Skip to content

Automatic translation from Russian to English. It may contain inaccuracies.

Essay

Does a smart home with Alice transmit data to intelligence agencies?

This article appeared as a kind of response to the hysteria around the security of the personal Internet of things and the concept of the “Smart Home” in particular. Scrolling through the comments under many videos and articles on the topics of voice assistants, automation, smart speakers, cameras, sensors, sockets and other similar technologies, I repeatedly came across statements about intruders, wiretapping of conversations by various services, total surveillance and the fact that now literally every device in the apartment is a potential employee in uniform

May 24, 202625 min readOriginal on siteSmart home PIoT Internet of Things security
Безопасность умного дома

Hi all!

This article appeared as a kind of response to the hysteria around the security of the personal Internet of things and the concept of the “Smart Home” in particular. Scrolling through the comments under many videos and articles on the topics of voice assistants, automation, smart speakers, cameras, sensors, sockets and other similar technologies, I repeatedly came across statements about intruders, wiretapping of conversations by various services, total surveillance and the fact that now literally every device in the apartment is a potential employee in uniform. In one of my posts on Telegram, I already touched on this issue, but, unfortunately, the limit on the number of characters does not allow me to turn around and consider this topic more comprehensively. Therefore, I decided that I would still act as the “devil’s advocate” and try to disassemble as much as possible into parts everything that bothers people in the context of the “Smart Home” and user technologies. I’ll say right away that I’m not going to prove that smart devices are absolutely safe, manufacturers are always white and fluffy, and users come up with all sorts of conspiracy theories for themselves. This is not entirely true. More precisely, this is a half-truth, and, as we know, it is worse than a lie. Devices do get hacked, data leaks, and manufacturers sometimes treat security as if it were not a basic feature of the product, but something completely optional (but at a lot of cost). But it’s one thing to talk about real risks, and another thing to turn any conversation about a smart speaker into a discussion of how at night it transfers all your conversations to the right place and at the same time, apparently, creates a psychological portrait of each member of your family

Hacking "Smart Home"

Взлом

Let's start with the security of modern Smart Homes in the context of hacker attacks. If you dig around the web, you can find a huge number of references to hacking of smart devices. And in fact this is true; it’s hard to argue with statistics. You can remember, for example, the botnet Mirai, which in 2016 massively infected IoT devices, including cameras and video recorders, using standard and weak passwords, after which these devices were used for DDoS attacks. Here is a very real example of what happens when a huge number of devices access the Internet with passwords of the admin/admin level or something like that (I already [mentioned] about it once ( https://notes-knyazev.ru/posts/195 ). You can also recall the story of Ring, an Amazon company that produced smart doorbells and cameras. US Federal Trade Commission Blames Ring is that the company did not provide sufficient protection for users' private videos, and employees and contractors could access the recordings, while weak security measures allowed attackers to seize user accounts, cameras and videos. As a result, Ring agreed to a settlement, and customers were even paid compensation in this case. In fact, my old subscribers know that it’s enough to simply provide a link to my Telegram channel, because I have already analyzed many of these cases (and continue to analyze them, because many people and organizations do not like to learn from mistakes). And here it is important to understand that in information security very often the most unpleasant stories begin not with some brilliant hack, but with the fact that someone configured something incorrectly, overlooked it, etc.

I don't want to go into denial of the obvious. Yes, device manufacturers and developers do not always take user safety into account. And I’m not going to defend this negligence. It is because of such manufacturers that the well-known thesis that the “S” in IoT stands for security (that is, it doesn’t seem to be there) has stuck to the IoT. But believe me, everything has its time, and sooner or later the market will change, because many corporations, alas, begin to think about security only when an incident occurs, a regulator comes, a scandal begins, or there is a risk of losing money, clients and reputation. Security is very expensive, and calculating the actual money saved on potential incidents, reputational risks, etc. is incredibly difficult (I state this officially as a security professional). It is much easier for a business to show a new feature of a device than to show that nothing bad happened precisely because they invested in security in advance. The work of the security guards is never visible until some incident occurs (which means that the security guards missed something). In other words, the good work of information security specialists in theory cannot be noticed at all. Only bad work catches your eye. And what follows from this is that no one wants to pay money “for unknown reasons.” But when a catastrophe happens, no one spares them to ensure that this does not happen again. This is the world we live in

Now security is built proactively mainly where it is required by the state itself, a large customer or an industry. Conventionally, when a solution needs to be sold to a bank, CII or something that directly affects the stability of the economy, the safety of citizens, the continuity of important processes, and so on, the legislation begins to require that this solution, hardware or software, meet certain security requirements (have a FSTEC certificate, etc.). As you might guess, this has almost nothing to do with PIoT, because in my practice I have not seen smart speakers anywhere on production lines or in the offices of employees of various services (although I conducted audits there and saw a lot of different things). Regarding IIoT or automated process control systems, everything naturally looks different, but now we are not talking about them, but about the personal Internet of things, the devices of which people buy for their home in order to turn on the lighting with their voice, control sockets, run a vacuum cleaner and, in general, make daily life a little more convenient and comfortable. And at the moment, at least in Russia, there are no obligations regarding the safety of such devices in the strict form we are accustomed to. To be fair, this does not exist in the vast majority of countries in the world in the form that security officials would like. Yes, there is 152-FZ “On Personal Data”, but it relates to the processing of personal data, and not to the security of a conventional smart light bulb, camera or socket as a device

At the same time, it cannot be said that nothing is happening in this direction in the world. In the same UK, the [Product Security and Telecommunications Infrastructure] regime has been in effect since 2024 (https://www.gov.uk/government/publications/the-uk-product-security-and-telecommunications-infrastructure-product-security-regime), where basic requirements for consumer connected devices include a ban on universal standard passwords, a mechanism for reporting vulnerabilities, and transparency on support periods. Voluntary labeling is actively developing in the United States U.S. Cyber Trust Mark for consumer IoT devices, so that the buyer has at least a rough idea that the device meets certain cybersecurity requirements. Europe has adopted the Cyber Resilience Act, which should set minimum requirements for the cybersecurity of products with digital elements (including connected devices and software), and the German BSI directly writes that this is the first standard in Europe that sets a minimum level of cybersecurity for connected products in the EU market. There are also technical standards, for example ETSI EN 303 645, which addresses the problem of universal standard logins and passwords (like admin/admin) and proposes forcing the user to set a password when setting up the device for the first time. In other words, there is movement, it’s just very uneven. In fact, the market is maturing, but not everywhere. Somewhere the regulator carefully tightens the screws, somewhere the manufacturers themselves understand that safety becomes part of the trust in the brand. Well, somewhere it is still believed that if the device turns on and the application opens, then the mission is completed, and let the user do the rest (whether he can do it or not)

But we should not forget that saving drowning people is the work of the drowning people themselves. What do you think, if the car manufacturer put locks on your car, but you didn’t lock it and went out on business, and then came to the place and found that your car was no longer there, who is to blame for the fact that your car was stolen? Manufacturer or yourself? Yes, I'm being a little hyperbolic, but the point here is quite simple. The manufacturer and developer can add a lot of device protection mechanisms, but if the user himself does literally everything to get hacked, this will not help him. If your password was brute-forced because you set it to qwerty123 or did not change the factory password at all, the responsibility largely lies with you. Because the manufacturer gave you the opportunity to set a normal password, but you did not take advantage of it. And after this, we hear about cases where smart cameras, routers, video recorders and other devices en masse become part of botnets or are used by attackers simply because the user left standard credentials or has not updated the device for years. The aforementioned Mirai is an example of this.

If you're nervous about using personal IoT devices, just think about what you can do to make them safer. Separate your network, change default passwords, enable two-factor authentication where available, and update firmware. Roskachestvo back in 2020 recommended if possible, place IoT devices on a separate network so that if one device is compromised, the attacker does not gain access to everything else. It is clear that not every user will (and can) configure a VLAN, write firewall rules and build a miniature SOC at home (although if sooner or later I completely go crazy, I’ll do it for myself). But basic things can be done. You can change your password. You can update the firmware. You can also check who has access to the cameras and smart home application. If you yourself are doing everything to get hacked, then this is literally the same as drinking beer every day and then complaining about doctors who are no longer able to cure your liver. No matter how much you would like to shift the responsibility onto someone else, preventive measures will always fall on you, too.

At the same time, I specifically say “including” because it is wrong to completely shift responsibility to the user. The user does not have to be an information security specialist. A normal product should be safe by default. Well, it shouldn’t be that the user needs to read 40 pages of instructions, find a hidden item in the application, turn on three incomprehensible checkboxes, go to the forum and reflash the device, and then it will become safe. Well, no. The user is not required to read traffic dumps of his air conditioner with a Wi-Fi module. Manufacturers should first of all take care of the safety of devices. But users should not neglect it. Here’s a simple social contract that, oddly enough, not everyone has mastered yet

"Alice, don't leak my data to the government"

Прослушка

Now it’s worth talking about espionage, Big Brother and the fact that the smart speaker listens to you and transmits all your conversations to different services. I have nothing to do with Yandex, Alice, Siri, Alexa, Google Assistant, etc. I didn’t hold a candle, but something tells me (and there were enough cases) that almost anything that has a microphone, camera, sensors and network access can listen, analyze, record and process us in one form or another. But it is still important to separate several things here. It's one thing for a device to technically be able to access audio. Another thing is that it can locally wait for a command to activate. And some of the records can go to the cloud to process the request, and some fragments can be used to improve the quality of recognition. Company employees or contractors in some cases could (and still can) actually gain access to such fragments. But it does not follow from this that a separate person in uniform sits next to each speaker and waits for you, between requests to change the channel on your smart TV, to say something particularly offensive (in their opinion) about the president or the political system

There really have been stories with voice assistants. In 2019, The Guardian wrote that Apple contractors could listen to fragments of Siri recordings as part of assessing the quality of the assistant’s work, and confidential conversations could be found among the recordings, and after publication, Apple suspended this practice of evaluating recordings by contractors. That same year, Google admitted that contractors could listen to Google Assistant recordings, and the story surfaced after part of the recordings were leaked. With Alexa there was a similar story when Amazon employees listened to recordings from smart speakers to improve the service. That is, people’s fears are not taken out of nowhere. The problem is not this, but the fact that the wrong conclusion is often drawn from real cases. The correct conclusion is that voice services require very careful handling of privacy, user consent, data storage, employee access and transparency. The wrong conclusion is that any speaker transmits all your conversations to the intelligence services around the clock. Well, think for yourself what power is needed to collect and analyze information for each smart home user around the clock. Although, why think? Let's count

Fascinating mathematics of wiretapping

Математика

First, we need to at least roughly understand how many devices we are talking about. According to open data Yandex, in 2025 the number of active devices on the YaOS and YaOS X platforms exceeded 5.3 million. These are not only smart speakers in their pure form, but also devices with Alice inside (TV stations are the same), but this is enough for us to assess the scale, because we are not counting specific people, but potential home devices that could theoretically stand next to the user and listen to something. If we additionally take market estimates for sales of smart speakers, where about 80% of the market was accounted for by Alice, about 7% by Marusya and about 5% by Salyut, then domestic assistants in total will account for approximately 92% of the market for such devices. If we very roughly estimate 5.3 million active Yandex devices as 80% of the market, then the entire Russian smart home market can be estimated at approximately 6.1 million active devices. Once again, this is not the exact number of users, because one person can have two speakers (hello), and at the same time the whole family can use one column, but for our calculations this is even better, because we are interested in the sheer number of devices that, in theory, should transmit user conversations somewhere further around the clock

Now let's take the audio itself. For speech recognition, audio with a sampling rate of 16 kHz and 16 bits is often used because this is usually sufficient for human speech. IBM in their documentation gives an example that 16 kHz and 16 bit audio gives a bitrate of 256 kbps, and Google for speech recognition recommends using a frequency of at least 16 kHz and formats like FLAC or LINEAR16. In terms of conversion, this is approximately 32 KB per second or 1.92 MB per minute per device if we store the message without compression. For the frequency of the experiment, we will correctly consider the option with compression. Let it be Opus. For audio, you can take a conventional 24 kbit/s, that is, approximately 0.18 MB per minute. I'd say this is a pretty economical scenario.

If we have 6.1 million devices and each of them writes audio 24/7 (as some commentators claim), then we get 6.1 million × 1440 minutes per day, that is, approximately 8.78 billion minutes of audio per day. That's about 263.5 billion minutes of audio per month. In its raw form, this is about 506 PB (petabytes) of data per month. In the compressed Opus 24 kbps version, this is about 47.4 PB of data per month. And this is only data storage without taking into account recognition, analysis, search, copies, etc. Just received and added audio files to disk

Let's move on. People who are far from IT believe that they can just install some kind of server, receive information from a speaker and just listen to what people are discussing at home. No, that's not how it works. If someone seriously claims that millions of home speakers transmit all conversations around the clock to a single center, where it is stored, recognized, analyzed and then used, then it is not only speech recognition that needs to be considered. You need to consider storage, backup, replication, indexes, metadata, communication channels, computation for recognition, operation, personnel, security of the infrastructure itself, monitoring, logs, access control, incident investigation, hardware purchases, data centers and everything else that usually turns out to be not free (yes, even for a state that prints money)

For a more realistic assessment, let’s take not just one month of storage, but 6 months of storage, 3 copies of data and 30% on top of all kinds of metadata + reserve. This is not an overestimate at all, but more than moderate calculations for a system that should be fault-tolerant, centralized and suitable for our task (store and then analyze all people’s voice recordings). In this case, uncompressed audio will require about 11.8 exabytes of stored data, and compressed Opus will require about 1.1 exabytes. I'll just say that this is crazy much. Personally, I can hardly imagine such values

Now let's talk about money. According to price Yandex Object Storage standard storage costs $0.0389508134 per 1 GB per month excluding VAT. If we calculate at this price, then storing uncompressed audio with a 6-month period, 3 copies and a reserve will cost approximately $461 million per month, that is, about 394 billion rubles per year at the rate of 71.2 rubles per dollar. For compressed Opus, this will be approximately $43 million per month, that is, about 37 billion rubles per year. And that's just storage. Without recognition, analysis, people and security. That is, it’s not even a system, it’s just a dump. But that's it for now. Let's move on Now recognition. According to price Yandex SpeechKit stream recognition is calculated through a billing unit of 15 seconds, and the cost of one such unit is $0.0013327867. Accordingly, one minute is 4 units, that is, approximately $0.0053311468 per minute. For 263.5 billion minutes per month, this is approximately $1.4 billion per month or about 1.2 trillion rubles per year. And this is only the translation of speech into text. We don't understand the context yet. Maybe it was some kind of phrase from the TV in the background?

Next comes the analysis. If we take Yandex SpeechSense, we will see that the cost of audio analysis by minute is indicated there, for example, $0.011459016 per minute at the first level of calculation. It is clear that such a price is not necessarily equal to the internal cost of a large closed system, but we will calculate based on the data that we have. If we run the same 263.5 billion minutes per month through such an analysis, we get approximately $3 billion per month or about 2.58 trillion rubles per year. That is, analysis alone is more expensive than recognition. And it's logical Now let's add up what we have already calculated. For compressed Opus, with 6 months of storage, 3 copies and 30% of the stock, this turns out to be approximately 37 billion rubles per year for storage, about 1.2 trillion rubles per year for recognition and about 2.58 trillion rubles per year for analysis. Total approximately 3.82 trillion rubles per year. If you add at least 30% on top for operation, security, personnel, monitoring, purchasing and updating hardware, internal services, incident investigations, access control, auditing and everything else that is definitely needed in such a system, you will get about 4.96 trillion rubles per year. Moreover, 30% on top is an insanely cautious estimate, because with such a scale, any mistake will become incredibly expensive, and any downtime will turn into a problem at the federal level (a leak of such an array of data will not just be news, but a scandal of unimaginable proportions) If you consider uncompressed audio, the picture is even more fun, although the fun here is, you know, with a slight smell of a burning budget. There, storage under the same conditions will cost about 394 billion rubles per year, recognition about 1.2 trillion rubles, analysis about 2.58 trillion rubles, and together with 30% of the reserve it will cost about 5.43 trillion rubles per year. That is, there is a difference between compressed and uncompressed audio, but it does not change the main conclusion, because the main cost comes from the constant processing and analysis of a gigantic audio stream

Now let's compare this to the federal budget, because we do not live in a world where any state has unlimited financial capabilities. Expenditures of the Russian federal budget for 2026 planned at the level of 44.1 trillion rubles. According to data on the structure of expenditures, about 12.93 trillion rubles are allocated for national defense in 2026, about 7.1 trillion rubles for social policy, about 4.77 trillion rubles for the national economy, about 3.91 trillion rubles for national security and law enforcement, about 1.74 trillion rubles for education, and about 1.88 trillion rubles for healthcare (I have a link to all this data here). But this all looks very interesting. A scenario with compressed audio, full recognition, analysis, storage, backup and a minimum margin of 30% gives about 4.96 trillion rubles per year. This is approximately 11.3% of all federal budget expenditures. This is about 38.4% of national defense spending. That's about 126.9% of national security and law enforcement spending. That is, such a system would cost more than the entire federal article “National Security and Law Enforcement.” This is approximately 285% of education expenditures and approximately 264% of healthcare expenditures. It turns out that such a project would cost more than two annual federal budgets for education or health care. And this despite the fact that we are counting only the conditional 6.1 million devices with Russian assistants, and not all devices with microphones in the country

If we take uncompressed audio, we get about 5.43 trillion rubles per year. That's about 12.3% of the federal budget, about 42% of defense spending, about 139% of homeland security and law enforcement spending, about 312% of education spending, and about 289% of health care spending. Roughly speaking, for the sake of round-the-clock centralized collection, storage, recognition and analysis of all our kitchen conversations from home speakers, we would have to find money at the level of several large federal areas. And what is this all for? To listen to a man ask Alice to turn on the light, discuss dinner, swear about delivery and watch TV? Well that's it

You can, of course, say that the state will build everything itself and get a lower cost. This is an appropriate remark. But even if we imagine that everything can be done 10 times cheaper, the scenario with compressed audio will still cost approximately 496 billion rubles per year. That's about 1.1% of the federal budget, about 3.8% of defense spending, about 12.7% of national security spending, about 28.5% of education spending, and about 26.4% of health care spending. Even if we do it 100 times cheaper, which already sounds very optimistic (and crazy how unrealistic), it’s about 49.6 billion rubles a year. Compared to the federal budget, this is already quite impressive, but it is still a separate large government program that needs to be hidden somewhere (people should not know that they are being recorded, otherwise who will buy the speakers), finance, maintain, protect and at the same time not get leaks, investigations, leaks of documentation and contractors who accidentally told something somewhere

What's the joke? The funny thing is that we haven’t even counted the iron yet. If we very roughly convert only storage into equipment, then for a compressed version with 6 months of storage, 3 copies and a service reserve, approximately 1.1 exabytes of usable volume is needed. If you take 24 TB corporate disks, you will need about 50 thousand disks just for the file compression option. For the option without compression we will be talking about approximately 500 thousand disks. Prices for enterprise 24 TB drives are around a few hundred euros per drive (about 890 euros for a 24 TB SATA option), and SAS options can be even more expensive. That is, only disks for the compression version can cost tens of millions of dollars, and without compression they cost hundreds of millions of dollars. But disks themselves do not operate in a vacuum. They need controllers, networks, racks, power, cooling, data centers, maintenance, replacement of failed disks, monitoring, redundancy and personnel who will service all this

With calculations the story is the same. If you buy accelerators for analysis and recognition, it will be even more expensive. NVIDIA does not publish the price for the H100, but there are various reviews indicate that the H100 80GB PCIe is often in the range$25-30 тысяч, а SXM-версии могут стоить $35-40 thousand. And again, one GPU is not a system. We need servers, network, power, cooling, SRE, security, etc. I understand that commentators usually don’t think about this, but in reality it turns out to be a very expensive zoo of hardware and people. Moreover, this zoo should also be better protected than most government systems, because the leak of round-the-clock home conversations of millions of people is not just a nuisance, but a catastrophe with legal, political and reputational consequences

Yes, let’s just remember that “Yarovaya Package”. There, too, was the idea of ​​storing user conversations, but not through smart speakers, but through telecom operators who already have the necessary infrastructure. In 2018, rules were approved according to which operators had to store user traffic for 30 days, and the capacity of technical storage facilities had to increase annually by 15% for 5 years. And what happened next? And then the harsh reality began. Operators talked about unaffordable costs, requirements were discussed, deadlines and volumes were adjusted, and later the Ministry of Digital Development proposed measures to support the industry, including the suspension of the annual 15 percent increase in storage capacity and the suspension of the requirement to store user traffic. The implementation of the Yarovaya Package turned out to be so prohibitive that the requirements had to be softened, transferred, discussed and separately supported by the industry. And this despite the fact that it was not about hidden round-the-clock wiretapping through a speaker, but about a public demand for telecom operators, where at least it was clear who the performer is, where the infrastructure is and who is formally responsible for it

But what if the speakers do not record the entire conversation, but turn on for certain words? Let’s say the column doesn’t write everything at all, but works locally on keywords like “government”, “president”, “revolution” and sends only a 30-second fragment. If each device sends one such fragment per day, then taking into account storage, recognition, analysis and 30% of the reserve, the amount will be approximately 1.7 billion rubles per year. If 10 fragments per day, it will be about 17.2 billion rubles per year. If 100 fragments per day, it will be about 172 billion rubles per year. Compared to the federal budget, this already looks quite normal (172 billion rubles is about 0.39% of the federal budget). From a financial point of view, this scenario is more realistic But he has another problem. To send only such fragments, the column must locally recognize these words, and in noise, with a TV in the background, with different voices, with false positives, with different wording and with a constantly updated list of words. And most importantly, the existence of such logic must be proven technically. It’s not enough to just think that Yandex or VK does this. This really needs to be proven. Because from a safety point of view, “technically possible” and “proven to happen” are completely different things. Technically, many things are possible. It's technically possible that your TV is in conspiracy with your robot vacuum cleaner. But until we have the facts, this cannot be an adequate conclusion And if you put all this together, the version about total round-the-clock wiretapping of all smart speakers begins to look very strange. In fact, this is infrastructure worth trillions of rubles per year, comparable to large federal budget items and exceeding annual expenditures on individual areas such as education and healthcare. Moreover, such a system must receive hundreds of petabytes of audio per month, store exabytes of data, recognize hundreds of billions of minutes of speech, analyze this entire stream, protect it, serve it, back it up, hide it, control employee access, prevent leaks, and at the same time, by some miracle, leave no traces at all (because neither I nor anyone else has been able to find anything like this over the years of the existence of smart speakers). And the experience of the Yarovaya Package shows us that even the record storage system of telecom operators, where there are clear performers, clear regulation and clear infrastructure, turned out to be very expensive and requires constant adjustment. Therefore, I would call the Alice the Spy scenario very unlikely, at least from a financial point of view. The option with keywords looks more realistic, but without technical evidence it remains just a hypothesis, which, again, no one has been able to prove over the years

The fascinating calculations end here, let’s return to the article.

Let's talk not about state wiretapping, but about advertising. Nowadays, user data is very expensive. They are used to build advertising, analytics, personalization, recommendations, targeting, behavioral models and a bunch of other things. The story of Facebook and Cambridge Analytica has become one of the most famous examples of how personal data can be used for political profiling and targeting. In 2019 FTC fined Facebook at 5 billion dollars and introduced additional privacy restrictions, and in materials by Cambridge Analytica there was a separate reference to the practice of collecting personal data of tens of millions of users for voter profiling. Therefore, when someone says “who needs my data,” the answer is quite simple: I don’t know, but they do. Maybe not your conversations with your family, but in any case your habits, routes, interests, purchases and places of residence. Most of us are most likely not needed by any intelligence services. More often, such information is collected for personalized advertising, for which companies are willing to spend a lot of money. It’s even a little offensive, but what can you do? Capitalism Here, unfortunately, I will have to upset many people. There is almost no complete privacy in the modern world. I will say more, it did not exist in the form in which many imagine. The phone is nearby. The laptop is nearby. Banking applications, telecom operators, street cameras, social networks, instant messengers, navigators, food delivery, marketplaces. If a person really wants digital invisibility, he will have to do more than just throw out Yandex Station. He will have to leave the network altogether. Any government in any period of history tried to protect itself. Riots were suppressed, secret societies were revealed, letters were read, circles were monitored, printing houses were controlled, denunciations, again, existed long before the advent of the Internet. But despite all this, somehow revolutions still happened. The government was overthrown. Closed regimes fell. How so? Maybe even the most closed and totalitarian regime can fall, no? In essence, little has changed. It’s just that now digital traces, cameras, advertising and the infrastructure of large companies have been added to all this, because large corporations make money from this. This doesn't mean that surveillance isn't dangerous. Of course it is dangerous. This means that you don’t have to think that if there is a column somewhere, then you are definitely being watched. You can accept this possibility. But think for yourself, if someone has clearly and irrevocably decided to follow you, will the absence of Yandex Stations in your home scare them away? And before, how did they eavesdrop and spy on the “Smart Home”? Therefore, if you managed to talk yourself into an article, they will come to you without any columns. And if the state is not particularly interested in you, then listening to you through a speaker will be unreasonably expensive

Maybe now someone will be surprised, but I have never hidden the fact that I love my country, but at the same time I am not a supporter of everything that those in power do in it. Actually, I am not satisfied with either what is happening in the States or what is happening in the vast majority of countries. Freedom of speech is not an empty phrase for me, but I know what kind of world I live in. And living in such a world (it doesn’t matter at all what country), I wouldn’t be surprised if at some point someone wants to get acquainted in more detail with what I write, say, etc. (and I can say this about any person). Kamon, I run a channel, write articles, speak publicly, work in information security... as if it’s too late to hide and go into the shadows, like I don’t exist. Regarding Max, my position is fundamental only because it is literally forced to be installed under various pretexts, and I am against the imposition of anything. If the product is good, convenient and competitive, people will use it themselves. Nobody forces you to buy Yandex Station. That's why I have two of them :) This is my decision, which I made on my own, realizing that in theory I could be wiretapped or that some data could be processed. This applies not only to Yandex, but also to Siri, ChatGPT and other software that I use (and you, by the way, too, don’t fool yourself). It is naive to believe that Alice is listening, and ChatGPT does not transmit any personal data anywhere. Well, yes, well, yes. Or what, the FBI won’t get it from another continent, but the FSB will definitely come, as they like to write in the comments? I don’t know of a single confirmed case where, after a conversation with Alisa, someone was detained precisely because of a recording from Yandex Station. I separately tried to find public confirmation of such a scenario, but I did not find any reliable cases. At the same time, in 2025, the media wrote about disputes surrounding intelligence services’ access to the infrastructure of smart devices and data, and Yandex publicly stated that before the activation word is pronounced, devices with Alice do not recognize human speech and do not transmit it to the cloud. Whether to take a company's word for it or not is a personal matter. In general, I wouldn’t take anyone’s word for it when it comes to privacy. But from an argumentative point of view, it is important to separate proven facts from sensations, otherwise we will quickly come to the conclusion that any device with a microphone can be a personal friend of the organs

So can I buy it or not?

Выводы

Specifically, my position here is very simple. A smart home is not an absolute evil. Voice assistants are not agents in uniform who leak your conversations to intelligence agencies. Automation in itself is not the problem. The problem is the thoughtless use of technology, incorrect settings, weak passwords, lack of updates, blind trust in manufacturers, buying the cheapest devices of unknown origin and the consumer’s reluctance to at least understand a little about what he connects to his network and installs in his home. At the same time, manufacturers should also not simply throw up their hands and say that the user is to blame for being hacked. No, guys, if you are selling a device with a microphone, camera and Internet access, you must think about security not after the scandal, but before it. And it’s good that requirements like the British PSTI, the European Cyber Resilience Act, the American Cyber Trust Mark and the ETSI EN 303 645 standard are already appearing in the world, because this is the only way we can make the personal Internet of things more secure

If you're nervous about using personal IoT devices, don't panic. Start with an inventory. Look at what is connected to the network in your home, what accounts are used, where the cameras are located, and whether you have demarcated the network for IoT devices that have Internet access. After such a mini-audit, it may turn out that the problem is not with Big Brother, but with the user who never changed the factory password after purchasing the device. A smart home is just a tool. In capable hands it helps. And in curves it can create a lot of problems. Let go of the illusion of complete privacy. No matter how sad it may be, it is not and never was. But this does not mean at all that you need to give up and give everyone access to everything. You just need to understand the risks, make informed decisions and not confuse convenience with safety

Discussion

Comments

Comments are available only to confirmed email subscribers. No separate registration or password is required: a magic link opens a comment session.

Join the discussion

Enter the same email that you already used for your site subscription. We will send you a magic link to open comments on this device.

There are no approved comments here yet.