Live data from Hacker News

Ring fired employees for watching customer videos

vice.com

141–147 of 147 posts

Re: Ring fired employees for watching customer videos

#141
post #138

Earlier quoted context omitted.

I avoid the ones that require an account to sign in or rely heavily on cloud services. This is the best IoT advice I can give anyone. I've had at least a dozen "smart" lightbulbs orphaned by two different companies. One went out of business, the other just decided not to support them anymore. The amazing thing is with the first group of bulbs, the IoT company actually pushed out a software update bricking the control…

that's also why sometimes it's worth a little more for the name brand/larger company. I paid a little more for Hue, but my first bulb still functions the same or better than the day I bought it.

Agreed, but at the time there were no big brands. Now if I buy IoT, I buy Homekit simply because I think Apple is the least likely company to go out of business or abandon the kit.

Re: Ring fired employees for watching customer videos

#142

Earlier quoted context omitted.

The easiest way to keep someone out is to lock the door. You can create penalties, punishments, hire security guards to watch the door. But the most efficient and effective way is just a lock.

That's absolutely not true. Most doors are trivial to pick and as easy to break down. The main, and usually only, real reason for the lock on the door is to serve as a physical symbol which establishes a particular legal status of the property behind the doors, with associated consequences for unlawful entry. The legal apparatus - penalties, punishments - is what deters crime. Lock is an XML tag made of matter. (The…

I've never had a window or door broken, but if I left my door unlocked, everything would be stolen. I've had stuff stolen that was outside, even had people try the locked door while I was inside. It doesn't seem to matter that my house is actually pretty easy to break into, as long as I lock the doors. So I would agree that the easiest way to keep people out of my house is to lock the door.

Re: Ring fired employees for watching customer videos

#143

Earlier quoted context omitted.

Unless I COMPLETELY misunderstand encryption, E2E encryption only protects your data in transit. It does not mean that data on servers are encrypted NOR does it mean that servers don't have decryption keys to that data if it is encrypted. Am I wrong about this?

At least in Apple's case, they do not have the keys because it is encrypted by your devices and then uploaded. It is then only able to be read by your devices because they have the keys to un-encrypt it.

The latest Apple platform security doc (fall 2019, available as pdf) does a half-decent job of explaining their key distribution mechanisms (iCloud Keychain, they call it) too. They are doing some pretty complicated stuff under the hood to support multiple devices (trust circles, they call it).

I just wish I could read the source code to make sure theory and practice are reasonably congruent.

Re: Ring fired employees for watching customer videos

#144
post #133

Earlier quoted context omitted.

The other end should be you too? Unless you intend for someone else to oversee your surveillance operation, your footage shouldn't leave your premises unless encrypted, using keys which don't leave your possession. You enter them out-of-band on the device on which you wish to watch remotely. Is there some implied benefit to not encrypting end-to-end or are they just being lazy and using nothing more than TLS because…

> The other end should be you too? But that cannot work with a cloud-based Motion Detection feature (arguably the second most important feature of Ring doorbell cameras, after the doorbell functionality). The Motion Detection is done server side so the server has to be able to see unencrypted video. Maybe if there was a lot more powerful (and programmable) hardware on the camera side you could do it there.

I don't see why you couldn't. The hardware to do it isn't expensive, so the camera itself could do that processing locally and just send the data along with the video encrypted to the end device. It might make the product cost a bit more, but it would also eliminate most of the concerns I have with that type of product.

Re: Ring fired employees for watching customer videos

#145
post #15

Whenever end-to-end encryption is not used, scenarios like these are bound to happen eventually. As far as I know, the only home surveillance products that use E2EE are ones that support HomeKit Secure Video [1]. 1. https://support.apple.com/en-us/HT210538

These kind of scenarios can happen with workers in government offices, archives and medical institutions as well. And yet the paper documents are not E2E encrypted. Maybe... just maybe... technology is not really what should be the core issue here? But we should perhaps look at our policies and legislation? Adding proper liability there will make technology come by itself. The magic of free market doesn't seem to be…

This brought back memories of doing data entry for an insurance company as a teenager. I spent eight hours a day transcribing people's names, addresses, SSNs, and medical ailments, including all sorts of sexually transmitted diseases.

It's weird, now that I think about it. I was just some kid they hired as a temp. We've never really known who's looking at our private data.

Re: Ring fired employees for watching customer videos

#146

What's a good cloudless setup? I've got a couple zwave devices, and have been looking into OpenHab. Win10 compatibility would be a bonus, as well as the ability to run my own OpenCV video analysis and voice recognition stacks...

Ubiquiti’s offerings can all run 100% locally. I have my entire setup using PoE so each only needs a single cable.

You can also access it remotely, too, which is nice. If you don't have a fixed IP/don't want to manage firewall rules, they have a central service that creates the handshake between your remote device and your NVR to facilitate the connection.

Re: Ring fired employees for watching customer videos

#147

Whenever end-to-end encryption is not used, scenarios like these are bound to happen eventually. As far as I know, the only home surveillance products that use E2EE are ones that support HomeKit Secure Video [1]. 1. https://support.apple.com/en-us/HT210538

Wyze has End to End encryption for their cloud stuff, or you can save it all on an SD card instead. Wyzecams are also really cheap $20 but they dont have a doorbell, so for now I'm keeping Ring (came with my house) till I see a good alternative.

Wyze is using the term end-to-end wrong, which is very disappointing but not surprising. They are considering themselves an end, which changes the meaning in a way to make the term totally meaningless. The end in end-to-end is end users.
Post reply on HN