Recently we published an article, Is your TV Watching you? Latest Models Raise Concerns, that questioned whether the integrated cameras and microphones in Samsung's top end 2012 LED and plasma models create risks that could be exploited by hackers to steal your personal information and even spy on you in the privacy of your living room.
HD Guru is reporting that Samsung has finally released an official comment, along with an updated privacy policy. The response published by HD Guru says:
Samsung takes all concerns regarding consumer privacy and information security very seriously. In all of our Smart TVs, including our new 2012 LED and Plasma TVs featuring built-in camera and microphone components, Samsung employs industry-standard security safeguards and practices (including data encryption) to secure consumers’ personal information and prevent its unauthorized collection or use.
Samsung also ensures consumers have the opportunity to review the terms of the company’s Privacy Policy prior to using Samsung’s Smart TV services. The Privacy Policy can be found at www.samsung.com/privacy.
The camera and microphone are integrated into the TV to provide users with innovative new ways to control the TV. They may also be used for video conference and speech-to-text services offered by third parties, in which case the audio and video data is transmitted to the service providers’ servers and does not pass through Samsung servers. Images captured in order to use the facial recognition feature are stored in a secure manner on the owner’s TV only.
Should the TV owner choose not to use these features, the camera and microphone can be disabled. Users can check if the camera and microphone are activated from the TV’s settings menu. As an added precaution, the camera can be rotated and tucked into the bezel of the TV. Once tucked away, the camera only captures a black image.
Samsung is dedicated to instilling consumer confidence in this matter. Any questions regarding the Privacy Policy or protection of personal information on the TV can be directed to intertv@samsung.com.
We are pleased that Samsung addressed some of the specific issues that were raised regarding how personal data is used and protected and whether facial recognition data is transmitted to or stored by Samsung (they're not). However, there are two significant concerns that remain unaddressed.
Personal information can be used for marketing
The first concern is the provision of your personal data to third parties for targeted advertising and other promotional purposes. In the language of Samsung's privacy policy, this use is explicitly allowed [bold emphasis added by Techlicious]:
[Samsung] may also use the personal or non-personal information we collect...for marketing and promotional efforts, including direct marketing, so that we or any of our related companies can send you information about products and services which we believe may be of interest to you.
Samsung Service may also offer co-branded services and features, such as events and/or promotions that we put together with another company...We may share your Personal Information with our Co-Branded Partner and your voluntary use of, or participation in, a co-branded service or feature means that you opt-in and give your affirmative consent to both Samsung Service and our Co-Branded Partner to collect and use your Personal Information provided during the registration process and/or in connection with the specific co-branded feature or service for the fulfillment of the feature or service and for marketing or administrative purposes. If you wish to opt-out of a Co-Branded Partner's future use of your Personal Information for marketing purposes, you will need to contact the Co-Branded Partner directly...
...[Samsung] may use third parties...to provide advertising, marketing and promotional assistance, provide e-mail services, or facilitate sales and our online services. In those instances, we may need to share your Personal Information with them.
In other words, your personal information may be used by Samsung for marketing purposes. provided to third parties and used by third parties for marketing purposes, even if you didn't explicitly agree to that use. Since many of the Internet-based services on Samsung TVs require you to provide personal information before using them, there is essentially no way to avoid opting into these marketing uses unless you choose not to use the Internet features (which negates the purpose of buying these models in the first place).
Hacking risk remains unknown
The ability to disable the microphone and camera through the TV settings is reassuring. However, there have been many well-publicized instances of computer hacking where the perpetrator was able to remotely activate laptop webcams and record those in the room. The fact that this can occur in a PC environment, with multiple layers of security protection, does not give us great confidence that a relatively brand new TV operating system has the necessary protections in place to prevent the same type of intrusion.
I recommend you follow Samsung's instructions for rotating the TV camera into the bezel when not in use and keep you clothes on when it is so those images don't end up on the Internet later.
What about other manufacturers?
Samsung has been on the forefront of rolling out Internet features on their TVs. But most other major manufacturers have Internet connected TVs in the market, and many are coming out with integrated cameras, as well. I expect that many of the concerns raised about Samsung will also be an issue elsewhere.
Why so many lies in one statement by Samsung?..
From rushin2 on February 11, 2015 :: 1:23 pm
“Samsung also ensures consumers have the opportunity to review the terms of the company’s Privacy Policy prior to using Samsung’s Smart TV services. The Privacy Policy can be found at www.samsung.com/privacy.”
No one ensured that I read this policy when the TV was sold to us. Neither did I expect such privacy concerns when we purchased it in 2013.
Disconnected from the internet. Let it be “stoopid” tv vs. too “smart” for own likeness…
Reply