Live data from Hacker News

A podcast that hacks Ring camera owners live

vice.com

101–110 of 283 posts

Re: A podcast that hacks Ring camera owners live

#101
post #2

It's obviously bad to hack into a citizen's systems without consent, but there's some kind of value that might be created here. Ring cameras are basically being used as a gigantic police-partnered dragnet: Amazon’s Ring Planned Neighborhood “Watch Lists” Built on Facial Recognition https://theintercept.com/2019/11/26/amazon-ring-home-securit... If this provides a disincentivize to an average user buying Ring cameras,…

>Ring cameras are basically being used as a gigantic police-partnered dragnet: Isn't that sort of like saying humans are basically used as a gigantic police-partnered dragnet...seeing as our entire criminal system is primarily driven by eye witnesses of crimes? Only what we know is eye-witnesses often have conflicting testimony, some will refuse to assist police officers (out of concern for their own safety or they j…

==seeing as our entire criminal system is primarily driven by eye witnesses of crimes?==

Do you have a source for this? In my yearlong experience on a Federal Grand Jury, the vast majority of evidence we deliberated on was "hard". By that I mean video evidence, financial transactions, text messages, emails, cell phones tower pings for location, etc. Eye witness testimony helps solidify a case, but you typically need some form of "hard" evidence to even indict someone.

Even in your example, the video is what identified the suspect and lead to arrest not eye witnesses.

Re: A podcast that hacks Ring camera owners live

#102

Earlier quoted context omitted.

Amazon is going to require a subpoena/warrant to turn over video...I'm not sure why you think their cooperation with police is required in order to continue selling cameras.

Why do you think that their cooperation must be required before they will cooperate? Police are major Amazon customers as well, what's to keep them from handing over data to preserve their good-will?

>Why do you think that their cooperation must be required before they will cooperate?

Because they have written Law Enforcement Guidelines that are pretty clear and otherwise as a lawyer I know they don't just turn over customer data and information without a written order (and even then, they may object and fight it in court).

Why do you believe they are just turning over consumer data/info/video without any court order (besides, police are customers and Amazon wants to keep customers happy)?

Re: A podcast that hacks Ring camera owners live

#103
post #16

I think "hacks" is a pretty strong word here. They're basically just brute forcing accounts with email and password combos that have been leaked from other sources.

Why is Ring allowing brute forcing? Individual cameras should be set to only allow logins at least a few seconds apart increasing up to several minutes and perhaps blocking IP addresses with excessive volume. If they're brute forcing Ring's servers an application firewall would catch and block this.

The term for this type of attack is credential stuffing.

https://www.owasp.org/index.php/Credential_stuffing

Re: A podcast that hacks Ring camera owners live

#104
post #96

Earlier quoted context omitted.

Not necessarily. What security measures does the camera have implemented? Have you told the police that they are free to ask for footage?

I prevent it from accessing the internet, but I guess they could hack my network and access it that way

[deleted]

Re: A podcast that hacks Ring camera owners live

#105

Earlier quoted context omitted.

As someone who tends to fall on the side of privacy more often than not, I'm actually not sure how I feel about facial recog+home security cameras. I'm completely against any fully automated system where the police can have access to the camera's data. But on the other hand, what if the system was implemented completely locally, and all with the owner's control and permission? So your Ring app pops up and says "Hey,…

Consider that nobody breaks into your home/vehicles because it's fun. They do it out of desperation. I'm not alleging any ignorance on your part, it's just not the sort of thing we think about often. The penalties for these crimes are already extremely severe. So I fall on the side of, I'd rather change the system proximally to help those who resort to this sort of petty crime for cash so they don't need it, rather t…

If someone robbed your home and you recognized them, would you report them to the police?

Re: A podcast that hacks Ring camera owners live

#106
post #2

It's obviously bad to hack into a citizen's systems without consent, but there's some kind of value that might be created here. Ring cameras are basically being used as a gigantic police-partnered dragnet: Amazon’s Ring Planned Neighborhood “Watch Lists” Built on Facial Recognition https://theintercept.com/2019/11/26/amazon-ring-home-securit... If this provides a disincentivize to an average user buying Ring cameras,…

I have no problem with this. I have ring cameras all around my property and so do most of my neighbors and it's already caught multiple people attempting breaking and stealing packages.

They get hacked because of poor password choices.

You are fighting against a changing tide and the benefits of the cameras vastly outweigh the privacy concerns.

Re: A podcast that hacks Ring camera owners live

#107

Earlier quoted context omitted.

Until all video starts streaming to the server in a software update. For the safety of your children.

At which point the company gets massive federal lawsuit violating multiple laws, and gets shut down quick.

No, a democracy dies to thunderous applause.

Re: A podcast that hacks Ring camera owners live

#108

Earlier quoted context omitted.

As someone who tends to fall on the side of privacy more often than not, I'm actually not sure how I feel about facial recog+home security cameras. I'm completely against any fully automated system where the police can have access to the camera's data. But on the other hand, what if the system was implemented completely locally, and all with the owner's control and permission? So your Ring app pops up and says "Hey,…

Consider that nobody breaks into your home/vehicles because it's fun. They do it out of desperation. I'm not alleging any ignorance on your part, it's just not the sort of thing we think about often. The penalties for these crimes are already extremely severe. So I fall on the side of, I'd rather change the system proximally to help those who resort to this sort of petty crime for cash so they don't need it, rather t…

The fact that some people commit crimes out of desperation isn’t a very good argument for removing disincentives to commit crimes. You don’t lock your door at night because you think someone might break in for fun and you want to deprive them of that fun. You lock your door to protect your family and your belongings.

The question of moral culpability might be relevant when discussing legal punishments, rehabilitation, social welfare, etc. but it really isn’t relevant to what basic measures one can take to protect their home. To use an extreme example, someone could be forced under duress to break into your home. They clearly wouldn’t be morally culpable, but that simply isn’t relevant. You still lock your doors.

Re: A podcast that hacks Ring camera owners live

#110
post #17

The title makes it sound like there is a security issue with the cameras, but the "hacks" are from password leaks.

At some point we have to admit that passwords have not worked and the general public does not understand how to use them despite decades of education attempts. This problem would be entirely solved if they enforced the use of 2fa

At the very least, have e-mail 2fa for new devices, it's fairly trivial, isn't too annoying, and works decently enough. Most banks and important services do this. Whenever you login for the first time on a new device or far away IP, it sends you an email to authorize the new device. It's pretty trivial but goes a long way.
Post reply on HN