Live data from Hacker News

A podcast that hacks Ring camera owners live

vice.com

51–60 of 283 posts

Re: A podcast that hacks Ring camera owners live

#51
post #2

It's obviously bad to hack into a citizen's systems without consent, but there's some kind of value that might be created here. Ring cameras are basically being used as a gigantic police-partnered dragnet: Amazon’s Ring Planned Neighborhood “Watch Lists” Built on Facial Recognition https://theintercept.com/2019/11/26/amazon-ring-home-securit... If this provides a disincentivize to an average user buying Ring cameras,…

As someone who tends to fall on the side of privacy more often than not, I'm actually not sure how I feel about facial recog+home security cameras.

I'm completely against any fully automated system where the police can have access to the camera's data.

But on the other hand, what if the system was implemented completely locally, and all with the owner's control and permission?

So your Ring app pops up and says "Hey, your local police department is looking for a suspect and your camera spotted them. Would you like to share the footage?".

So many petty crimes (e.g. home burglaries, car breakins, etc) go unsolved because the police just don't have the tools and resources to go after all those crimes. I have neighbors who've had their homes and cars broken into. It's a violating experience, and I think it's justified to want the perpetrators of those crimes caught and sentenced appropriately; at the very least to dissuade others.

Within the context of a well built, local, permissioned system, I'm not sure I'm against it.

Of course A) The likes of Amazon would never build such a system responsibly; they'd rather gobble up and abuse the data themselves. B) There are serious security concerns, as evidenced by TFA. C) Civil disobedience and similar acts are an important part of democratic society, and mass surveillance, responsible or not, threatens that. And finally, D) something which I think everyone misses when it comes to facial recognition systems ... they're still not very good. SOTA published recog systems make a mistake on 1 in 1000 faces (http://vis-www.cs.umass.edu/lfw/results.html), and that's on LFW which is fairly high quality. I'm sure FAANG does better, and SOTA will continue to improve quickly, but is that good enough for this kind of application?

So I'm torn.

Re: A podcast that hacks Ring camera owners live

#52

> The software churns through previously compromised email addresses and passwords to break into Ring cameras at scale. Given the sensitive nature of cameras in homes, I think Ring should require 2FA.

Or just have a min password length requirement that is at least a 5 word sentence. Easier to remember, and more secure.

Although password security makes no difference to how these devices were hacked, by password leaks.

Re: A podcast that hacks Ring camera owners live

#54

Earlier quoted context omitted.

They are not the same, and the latter does not happen with Ring cameras. Read all the articles more carefully. The issue is with the app and cloud stored footage, both of which are optional.

"Optional" features that literally everybody is going to get because what is the point of a security camera if you can't record or view remotely.

I don't know about the indoor cameras, but the ring doorbell can send a notification live to your phone with live video, without saving it on the server. I would imagine this is the same case for indoor cameras.

Re: A podcast that hacks Ring camera owners live

#56
post #16

I think "hacks" is a pretty strong word here. They're basically just brute forcing accounts with email and password combos that have been leaked from other sources.

Why is Ring allowing brute forcing? Individual cameras should be set to only allow logins at least a few seconds apart increasing up to several minutes and perhaps blocking IP addresses with excessive volume. If they're brute forcing Ring's servers an application firewall would catch and block this.

Not actually brute forcing individual ring accounts. They are just using previously leaked combinations

Re: A podcast that hacks Ring camera owners live

#57

Earlier quoted context omitted.

Or just have a min password length requirement that is at least a 5 word sentence. Easier to remember, and more secure.

Although password security makes no difference to how these devices were hacked, by password leaks.

Method wise, you are correct. However, forcing all the users to adopt a new password creation paradigm will statistically make this a very small issue.

Re: A podcast that hacks Ring camera owners live

#58
post #2

It's obviously bad to hack into a citizen's systems without consent, but there's some kind of value that might be created here. Ring cameras are basically being used as a gigantic police-partnered dragnet: Amazon’s Ring Planned Neighborhood “Watch Lists” Built on Facial Recognition https://theintercept.com/2019/11/26/amazon-ring-home-securit... If this provides a disincentivize to an average user buying Ring cameras,…

I disagree that it is a 'dragnet'. That seems like an emotionally-colored take. It is camera owners voluntarily sharing footage with police when they request it. Citizens are allowed to lawfully film in many locations (their own homes, public spaces, etc.) and citizens are allowed to voluntarily exchange information they own with entities of their choosing.

> It is camera owners voluntarily sharing footage with police when they request it.

Police can request that you share the footage you have, or police can get a warrant and obtain the footage directly from Ring.

The difference between a camera whose footage you control and Ring is that Ring provides a nice interface to let police know that potential video evidence that you captured exists. A camera system that you rolled out yourself doesn't send a message to law enforcement agencies each time your cameras potentially capture evidence.

The knowledge that video evidence exists makes it infinitely easier to get a warrant for it from a judge.

Re: A podcast that hacks Ring camera owners live

#59

Earlier quoted context omitted.

This is a very hyperbolic take. Police do not have access to the cameras, only the server stored footage, which is both optional to share and optional to even participate in.

> Police do not have access to the cameras, only the server stored footage, which is both optional to share Ring lets police know that potential video evidence exists, and with that knowledge, they can then get a warrant to obtain the potential evidence from Ring if you choose not to share it.

Thats why I said both are optional. You can choose to never upload the footage in the first place.

Re: A podcast that hacks Ring camera owners live

#60

Once again there is no need for this, anyone using these kinds of systems are literally trading privacy over small value provided feature.

Being able to check on children remotely are not a small value to most working parents, or at least, not particularly smaller than most tech improvements in life.
Post reply on HN