Living Room Connected Devices Opportunities, Security Challenges and Privacy Implications for Users and Industry
Total Page:16
File Type:pdf, Size:1020Kb
CHILDREN AND FAMILIES The RAND Corporation is a nonprofit institution that helps improve policy and EDUCATION AND THE ARTS decisionmaking through research and analysis. ENERGY AND ENVIRONMENT HEALTH AND HEALTH CARE This electronic document was made available from www.rand.org as a public INFRASTRUCTURE AND service of the RAND Corporation. TRANSPORTATION INTERNATIONAL AFFAIRS LAW AND BUSINESS NATIONAL SECURITY Skip all front matter: Jump to Page 16 POPULATION AND AGING PUBLIC SAFETY SCIENCE AND TECHNOLOGY Support RAND TERRORISM AND Browse Reports & Bookstore HOMELAND SECURITY Make a charitable contribution For More Information Visit RAND at www.rand.org Explore RAND Europe View document details Limited Electronic Distribution Rights This document and trademark(s) contained herein are protected by law as indicated in a notice appearing later in this work. This electronic representation of RAND intellectual property is provided for non-commercial use only. Unauthorized posting of RAND electronic documents to a non-RAND Web site is prohibited. RAND electronic documents are protected under copyright law. Permission is required from RAND to reproduce, or reuse in another form, any of our research documents for commercial use. For information on reprint and linking permissions, please see RAND Permissions. This report is part of the RAND Corporation research report series. RAND reports present research findings and objective analysis that address the challenges facing the public and private sectors. All RAND reports undergo rigorous peer review to ensure high standards for research quality and objectivity. EUROPE Living Room Connected Devices Opportunities, security challenges and privacy implications for users and industry Neil Robinson, Jon Freeman, Jan Gaspers, Veronika Horvath, Tess Hellgren, Alex Hull EUROPE Living Room Connected Devices Opportunities, security challenges and privacy implications for users and industry Neil Robinson, Jon Freeman, Jan Gaspers, Veronika Horvath, Tess Hellgren, Alex Hull Prepared for Ofcom For more information on this publication, visit www.rand.org/t/rr604 Published by the RAND Corporation, Santa Monica, Calif., and Cambridge, UK R® is a registered trademark. © Copyright 2014 Ofcom RAND Europe is an independent, not-for-profit policy research organisation that aims to improve policy and decisionmaking in the public interest through research and analysis. RAND’s publications do not necessarily reflect the opinions of its research clients and sponsors. All rights reserved. No part of this book may be reproduced in any form by any electronic or mechanical means (including photocopying, recording, or information storage and retrieval) without permission in writing from the sponsor. Support RAND Make a tax-deductible charitable contribution at www.rand.org/giving/contribute www.rand.org www.rand.org/randeurope Preface RAND Europe was commissioned by Ofcom, the UK communications regulator, to investigate and prepare an independent expert report on the growth of the connected living room and the implications of this growth for UK citizens and consumers. As the living room becomes an Internet connected space, this shift offers opportunities to consumers and industry while also raising potential privacy and security concerns. Although currently a nascent market, the uptake of living room connected devices is expected to grow significantly in the coming years. However, it appears that there is a low awareness of how the capabilities of living room connected devices might be used, either legitimately by industry or illegitimately by criminal actors. This report addresses the security and privacy implications of the Internet connected living room for both industry and consumers, discussing potential benefits and emerging threats associated with living room connected devices and their technical capabilities. Ofcom has a principal duty to further the interests of citizens and consumers in relation to communication matters. It is also guided by a regulatory principle to research markets constantly. Ofcom aims to remain at the forefront of technological developments and it is on this basis that this report was commissioned. RAND Europe is an independent not-for-profit policy research organisation that aims to improve policymaking and decisionmaking in the public interest through research and analysis. RAND Europe’s clients include European governments, institutions, NGOs and firms with a need for rigorous, independent, multidisciplinary analysis. For more information about RAND Europe or this document, please contact: Neil Robinson Research Leader RAND Europe Westbrook Centre Milton Road Cambridge CB4 1YG United Kingdom +44 (1223) 353 329 [email protected] More information about RAND Europe is available at: http://www.rand.org/randeurope.html iii Table of Contents Preface ......................................................................................................................................................iii Table of Contents ...................................................................................................................................... v Figures ..................................................................................................................................................... vii Tables ....................................................................................................................................................... ix Executive summary ................................................................................................................................... xi Abbreviations ......................................................................................................................................... xiii 1. Understanding the growth of the Internet connected living room ............................................ 1 1.1. Introduction ................................................................................................................................. 1 1.2. The living room is transforming through growing use of living room connected devices ............... 1 1.3. LRCDs are blurring the line between passive and active entertainment ......................................... 4 1.4. The market for LRCDs is forecast to grow significantly in coming years ....................................... 4 1.5. A complex range of industry actors are engaged in the ICLR, with varying roles and motivations ................................................................................................................................... 7 2. Security, privacy and industry challenges in the Internet connected living room ..................... 10 2.1. Introduction ............................................................................................................................... 10 2.2. There are no new threats, just old threats in new devices ............................................................. 10 2.3. ICLR industry actors also pose privacy and data protection challenges ........................................ 20 2.4. Some types of users are more vulnerable in the ICLR than others ............................................... 21 2.5. Industry also faces challenges in the ICLR .................................................................................. 23 3. Protecting users and industry in the Internet connected living room ...................................... 27 3.1. Introduction ............................................................................................................................... 27 3.2. Inadequate tools limit protection from emerging threats ............................................................. 28 3.3. Secure user behaviours may be either constrained or enabled by default security and content control settings ............................................................................................................... 33 3.4. Raising user awareness can improve security ............................................................................... 38 4. Potential ways to increase the security of living room connected devices ................................. 43 4.1. Introduction ............................................................................................................................... 43 v 4.2. There is a need to follow the evolution of the LRCD value chain ............................................... 43 4.3. A number of existing tools could be adapted to promote a more secure ICLR ............................. 44 4.4. Secure user behaviour can be encouraged through both technical and non-technical tools .......... 45 4.5. Information sharing enhances awareness and response to potential risks ..................................... 46 4.6. Effective partnerships offer an opportunity to address challenges without losing benefits ............ 49 References .................................................................................................................................. 51 Appendix A – Methodology ........................................................................................................ 65 A.1 Literature review ......................................................................................................................... 65 A.2 Key stakeholder interviews .......................................................................................................... 69 Appendix B – Descriptions of LRCDs and