Skip to content

"Am I Just Dumb?": Applicability, Action and Verification in Consumer IoT Security Advice

Veerle van Harten, Carlos Hernández Gañán, Michel van Eeten, Simon Parkin

cs.HCarXiv:2608.25225

Abstract

Public campaigns urge people to update their Internet of Things (IoT) devices and change default passwords. What happens when people try? We gave 28 participants in the Netherlands two pieces of government-issued advice and asked them to try applying each to three of six bestselling IoT devices (168 sessions). We located no manufacturer-set password shared across units, the kind the advice describes; the only device-level credential located was unique to its unit. Fewer than half the update sessions established firmware status. Told that a setting might not apply, no participant concluded it did not: they treated whatever related setting the interface offered as the target, and located the difficulty in themselves rather than in the advice or device. Generic advice asks people to judge what only manufacturers can state and only devices can report. Campaigns must be coordinated with device design, or replaced by secure defaults that remove the task.

Create a lesson