Skip to content, sitemap or skip to search.

Personal tools
Join now
You are here: Home Blogs Community The hidden cost of today's "smart" devices

The hidden cost of today's "smart" devices

by seano Contributions Published on Aug 24, 2026 01:54 PM
A simple house with an eye over it with a Bluetooth symbol in the pupil of the eye
Google uses "smart" devices to watch and control you.

The closer computers get to our bodies and homes, the less control we seem to have over them. "Wearable" devices are sold as personal technology, but they rarely belong to the people who purchase them in any meaningful sense. We have brought attention to these devices in our Fight to Repair campaign, emphasizing that owners usually aren't allowed to inspect them, repair them, or change how they behave. Though it is sometimes possible to modify the nonfree software they run, users can't share the modified versions without facing legal risks. This is a clear example of a broader problem: technology that is physically close to us, yet still out of our hands.

"Fast Pair" equals fast insecurity

Audio headsets that connect to computers wirelessly via Bluetooth demonstrate how quickly this loss of control turns into a security problem. Millions of Bluetooth-capable products utilize Google's "Fast Pair" service, which is nonfree software that promises to make pairing of wearable devices easier. It uses Bluetooth Low Energy and Android’s location services to detect nearby Bluetooth devices automatically and prompts you to pair. Security researchers discovered this feature was really a bug, as it introduced a serious weakness across a wide range of devices. This included wireless earbuds and headphones from major manufacturers, which could be turned into surveillance machines. Attackers could silently pair with these devices and hijack the audio to spy on the person wearing them, as well as anyone they spoke to. In some cases, the microphone could be activated and the wearer could be tracked through Google's own network.

What makes this so troubling is that researchers did not have access to the source code needed to inspect how Fast Pair worked. Instead, discovering the flaws required independent researchers to reverse engineer the nonfree software. This difficult and time-consuming process would not have been necessary if the software were free and available for anyone to study and improve.

The problem was not confined to one device model or a single vendor, and it is likely that many devices around the world are still vulnerable. Worse, most users will be unable to patch their device without utilizing nonfree software from the manufacturer or Google to run an update. Instead of giving users the freedom to modify and improve, they are forced to trust nonfree software that cannot be easily inspected.

Due to issues with "Fast Pair" security and Bluetooth privacy concerns in general, the Federal Communications Commission now recommends turning Bluetooth off when not in use and avoiding unnecessary pairing. Google is not the only Big Tech company creating vulnerabilities for people who use its products. Just recently, Apple released an update to the nonfree firmware in its Beats Studio Buds headphones which plugged a hole that allowed attackers to record conversations via the microphones. Though Apple patched this issue, it's clear that such flaws are a symptom of a wider problem and not confined to one specific device or manufacturer. When users cannot inspect or modify the software running on their devices, they depend on corporations to discover problems, provide fixes, and continue supporting the products they paid for but don't have full control over.

Google spying on your nest with Nest

The same problem is demonstrated by Google's Nest products, a series of home thermostats, doorbells, cameras, and alarm systems that are connected to Google's network. Although the Nest brand continues, Google has ended support for certain products and older generations of Nest hardware. These devices are marketed as helpful and convenient, but their usefulness and safety depends on the vendor's nonfree software. When Google ends support for a Nest product, the device may stop receiving software updates, in addition to becoming useless for its intended purpose.

In the case of the discontinued "Nest Secure" home alarm system, these devices became unusable when Google's support ended, turning expensive hardware into expensive paperweights. Support for several older Nest thermostat models has also been discontinued, leaving homeowners with devices affixed to their walls that will, as Google puts it, "no longer receive software or security updates, which may lead to decreased performance with continued use." That is exactly the kind of failure that can be prevented by free software and the right to repair.

Fortunately for users of Nest devices, hackers have been able to analyze and update Google's nonfree software and publish their update methods as part of a project called "No Longer Evil." These modifications are intended to provide the security for Nest users that Google fails to provide, but they have also revealed disturbing surveillance practices baked into Nest devices. Though Google disabled the capability to provide updates to Nest devices that the company no longer supports, they notably did not turn off logging of information about the owners and their homes. Nest devices, even those that are no longer supported by Google, phone home with data about manual temperature changes, amount of sunlight, and the presence of people in the room. These data points can be aggregated to build detailed profiles on household habits and lifestyles.

Google may have stopped maintaining these devices for their owners, but the devices continue to serve Google's interests by transmitting information about the people and homes around them. The hackers behind "No Longer Evil" were able to disable this privacy-invasive logging, proving once again the vital importance of giving users the freedom to study and modify the software running in their own homes.

Thankfully, there are communities of researchers and hackers willing to risk legal action and spend their time and energy making unsafe, nonfree systems less dangerous. But a small number of hacktivists should not have to carry the burden of correcting the consequences of privacy-invasive corporate decisions. Manufacturers earn money from selling this hardware, controlling the software, and collecting information from their users. Companies should not be allowed to abandon their responsibility to maintain these systems by preventing users from taking control.

Wearable and home devices should not require advanced technical skills to discover and fix security and privacy threats, especially when the companies responsible for the software have the resources to address those problems themselves. In the examples above, independent researchers had to compensate for manufacturers who restricted access to source code, retained control over updates, and decided when purchased hardware would stop receiving support. In the case of Nest, Google stopped providing security updates to certain devices while those devices continued transmitting information about their owners and their homes.

Users deserve devices they can inspect, repair, and improve themselves, not products that remain under a manufacturer's control long after purchase. When software is nonfree, owners remain dependent on vendors for security updates, application support, and even basic functionality, while those companies remain able to change the rules, collect your sensitive data, or withdraw support entirely. This is why free software and the right to repair are inextricably tied together. It's also why privacy and security will continue to be part of our campaigns. When a thermostat can quietly collect data on users after support ends and report it back to the vendor, or when a headset can become an eavesdropping device for criminals, the problem is not the user's carelessness — it is the lack of software freedom.

If you're using devices or accessories with optional Bluetooth capabilities, keep the Blueooth setting off unless you're using it. A bigger step if you interact with Google through its products or disservices: disinvest. If you've already cut Google out of your life, educate others about how harmful Google is.

This work, "Bluetooth surveillance," is adapted from "Bluetooth Figure Mark Logo" © by Bluetooth SIG, dedicated to the public domain under a Creative Commons CC0 No Rights Reserved license; "Eye outline Pinhead icon" © by Quincylvania, dedicated to the public domain under a Creative Commons CC0 No Rights Reserved license; and "OpenClipArt House 1" © by Cdang, dedicated to the public domain under a Creative Commons CC0 No Rights Reserved license. "Bluetooth surveillance" © 2026 Free Software Foundation, Inc., by Eko K. A. Owen is licensed under a Creative Commons Attribution 4.0 International license.

Document Actions

The FSF is a charity with a worldwide mission to advance software freedom — learn about our history and work.

fsf.org is powered by: