million Vizio Smart TV users who connected to the internet between February 2014 and February 2017.
Samsung (2015):
- Samsung’s Smart TV privacy policy warned users: “Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party.” The “third party” was Nuance Communications, processing voice commands.
- EPIC filed a formal FTC complaint (February 24, 2015) regarding Samsung’s “deceptive and unfair trade practices.”
- Samsung later clarified the policy but the damage to public trust was done.
LG:
- Uses ACR through its Live Plus feature, partnering with Alphonso (advertising technology company) to manage ACR data.
- LG’s privacy policy explicitly states that viewing history “may be sold or shared with third parties.”
- A configuration file analysis showed a sample rate of 48 kHz, raising questions about what data beyond viewing habits is being captured.
Industry-wide enforcement (2024-2025):
- In December 2025, Texas Attorney General Ken Paxton filed lawsuits against Samsung, Sony, LG, TCL, and Hisense for unlawfully collecting and monetizing consumer viewing data through ACR technology; the filing put the capture rate at LG every 10 milliseconds and Samsung every 500. Samsung settled in February 2026 (agreeing to consent screens for Texas residents); the suits against the other four continue.
- Per the Texas AG’s complaint, TCL and Hisense data is subject to China’s National Security Law, which can compel companies to share data with the Chinese government.
- Roku’s ACR system (“Smart TV Experience”) required 11 to 24 clicks to disable.
References:
- FTC: VIZIO to Pay $2.2 Million — Collected Viewing Histories on 11 Million TVs Without Consent
- FTC: What Vizio Was Doing Behind the TV Screen
- Hunton: Vizio Agrees to $17M Settlement
- CNN Money: Your Samsung TV Is Eavesdropping on Your Private Conversations
- EPIC: Samsung SmartTV Complaint
- The Markup: Your Smart TV Knows What You’re Watching
- SecurityWeek: Smart TV Surveillance — Samsung and LG’s ACR Technology
- Consumer Reports: How to Turn Off Smart TV Snooping Features
- IAPP: Automated Content Recognition Technology Takes Privacy Enforcement Spotlight
- UCL News: Smart TV Tracking Raises Privacy Concerns — Academic research
10. Connected Car Surveillance
Mozilla Foundation “Privacy Not Included” (September 2023): All 25 car brands reviewed earned the privacy warning label, making cars “the worst category of products we have ever reviewed for privacy.”
What cars collect: GPS location (continuous), driving behavior (speed, braking, acceleration, steering), voice recordings from in-car microphones, passenger weight/seatbelt data, and — per manufacturers’ own privacy policies — data categories as invasive as “sexual activity,” “facial expressions,” and “genetic and health information.”
GM / LexisNexis scandal: General Motors (Chevrolet, Buick, GMC, Cadillac) sold personal driving data collected through OnStar to data brokers LexisNexis and Verisk, who used it to create driver “risk scores” sold to insurance companies. Drivers only discovered this when their insurance premiums increased. GM later said it would stop selling “some” OnStar data to these brokers (Edmunds; the story was broken by Kashmir Hill at the New York Times, March 2024).
Volkswagen data breach (December 2024): Precise location data for approximately 800,000 vehicles was left exposed online (a Cariad/AWS misconfiguration, discovered by the Chaos Computer Club, first reported by Der Spiegel) — extensive data collection also creates a massive breach target (TechCrunch).
References:
- Mozilla Foundation: It’s Official — Cars Are the Worst Product Category for Privacy
- Mozilla Foundation: Privacy Nightmare on Wheels — Every Car Brand Flunks Privacy Test
- Mozilla Foundation: Cars — Privacy & Security Guide
- Mozilla Foundation: Car Companies — Stop Your Huge Data Collection Programs
- The Register: Mozilla Flunks 25 Major Car Brands for Data Privacy Fails
- CNBC: How Automakers Ran Afoul of Privacy Advocates
11. IoT Security Failures
The same devices that create consumer surveillance infrastructure also create an enormous attack surface.
The Mirai Botnet (2016):
- First discovered August 2016 by MalwareMustDie.
- Exploited default usernames and passwords on IoT devices (IP cameras, home routers, DVRs, baby monitors) using a list of just 64 known default credentials.
- At peak, infected over 600,000 IoT devices.
- Launched the largest DDoS attacks on public record at the time:
- September 2016: Attack on journalist Brian Krebs’ website.
- September 2016: Attack on French web host OVH, exceeding 1 Tbps.
- October 2016: Attack on DNS provider Dyn, which took down Twitter, Netflix, Reddit, GitHub, Spotify, and other major services across the eastern U.S.
- Demonstrated that cheap IoT devices with no security updates constitute a weaponizable surveillance infrastructure.
Baby monitor hacking: Documented incidents of hackers speaking to children through compromised baby monitors. Rapid7 conducted formal IoT baby monitor security research documenting widespread vulnerabilities. Devices ship with default credentials and no mandatory firmware updates.
Smart lock vulnerabilities:
- DEF CON 24 (2016): Security researcher Anthony Rose tested 16 Bluetooth-enabled smart locks and found 12 of 16 (75%) had no security or poorly enabled security.
- August Smart Locks (2017): Researchers demonstrated Bluetooth replay and relay attacks; older firmware lacked anti-replay protections.
- Schlage: Weak Zigbee/Z-Wave implementations permitted command injection or replay attacks.
- UltraLoq: Attackers could steal “unlock tokens” in bulk knowing only the MAC address.
- Master Lock: Replay attacks enabled unauthenticated unlocking; former guests could continue unlocking after access should have expired.
The fundamental problem: IoT devices are built for convenience over security. There is no cost to the user when their device is compromised (it continues to function), so there is no incentive to secure it. Most owners lack the technical knowledge to update firmware or change default credentials.
References:
- Cloudflare: What Is the Mirai Botnet?
- Cloudflare Blog: Inside Mirai — A Retrospective Analysis
- Wikipedia: Mirai (malware)
- CISA: Heightened DDoS Threat Posed by Mirai and Other Botnets
- CIS: The Mirai Botnet — Threats and Mitigations
- Rapid7: IoT Baby Monitor Security Research
- USENIX: No Key, No Problem — Vulnerabilities in Master Lock Smart Locks
- ResearchGate: Smart-Locks Cybersecurity and Vulnerabilities (PDF)
12. The Aggregate Surveillance Picture
When you combine smart speakers, smart TVs, Ring doorbells, connected cars, smart thermostats, and fitness trackers in a single household, the result is ambient surveillance — a comprehensive behavioral profile assembled from dozens of data streams that no single device could produce alone.
Princeton IoT Inspector:
- Developed by Princeton’s Center for Information Technology Policy (CITP), launched 2018.
- An open-source tool that monitors network traffic from all IoT devices on a home network using ARP spoofing.
- Collects DNS requests, destination IP addresses, TLS handshakes, traffic statistics, and device manufacturer information.
- Key finding: Third-party services used by IoT devices enable data aggregation across devices. A single third party (e.g., an advertising SDK or analytics service) embedded in multiple device types can track user behavior across smart speakers, TVs, doorbells, and thermostats — creating a unified behavioral profile the consumer never consented to.
- The project produced an open-source, anonymized dataset of IoT network traffic for academic research.
- Now maintained at NYU: nyu.edu
The aggregation problem: No consumer opts into “ambient surveillance.” They buy a doorbell camera for package theft, a smart speaker for convenience, a smart TV for streaming. Each device’s privacy policy is assessed in isolation. But the aggregate data picture — when is someone home, what do they watch, what do they say, who visits, when do they sleep, how do they drive — constitutes a level of behavioral surveillance that would have required a dedicated intelligence operation a generation ago.
References:
- Princeton CITP Blog: Announcing IoT Inspector
- NYU IoT Inspector
- TechCrunch: Spy on Your Smart Home with This Open Source Research Tool
- Schneier on Security: IoT Inspector Tool from Princeton
- Digital Trends: Use This Tool to See Where Your Smart Home Devices Are Sending Data
- Gizmodo: This Simple Tool Will Reveal the Secret Life of Your Smart Home
Cross-Cutting Themes
Consent theater. Terms of service and privacy policies serve as legal cover for surveillance, not meaningful informed consent. Roku requires 11-24 clicks to disable ACR. Most bossware can be installed silently.
The ECPA gap. U.S. federal law governing electronic surveillance was written in 1986. Only three states require employers to even disclose monitoring. The EU is decades ahead via GDPR.
Algorithmic management as control. Amazon’s TOT system, Uber’s personalized pricing, and call center emotion scoring all use the same pattern: granular real-time data collection feeding automated decision-making that controls human behavior — hiring, firing, pay, discipline — with minimal or no human review.
Surveillance infrastructure as attack surface. The Mirai botnet proved that devices collecting data on consumers are also exploitable weapons. Ring’s 55,000 compromised accounts showed the same. The data collected “for your convenience” becomes a liability when (not if) it’s breached.
The aggregation ratchet. Each new connected device adds a data stream. No single device seems dangerous. The aggregate picture is total.