Live data from Hacker News

Ring Doorbell Vulnerability Exposes Wifi Password

pentestpartners.com

11–20 of 37 posts

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#11
post #2

I thought I recognized the packaging. Turns out this was 'DoorBot' from Shark Tank that got renamed to 'Ring.' They ended up getting a $28MM investment from Richard Branson for a $60MM valuation after getting a shoddy deal on the tank: http://www.businessinsider.com/ring-from-shark-tank-to-richa... Good on them.

I'm surprised that they received such a negative reception on SharkTank. Unlike most IoT products I've seen, this really seems like a great idea.

It's not a new idea though. There are a few other companies making the same thing.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#13

not just a low-level exploit but an actual fatal design flaw. oops. software engineers for IoT should really be forced to participate in security training.

From this comment and the one about the memory wipe I get the feel that there is a notion that hardware-based (anti-tampering) security is the only solution to this problem.

Isn't a straightforward software solution is to make the PSK write-only or protected by a different, changeable password?

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#16

Even from a theft perspecive it is bad design practise to have this placed outdoor... Why not place only the camera and button outdoor and have a simple wire connection to the wifi module. It's such a design flaw it becomes even funny

Because 95+% of consumers would rather have something simple to install rather than something that requires drilling holes in their house or professional installation.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#17

serious question: what would be a better way to store the wifi credentials protected against the device theft?

A base module inside the house instead of using the wireless directly. The doorbell would talk to the base module over some type of encrypted connection using a separate wireless network or bluetooth, and the module in the house would be plugged into the network, either over ethernet or wireless. The connection between the base and the doorbell would be configured to only allow for the voice/video/doorbell functions and that's it.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#18
It doesn't seem all that serious. If somebody's going to be removing parts of your house, they're putting themselves are far greater risk of arrest than a hacker hiding behind the internet. Why not just slash their tires or start a fire while you're there? Even having the wifi password doesn't necessarily give you access to anything but their internet connection anyway.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#19
post #10

serious question: what would be a better way to store the wifi credentials protected against the device theft?

do what every lock do for the last century: do not leave screws outside. further, I'd have one module inside the door, a little wire just connecting a dumb button to the outside. granted installation would require a single drill hole, but it wouldn't be a huge fail like this.

But the module seems to have a camera.

Re: Ring Doorbell Vulnerability Exposes Wifi Password

#20
post #16

Even from a theft perspecive it is bad design practise to have this placed outdoor... Why not place only the camera and button outdoor and have a simple wire connection to the wifi module. It's such a design flaw it becomes even funny

Because 95+% of consumers would rather have something simple to install rather than something that requires drilling holes in their house or professional installation.

But presumably the existing doorbell would already have simple wires running inside?
Post reply on HN