Today In Creepy Privacy Policies, Samsung’s Eavesdropping TV

As the number of connected devices — aka the Internet of Things, aka the sensornet — proliferates so too does the number of devices leaning on voice recognition technology as an interface to allow for hands free control.

Last fall, for instance, Amazon revealed a connected speaker with a Siri-style assistant that can perform tasks like adding items to your ecommerce shopping basket on command. Internet connected ‘smart TVs’ which let couch-potatoes channel-hop by talking at their screen, rather than mashing the buttons of a physical remote control are even more common — despite dubious utility to the user. The clear consumer electronics trajectory is for more devices with embedded ears that can hear what their owners are saying. And, behind those ears, the server-side brains to data-mine our conversations for advertising intelligence.

The potential privacy intrusion of voice-activated services is massive. Samsung, which makes a series of Internet connected TVs, has a supplementary privacy policy covering its Smart TVs which includes the following section on voice recognition (emphasis mine):

You can control your SmartTV, and use many of its features, with voice commands. If you enable Voice Recognition, you can interact with your Smart TV using your voice. To provide you the Voice Recognition feature, some voice commands may be transmitted (along with information about your device, including device identifiers) to a third-party service that converts speech to text or to the extent necessary to provide the Voice Recognition features to you. In addition, Samsung may collect and your device may capture voice commands and associated texts so that we can provide you with Voice Recognition features and evaluate and improve the features. Please be aware that if your spoken words include personal or other sensitive information, that information will be among the data captured and transmitted to a third party through your use of Voice Recognition.

As an Electronic Frontier Foundation activist pointed out earlier today, via Twitter, the concept of a TV screen that might be snooping on your private conversations  — and thus broadcasting a chilling effect by inculcating self-censorship within its viewers — is straight out of George Orwell’s 1984:

The Samsung example is just the latest privacy-related concern involving smart TVs — many of which routinely require users to agree to having their viewing data sent back to the TV maker and shared by them with advertisers and others simply in order for them to gain access to the service. But the clarity of wording in Samsung’s privacy policy is impressive — given it amounts to a warning not to talk about private stuff in front of your telescreen because multiple unknown entities can listen in.

Creepy, tech-fueled privacy intrusions are rarely detailed as clearly as that. So full marks to Samsung for clarity. Albeit, as per usual, these warnings are contained within the most overlooked type of document on the Internet so will easily go unnoticed by the average user.

If the SmartTV owner does realize how ridiculous this is, Samsung does at least allow them to disable the eavesdropping voice recognition ‘feature’, and instead use a more limited set of predefined ‘voice commands’ (which are processed locally on the device, unlike the VR feature which uses third party cloud-processing) — and in that instance says it does not harvest their spoken words.

However it will still gather usage info and any other text-based inputs for data mining purposes, as it also notes further down in the policy. So an entire opt-out of being tracked is not part of this very expensive package.

If you do not enable Voice Recognition, you will not be able to use interactive voice recognition features, although you may be able to control your TV using certain predefined voice commands. While Samsung will not collect your spoken word, Samsung may still collect associated texts and other usage data so that we can evaluate the performance of the feature and improve it.

You may disable Voice Recognition data collection at any time by visiting the “settings” menu. However, this may prevent you from using all of the Voice Recognition features.

Update: Samsung has now provided the below statement with additional details about the working of its Voice Recognition SmartTV feature to TechCrunch in response to this article. The company also suggests consumers with “product concerns or questions” should contact it directly.

In all of our Smart TVs we employ industry-standard security safeguards and practices, including data encryption, to secure consumers’ personal information and prevent unauthorized collection or use.

Voice recognition, which allows the user to control the TV using voice commands, is a Samsung Smart TV feature, which can be activated or deactivated by the user. The TV owner can also disconnect the TV from the Wi-Fi network. Should consumers enable the voice recognition capability, the voice data consists of TV commands, or search sentences, only. Users can easily recognize if the voice recognition feature is activated because a microphone icon appears on the screen.

Samsung does not retain voice data or sell it to third parties. If a consumer consents and uses the voice recognition feature, voice data is provided to a third party during a requested voice command search. At that time, the voice data is sent to a server, which searches for the requested content then returns the desired content to the TV. 

An Internet connected TV that might be eavesdropping on the stuff you say when you’re sitting on the sofa is just the latest overreaching privacy intrusion to come to light in the tech sphere.

It’s unlikely to be the worst, and sure won’t be the last. But as more of these egregious, overreaching policies come to light — and as more of the objects with which we are surrounded in our homes, cars and lives are networked up and brought online, and thus given (at very least) the technical ability to snoop on us — there is a growing imperative to clean up the darker corners of the digital commerce sphere. To set some boundaries on what is and is not acceptable. Or risk growing consumer mistrust.

When all the objects in your home have networked ears that are fine-tuned for commercial intelligence gathering, where will you go to talk about “personal” or “sensitive” stuff?

Postscript: The bottom line here is that companies building ‘smart’ services need to be thinking about privacy by design — at the very front and centre of the devices and services they are building — not tacking on auxiliary clauses to catch-all privacy policies which are designed to fly under the user’s radar anyway. The creepy wording of Samsung’s SmartTV privacy policy only serves to pass the buck on risks — and fails to educate the user on how exactly the technology they have paid for works, opting to make them feel uneasy/urge them to self-censor instead. If this privacy policy pleases anyone, it’s only going to put smiles on the face of Samsung’s legal department. So while the content of the policy comes off as Orwellian, the processes here are more impenetrably Kafka-esque, with unseen layers and players (in the case of the VR in this TV the third party processor is apparently Nuance — which has its own privacy policy that TV users suddenly become subject to if they utilize the on-board voice recognition feature) involved in the processing of the user’s data, leaving the person who has actually paid for the device in the dark about what exactly is going on. As more consumer electronics devices are networked and augmented with cloud-services, far greater levels of transparency about data processing will be required from device makers — along with clearly signposted opt-outs and user-controls for cloud-processing — to avoid the people who actually pay for this stuff to end up viewing ‘smart’ as ‘suspicious’.