Live data from Hacker News

Ring fired employees for watching customer videos

vice.com

131–140 of 147 posts

Re: Ring fired employees for watching customer videos

#131

Earlier quoted context omitted.

I must disagree, although I find what you are saying an important part of the defenses, and likely a larger issue in certain parts of the country and certain neighborhoods.. I think the gp is not 'absolutely not true'.. I have a fair amount of hobby interest experience dealing with petty thieves / criminals for the past couple decades; studying them locally and through polls and news articles... stories about locked…

You're right that I shouldn't have said "absolutely not true", but I stand by my general message. Regular locks are inconveniences for thieves, not deal breakers. > In most neighborhoods seeing someone crouched down playing with a door lock would attract attention and likely calls to the police. Not if that someone is wearing a hi-vis safety vest (perhaps with "Cory & Trevor Locksmith Company" or something similar wr…

[deleted]

Re: Ring fired employees for watching customer videos

#132
post #4

> It says three employees can currently access stored customer videos. I can't think of a legitimate reason for 1 employee at Ring to have the capability of viewing customer videos. 1. Law enforcement requests? Blind-forward what the warrant asks for. 2. Verifying service is functioning? Canary devices utilizing the normal application workflow. Login to your canary account and make sure the video is working. 3. Custo…

1. if law enforcement can view it, so can you

2. “it works on my end” really now

3. you just said the police can view it. let me view it. you can’t just becomes you won’t.

Re: Ring fired employees for watching customer videos

#133

Earlier quoted context omitted.

Why would end-to-end help when it's the other end that's watching?

The other end should be you too? Unless you intend for someone else to oversee your surveillance operation, your footage shouldn't leave your premises unless encrypted, using keys which don't leave your possession. You enter them out-of-band on the device on which you wish to watch remotely. Is there some implied benefit to not encrypting end-to-end or are they just being lazy and using nothing more than TLS because…

> The other end should be you too?

But that cannot work with a cloud-based Motion Detection feature (arguably the second most important feature of Ring doorbell cameras, after the doorbell functionality). The Motion Detection is done server side so the server has to be able to see unencrypted video. Maybe if there was a lot more powerful (and programmable) hardware on the camera side you could do it there.

Re: Ring fired employees for watching customer videos

#134
post #133

Earlier quoted context omitted.

The other end should be you too? Unless you intend for someone else to oversee your surveillance operation, your footage shouldn't leave your premises unless encrypted, using keys which don't leave your possession. You enter them out-of-band on the device on which you wish to watch remotely. Is there some implied benefit to not encrypting end-to-end or are they just being lazy and using nothing more than TLS because…

> The other end should be you too? But that cannot work with a cloud-based Motion Detection feature (arguably the second most important feature of Ring doorbell cameras, after the doorbell functionality). The Motion Detection is done server side so the server has to be able to see unencrypted video. Maybe if there was a lot more powerful (and programmable) hardware on the camera side you could do it there.

Makes sense, I thought there would have to be some "good" reason.

Your wouldn't need anything much more powerful than a Pi4B to do that part for a couple of cams, but I guess this keeps the cost down for a security-unconscious public.

Re: Ring fired employees for watching customer videos

#135
post #79

Earlier quoted context omitted.

The only reason you had to explain it was sarcasm is of course you should care. You sound like one of those "I have nothing to hide" people even though having something to hide is completely irrelevant. You're being spied on and you don't see any problems with that? And by the way, everyone has something to hide whether they know it or not.

There's that one TED talk about privacy where the guy says something like, "People say they have nothing to hide, but do any of you want to give me access to your private email account right now? No? Right, no one's ever taken me up on that". I've always thought that was a bit of a strawman. In the case of my front door, I really wouldn't mind even if it were livestreamed for the whole world to watch. I agree that "I…

If your front door were live streamed then people can basically watch your front door 24/7 while being invisible to you. They can watch long enough to be 99% certain the house is empty and rob you, or they can see if a package has arrived and you're not normally due home for hours and grab it. It would make casing the joint pretty easy.

Re: Ring fired employees for watching customer videos

#136

At least the homeowner has a choice to upload their video to ring. Street-facing doorbell cameras on public sidewalks are in my opinion the worse problem. Pedestrians didn't opt-in. Operators of these cameras (both the buyer and the vendor) should be subject to the same legal obligations as other data collectors.

My neighbor, across the street, has a Ring camera aimed directly at my house, since that is where their front door faces. What is my recourse for preventing my private property from being recorded?

Put up a fence.

Re: Ring fired employees for watching customer videos

#137

Earlier quoted context omitted.

In an ideal world, sure. But it's easy enough to imagine how you'd end up with this situation. For example, you have a customer support phone number, and you want your call centre workers to be able to see exactly what the user sees, and help the user do anything the user can do through the website. After all, if you're keeping your support costs down, the website should be able to do 99% of what users call support f…

Even if you offered a “log-in as customer” feature, that could incorporate a notification and/or authorization request to the user so that it can’t be abused.

We implemented this at my work. In order to sign in as the customer, the customer must first explicitly consent to this and can withdraw that consent (and the ability to sign in as the customer) at any time. Without the consent, the sign in as customer function in our support tools doesn't work.

There are some agents/admins with override abilities but the overrides are logged and reason (with ticket number) is required to create the override.

Re: Ring fired employees for watching customer videos

#138

My big problem with IoT devices is trust. When a third party has control of my data, I have to trust the company is going be a responsible steward for my data. This is particularly telling since few of them (none?) have binding terms of service which protect the rights of the buyer. So you have situations like this where abuse happens or companies like Canary which made a rather big and infuriating change to their po…

I avoid the ones that require an account to sign in or rely heavily on cloud services. This is the best IoT advice I can give anyone. I've had at least a dozen "smart" lightbulbs orphaned by two different companies. One went out of business, the other just decided not to support them anymore. The amazing thing is with the first group of bulbs, the IoT company actually pushed out a software update bricking the control…

that's also why sometimes it's worth a little more for the name brand/larger company. I paid a little more for Hue, but my first bulb still functions the same or better than the day I bought it.

Re: Ring fired employees for watching customer videos

#139

Earlier quoted context omitted.

The easiest way to keep someone out is to lock the door. You can create penalties, punishments, hire security guards to watch the door. But the most efficient and effective way is just a lock.

That's absolutely not true. Most doors are trivial to pick and as easy to break down. The main, and usually only, real reason for the lock on the door is to serve as a physical symbol which establishes a particular legal status of the property behind the doors, with associated consequences for unlawful entry. The legal apparatus - penalties, punishments - is what deters crime. Lock is an XML tag made of matter. (The…

Protecting property is not the only use-case for locks.

There are also locks on e.g. cell doors in prisons. Those are pretty essential to the function of the cell, and tend to survive anything prisoners might try to do to them.

There are also locks (specifically, interlocks) on e.g. dam spillways, or on the airlocks on submarines. (For these, the "key" is a button somewhere else that's not necessarily itself secured, but it is still very crucial that they keep things out when that button has not been pushed.) They hold up pretty well—even against malicious infiltrators—mostly because they fail closed and have no UI components mechanically linked to the locking mechanism.

Re: Ring fired employees for watching customer videos

#140

My big problem with IoT devices is trust. When a third party has control of my data, I have to trust the company is going be a responsible steward for my data. This is particularly telling since few of them (none?) have binding terms of service which protect the rights of the buyer. So you have situations like this where abuse happens or companies like Canary which made a rather big and infuriating change to their po…

I avoid the ones that require an account to sign in or rely heavily on cloud services. This is the best IoT advice I can give anyone. I've had at least a dozen "smart" lightbulbs orphaned by two different companies. One went out of business, the other just decided not to support them anymore. The amazing thing is with the first group of bulbs, the IoT company actually pushed out a software update bricking the control…

One of the most frustrating was my anova Sous Vide with bluetooth. It had a fairly useful app that worked well for monitoring temperature and setting temperature until they changed their policy to force users to create an account on their site. Fortunately I can just use the cooker without the app entirely which is much better than what Canary did.

I do like my smart lights, but I'm for a good chunk of them I'm buying the ones where the brain is integrated into the switch and the switch defaults to being a dumb switch when it can't find the cloud connection.

Post reply on HN