Live data from Hacker News

Ring Doorbell Vulnerability Exposes Wifi Password

pentestpartners.com

21–30 of 37 posts

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#21

Even from a theft perspecive it is bad design practise to have this placed outdoor... Why not place only the camera and button outdoor and have a simple wire connection to the wifi module. It's such a design flaw it becomes even funny

Why would someone steal a doorbell? Vandalise, sure, but steal it?

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#22
post #16

Even from a theft perspecive it is bad design practise to have this placed outdoor... Why not place only the camera and button outdoor and have a simple wire connection to the wifi module. It's such a design flaw it becomes even funny

Because 95+% of consumers would rather have something simple to install rather than something that requires drilling holes in their house or professional installation.

How is this device powered? Do you have to charge it or is it connected to an outlet in some way? I'm thinking that you might already have to drill a hole for power.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#23
It would be interesting to do a similar device, but based around a peephole rather than a doorbell. I'll call it Peep.

Peep will require a little more work to install than Ring, so won't be quite as convenient.

You'd remove the existing peephole, and then attach Peep through the hole. Peep would have an outside component that contains the camera, microphone, and speaker, and an inside component that contains a display and the wifi unit.

The place where the outside component connects to the inside would be on the inside, so from outside you can not simply detach the outside component like you can with Ring.

The inside component would also contain a microphone and a vibration sensor, so that it can tell when someone rings the doorbell or knocks on the door.

Although Peep installation would not be as easy as installing Ring, it shouldn't be too bad since it reuses the peephole hole so you do not have to make any new holes.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#24
post #21

Even from a theft perspecive it is bad design practise to have this placed outdoor... Why not place only the camera and button outdoor and have a simple wire connection to the wifi module. It's such a design flaw it becomes even funny

Why would someone steal a doorbell? Vandalise, sure, but steal it?

I might be missing something, but .. in this case? I thought that this thing is completely wireless and probably can be firmware reset.

So - you steal it, because you can actually install it at home (or resell it for that purpose). You don't steal a (broken) part of a doorbell, you steal a complete IoT device that the thread here and the original article seem to consider useful.

https://ring.com/store/products/ring-doorbell - it's $200..

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#25
post #10

Earlier quoted context omitted.

do what every lock do for the last century: do not leave screws outside. further, I'd have one module inside the door, a little wire just connecting a dumb button to the outside. granted installation would require a single drill hole, but it wouldn't be a huge fail like this.

But the module seems to have a camera.

Make it two drill holes then.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#26
post #20
post #16

Earlier quoted context omitted.

Because 95+% of consumers would rather have something simple to install rather than something that requires drilling holes in their house or professional installation.

But presumably the existing doorbell would already have simple wires running inside?

You can either wire it in to an old doorbell for power or you can disconnect it periodically and recharge via USB.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#27
post #15

serious question: what would be a better way to store the wifi credentials protected against the device theft?

Host its own wifi, with small preconfigured bridge device to plug into spare ethernet port of router?

Unfortunately if the unit isn't wired in, you have to remove it for charging meaning redoing setup when the battery gets low.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#30
post #18

It doesn't seem all that serious. If somebody's going to be removing parts of your house, they're putting themselves are far greater risk of arrest than a hacker hiding behind the internet. Why not just slash their tires or start a fire while you're there? Even having the wifi password doesn't necessarily give you access to anything but their internet connection anyway.

Use wifi password to change nameservers on router (assuming router is using default admin user:pass) find which online bank they're using and clone the site's homepage with a passthrough form to steal credentials. Et cetera.

Seems useful to a crook.

Post reply on HN