← Latest papers
💻 computer science

"Am I Just That Dumb?": Applicability, Action and Verification in Consumer IoT Security Advice

This study evaluates the applicability, actionability, and verifiability of government-issued consumer IoT security advice in the Netherlands, revealing significant gaps between generic guidance and the actual capabilities of best-selling devices, which often lack shared default credentials and clear update mechanisms, thereby hindering users' ability to effectively secure their devices.

Original authors: Veerle van Harten, Carlos Hernández Gañán, Michel van Eeten, Simon Parkin

Published 2026-08-27
📖 5 min read🧠 Deep dive

Original authors: Veerle van Harten, Carlos Hernández Gañán, Michel van Eeten, Simon Parkin

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the modern home, a quiet revolution has taken place. Everyday objects—from smart speakers and doorbells to kitchen appliances and light bulbs—have been connected to the internet, creating a network of devices that can be controlled remotely. This convenience, however, comes with a hidden cost: security. Just as a physical house needs a lock on the front door, these digital devices need protection against intruders who might try to take control of them. For years, governments and security experts have offered a simple, two-part solution to keep these homes safe: change the default password that comes with the device, and keep the device's software updated. The assumption behind this advice is that anyone can follow these instructions, find the right settings on their specific gadget, and verify that they have done so. But this assumption relies on a belief that the advice fits every device perfectly, and that the path to security is clear and visible to the average person.

A team of researchers at Delft University of Technology in the Netherlands decided to test whether this simple advice actually works in the real world. They did not ask people what they thought they would do; they watched them do it. The researchers recruited twenty-eight volunteers and gave them a specific challenge. Each person was handed a printed card containing the standard government advice to change default passwords and check for updates. They were then asked to try to follow this advice on three different smart home devices selected from the top-selling lists of a major online retailer. The devices included a smart plug, a humidity sensor, a doorbell chime, a smart speaker, a printer, and an indoor security camera. The participants were told to imagine they owned these devices and were trying to secure them, but they were not allowed to actually change the settings or install updates, only to show where they would go to do so. This allowed the researchers to see exactly where the instructions led and where they got stuck, without altering the devices' actual state.

The results revealed a significant gap between the advice given and the reality of the devices. When the participants tried to change the default password, they faced a confusing maze. In thirty-three out of eighty-four attempts, they could not find any password setting at all. In fifty attempts, they found a place to change a password, but it was for an online account linked to the device, not for the device itself. Only one session actually reached the specific setting on the device hardware where a default password would be changed. The researchers discovered that none of the six popular devices they tested actually had the kind of shared, factory-set password that the advice described. Instead, some devices had unique passwords for each unit, while others had no default password at all, requiring the owner to create one from scratch. Because the advice did not explain how to tell the difference, participants often felt they had succeeded when they had actually changed the wrong thing, such as their account login, leaving the device itself vulnerable.

The situation was similar when participants tried to update the software. In twenty-seven sessions, they could not find any update option. In nineteen sessions, they found an update, but it was for the companion app on their phone, not for the device's internal software. Only thirty-eight sessions successfully reached the actual firmware update status for the device. The researchers found that the language used in the advice and the labels on the devices often did not match. Terms like "firmware" were unfamiliar to many users, who hesitated to click on them for fear of breaking something. On some devices, the update information was hidden deep in menus, while on others, it was clearly displayed. The confusion was so profound that in several cases, participants concluded they had followed the advice perfectly, even though they had not actually secured the device. One participant, frustrated by the difficulty, asked the researchers, "Am I just that dumb?" The researchers' answer was clear: the problem was not the user's intelligence, but the mismatch between the generic instructions and the specific, often hidden, design of the devices.

The study showed that the current approach to security advice is flawed because it assumes all devices work the same way. When a user is told to "change the default password," they have no way of knowing if their device even has one, or if the setting they find is the correct one. The researchers found that users naturally followed the most obvious path, which often led them to change their account password instead of the device's. This gave them a false sense of security, a feeling that they had done the job when the device remained unprotected. The evidence suggests that simply telling people to be more careful or to read the instructions is not enough. The advice itself needs to change to help users determine if the action is even necessary for their specific device, and the devices need to be designed so that the security settings are visible and easy to understand. Until the gap between the advice and the technology is closed, users will continue to struggle, not because they are incapable, but because the path to safety is obscured by a design that does not speak their language.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →