A security researcher in Michigan discovered something unsettling last month: her video doorbell had been streaming footage to an IP address in Eastern Europe for eleven days.
She only noticed because her Wi-Fi bill spiked.
The manufacturer's app showed everything as normal.
A wave of consumer-grade breaches has hit American homes over the past eighteen months, and the pattern is always the same.
Cheap chips, rushed firmware, and a support team that vanishes the moment you need them.
The latest wave centers on the "internet of things" — the estimated 1.7 billion connected gadgets sitting in US households.
Baby monitors, robot vacuums, smart thermostats, even connected light bulbs.
Each one is a tiny computer with a network connection and, often, the security of a paper bag.
What makes this different from the corporate hacks you read about is the intimacy.
When a retailer loses your credit card, you get a new card.
When your nursery camera gets hijacked, someone has watched your kid sleep.
Security firms tracking these incidents say the majority of compromised devices share three traits: default passwords never changed, firmware that has not been updated in over a year, and companion apps that request permissions they have no business requesting.
These gadgets sell for $25 to $60, and manufacturers compete almost entirely on price.
So does hiring engineers to patch vulnerabilities after launch.
The result is a market where the cheapest device often wins, and the buyer absorbs the risk without knowing it.
There is also a quieter problem: many of these devices phone home to servers the manufacturer does not fully control.
A 2023 study of popular smart home gear found that nearly a third of devices sent data to third-party analytics firms the user never agreed to.
Some of those firms then resold the data.
Your living room habits became someone's product.
If your router lets you create a separate guest network, put every smart device on it.
That way, a compromised doorbell cannot reach your laptop.
Change every default password the moment you unbox something.
If a device has not received a firmware update in a year, treat it as compromised and replace it.
And check your router's connected-device list once a month — you will be surprised what is on there.
The uncomfortable truth is that convenience and security are pulling in opposite directions, and most Americans are voting for convenience without realizing there is a vote.
The industry will not fix this on its own.
The only real pressure comes from buyers who ask hard questions before they tap "add to cart." Treat every connected gadget like a stranger you are inviting into your home, because that is exactly what it is.
If a company cannot tell you how it secures its devices, it does not deserve your money.
Final Thoughts
The breach you prevent is the one you never hear about.