{"id":17131,"date":"2019-12-09T10:10:02","date_gmt":"2019-12-09T18:10:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/12\/09\/news-10867\/"},"modified":"2019-12-09T10:10:02","modified_gmt":"2019-12-09T18:10:02","slug":"news-10867","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/12\/09\/news-10867\/","title":{"rendered":"Please don&#8217;t buy this: smart doorbells"},"content":{"rendered":"<p><strong>Credit to Author: David Ruiz| Date: Mon, 09 Dec 2019 17:15:56 +0000<\/strong><\/p>\n<p>Though Black Friday and Cyber Monday are over, the two shopping holidays were just precursors to the larger Christmas season\u2014a time of year when online packages pile high on doorsteps and front porches around the world. <\/p>\n<p><a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/blog.ring.com\/2019\/11\/29\/10-safety-tips-to-protect-your-packages-this-holiday-season\/\" target=\"_blank\">According to some companies<\/a>, it&#8217;s only logical to want to protect these packages from theft, and wouldn\u2019t it just so happen that these same companies have the perfect device to do that\u2014smart doorbells.  <\/p>\n<p>Equipped with cameras and constantly connected to the Internet, smart doorbells provide users with 24-hour video feeds of the view from their front doors, capturing everything that happens when a user is away at work or sleeping in bed. <\/p>\n<p>Some devices, like the Eufy Video Doorbell, can allegedly differentiate between a person dropping off a package and, say, a very bold, very unchill goat marching up to the front door (<a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/youtu.be\/3M8iCIjnpqk?t=67\" data-rel=\"lightbox-video-0\" target=\"_blank\">it really happened<\/a>). Others, like Google\u2019s Nest Hello, proclaim to be able to \u201crecognize packages and familiar faces.\u201d Many more, including Arlo\u2019s Video Doorbell and Netatmo\u2019s Smart Video Doorbell, can deliver notifications to users whenever motion or sound are detected nearby. <\/p>\n<p>The selling point for smart doorbells is simple: total vigilance in the palms of your hands. But if you look closer, it turns out a privatized neighborhood surveillance network is a bad idea. <\/p>\n<p>To start, some of the more popular smart doorbell products have suffered severe cybersecurity vulnerabilities, while others lacked basic functionality upon launch. Worse, the data privacy practices at one major smart doorbell maker resulted in wanton employee access to users\u2019 neighborhood videos. Finally, partnerships between hundreds of police departments and one smart doorbell maker have created a world in which police can make broad, multi-home requests for user videos without needing to show evidence of a crime. <\/p>\n<p>The path to allegedly improved physical security shouldn\u2019t involve faulty cybersecurity or invasions of privacy. <\/p>\n<p>Here are some of the concerns that cybersecurity researchers, lawmakers, and online privacy advocates have found with smart doorbells. <\/p>\n<h3><strong>Congress fires off several questions on privacy<\/strong><\/h3>\n<p>On November 20, relying on public reports from earlier in the year, five US Senators sent a letter to Amazon CEO Jeff Bezos, <a href=\"https:\/\/theintercept.com\/2019\/11\/20\/amazon-ring-security-senate\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">demanding answers about a smart doorbell company<\/a> that Bezos\u2019 own online retail giant swallowed up for $839 million\u2014Ring. <\/p>\n<p>According to an <a href=\"https:\/\/theintercept.com\/2019\/01\/10\/amazon-ring-security-camera\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">investigation by The Intercept<\/a> cited by the senators, beginning in 2016, Ring \u201cprovided its Ukraine-based&nbsp;research and development&nbsp;team virtually unfettered access to a folder on Amazon\u2019s S3 cloud storage service that contained every video created by every Ring camera around the world.\u201d<\/p>\n<p>The Intercept\u2019s source also said that \u201cat the time the Ukrainian access was provided, the video files were left unencrypted, the source said, because of Ring leadership\u2019s \u2018sense that encryption would make the company less valuable,\u2019 owing to the expense of implementing encryption and lost revenue opportunities due to restricted access.\u201d<\/p>\n<p>Not only that, but, according to the Intercept, Ring also \u201cunnecessarily\u201d provided company executives and engineers with access to \u201cround-the-clock live feeds\u201d of some customers\u2019 cameras. For Ring employees who had this type of access, all they needed to actually view videos, The Intercept reported, was a customer\u2019s email address. <\/p>\n<p>The senators, in their letter, were incensed. <\/p>\n<p>\u201cAmericans who make the choice to install Ring products in and outside their homes do so under the assumption that they are\u2014as your website proclaims\u2014\u2018making the neighborhood safer,\u2019\u201d <a href=\"https:\/\/www.wyden.senate.gov\/imo\/media\/doc\/112019%20Wyden%20Markey%20Can%20Hollen%20Coons%20Peters%20Ring%20Letter%20to%20Amazon.pdf\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">the senators wrote<\/a>. \u201cAs such, the American people have a right to know who else is looking at the data they provide to Ring, and if that data is secure from hackers.\u201d <\/p>\n<p>The lawmakers\u2019 questions came hot on the heels of <a href=\"https:\/\/www.washingtonpost.com\/technology\/2019\/09\/05\/sen-markey-seeks-answers-ring-doorbell-camera-police-network\/\">Senator Ed Markey\u2019s own efforts in September into untangling Ring\u2019s data privacy practices for children<\/a>. How, for instance, does the company ensure that children\u2019s likenesses won\u2019t be recorded and stored indefinitely by Ring devices, the senator asked. <\/p>\n<p>According to The Washington Post, when Amazon responded to Sen. Markey\u2019s questions, the answers potentially came up short: <\/p>\n<p>\u201cWhen asked by Markey how the company ensured that its cameras would not record children, [Amazon Vice President of Public Policy Brian Huseman] wrote that no such oversight system existed: Its customers \u2018own and control their video recordings,\u2019 and \u2018similar to any security camera, Ring has no way to know or verify that a child has come within range of a device.\u2019\u201d<\/p>\n<p>But Sen. Markey\u2019s original request did not just focus on data privacy protections for children. The Senator also wanted clear answers on an internal effort that Amazon had provided scant information on until this year\u2014its partnerships with hundreds of police departments across the country. <\/p>\n<h3><strong>Police partnerships<\/strong><\/h3>\n<p>In August, The Washington Post reported that <a href=\"https:\/\/www.washingtonpost.com\/technology\/2019\/08\/28\/doorbell-camera-firm-ring-has-partnered-with-police-forces-extending-surveillance-reach\/\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\"Ring had forged video-sharing relationships with more than 400 police forces in the US (opens in a new tab)\">Ring had forged video-sharing relationships with more than 400 police forces in the US<\/a>. Today, that number has grown to at least 677\u2014an increase of roughly 50 percent in just four months. <\/p>\n<p>The video-sharing partnerships are simple. <\/p>\n<p>By partnering with Ring, local police forces gain the privilege of requesting up to 12 hours of video spanning a 45-day period from all Ring devices that are included within half a square mile of a suspected crime scene. Police officers request video directly from Ring owners, and do not need to show evidence of a crime or obtain a warrant before asking for this data. <\/p>\n<p>Once the video is in their hands, police can, <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.washingtonpost.com\/technology\/2019\/11\/19\/police-can-keep-ring-camera-video-forever-share-with-whomever-theyd-like-company-tells-senator\/\" target=\"_blank\">according to Ring, keep it for however long they wish and share it with whomever they choose<\/a>. The requested videos can sometimes include video that takes place inside a customer\u2019s home, not just outside their front door. <\/p>\n<p>At first blush, this might appear like a one-sided relationship, with police officers gaining access to countless hours of local surveillance for little in return. But Ring has another incentive, far away from its much-trumpeted mission \u201cto reduce crime in neighborhoods.\u201d Ring\u2019s motivations are financial. <\/p>\n<p>According to Gizmodo, for police departments that partner up with Ring to gain access to customer video, Ring gains <a href=\"https:\/\/gizmodo.com\/everything-cops-say-about-amazons-ring-is-scripted-or-a-1836812538\" target=\"_blank\" rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\">near-unprecedented control in how those police officers talk about the company\u2019s products<\/a>. The company, Gizmodo reported, \u201cpre-writes almost all of the messages shared by police across social media, and attempts to legally obligate police to give the company final say on all statements about its products, even those shared with the press.\u201d<\/p>\n<p>Less than one week after Gizmodo\u2019s report, Motherboard obtained documents that included standardized responses for police officers to use on social media when answering questions about Ring. <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"https:\/\/www.vice.com\/en_us\/article\/wjwea4\/revealed-the-secret-scripts-amazon-give-to-cops-to-promote-ring-surveillance-cameras\" target=\"_blank\">The responses, written by Ring, at times directly promote the company&#8217;s products<\/a>. <\/p>\n<p>Further, in the California city of El Monte, police officers offered <a rel=\"noreferrer noopener\" aria-label=\" (opens in a new tab)\" href=\"\u201cLaw%20enforcement%20is%20supposed%20to%20answer%20to%20elected%20officials%20and%20the%20public,%20not%20to%20public%20relations%20operatives%20from%20a%20profit-obsessed%20multinational%20corporation%20that%20has%20no%20ties%20to%20the%20community%20they%20claim%20they're%20protecting.%22\" target=\"_blank\">Ring smart doorbells as an incentive<\/a> for individuals to share information about any crimes they may have witnessed. <\/p>\n<p>The partnerships have inflamed multiple privacy rights advocates. <\/p>\n<p>\u201cLaw enforcement is supposed to answer to elected officials and the public, not to public relations operatives from a profit-obsessed multinational corporation that has no ties to the community they claim they&#8217;re protecting,&#8221; said Evan Greer, deputy director of Fight for the Future, when talking to Vice. <\/p>\n<p>Matthew Guariglia, policy analyst with Electronic Frontier Foundation, <a href=\"https:\/\/www.eff.org\/deeplinks\/2019\/08\/five-concerns-about-amazon-rings-deals-police\">echoed Greer\u2019s points<\/a>:<\/p>\n<p>\u201cThis arrangement makes salespeople out of what should be impartial and trusted protectors of our civic society.\u201d<\/p>\n<h3>Cybersecurity concerns<\/h3>\n<p>When smart doorbells aren\u2019t potentially invading privacy, they might also be lacking the necessary cybersecurity defenses to work as promised. <\/p>\n<p>Last month, a group of cybersecurity researchers from Bitdefender announced that they\u2019d discovered a vulnerability in Ring devices that could have <a href=\"https:\/\/www.cnet.com\/news\/ring-doorbells-had-vulnerability-leaking-wi-fi-login-info-researchers-found\/\">let threat actors swipe a Ring user\u2019s WiFi username and password<\/a>. <\/p>\n<p>The vulnerability, which Ring fixed when it was notified privately about it in the summer, relied on the setup process between a Ring doorbell and a Ring owner\u2019s Wi-Fi network. To properly set up the device, the Ring doorbell needs to send a user\u2019s Wi-Fi network login information to the doorbell. But in that communication, Bitdefender researchers said Ring had been sending the information over an unencrypted network. <\/p>\n<p>Unfortunately, this vulnerability was not the first of its kind. In 2016, a company that tests for security vulnerabilities <a href=\"https:\/\/www.cnet.com\/news\/rings-smart-doorbell-can-leave-your-house-vulnerable-to-hacks\/\">found a flaw in Ring devices<\/a> that could have allowed threat actors to steal WiFi passwords. <\/p>\n<p>Further, this year, another smart doorbell maker suffered so many basic functionality issues that it <a href=\"https:\/\/www.theverge.com\/2019\/4\/26\/18518177\/august-view-doorbell-issue-shipment-stop-testing-refund\">stopped selling its own device just 17 days after its public launch<\/a>. The smart doorbell, the August View, went <a href=\"https:\/\/www.theverge.com\/2019\/11\/5\/20950333\/august-view-video-doorbell-on-sale-again-connectivity-issues-fixed\">back on sale six months<\/a> later.<\/p>\n<h3>Please don&#8217;t buy<\/h3>\n<p>We understand the appeal of these devices. For many users, a smart doorbell is the key piece of technology that, they believe, can help prevent theft in their community, or equip their children with a safe way to check on suspicious home visitors. These devices are, for many, a way to calmer peace of mind. <\/p>\n<p>But the cybersecurity flaws, invasions of privacy, and attempts to make public servants into sales representatives go too far. The very devices purchased for security and safety belie their purpose. <\/p>\n<p>Therefor, this holiday season, we kindly suggest that you please stay away from smart doorbells. Deadbolts will never leak your private info. <\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/please-dont-buy-this\/2019\/12\/please-dont-buy-this-smart-doorbells\/\">Please don&#8217;t buy this: smart doorbells<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/please-dont-buy-this\/2019\/12\/please-dont-buy-this-smart-doorbells\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: David Ruiz| Date: Mon, 09 Dec 2019 17:15:56 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/please-dont-buy-this\/2019\/12\/please-dont-buy-this-smart-doorbells\/' title='Please don't buy this: smart doorbells'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2019\/12\/smart-doorbell-with-hand-approaching.jpg' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>This holiday season, please reconsider buying smart doorbells to protect your online shipments. The cybersecurity and privacy risks are too severe.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/please-dont-buy-this\/\" rel=\"category tag\">Please don&#8217;t buy this<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/amazon\/\" rel=\"tag\">amazon<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/august-view\/\" rel=\"tag\">August View<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/bitdefender\/\" rel=\"tag\">Bitdefender<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/black-friday\/\" rel=\"tag\">black friday<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/christmas\/\" rel=\"tag\">Christmas<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/cyber-monday\/\" rel=\"tag\">cyber monday<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/el-monte\/\" rel=\"tag\">El Monte<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/gizmodo\/\" rel=\"tag\">Gizmodo<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/google-nest-hello\/\" rel=\"tag\">Google Nest Hello<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/jeff-bezos\/\" rel=\"tag\">Jeff Bezos<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/motherboard\/\" rel=\"tag\">Motherboard<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/ring\/\" rel=\"tag\">Ring<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/senator-ed-markey\/\" rel=\"tag\">Senator Ed Markey<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/senator-ron-wyden\/\" rel=\"tag\">Senator Ron Wyden<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/smart-doorbells\/\" rel=\"tag\">smart doorbells<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/the-intercept\/\" rel=\"tag\">The Intercept<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/vice\/\" rel=\"tag\">Vice<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/please-dont-buy-this\/2019\/12\/please-dont-buy-this-smart-doorbells\/' title='Please don't buy this: smart doorbells'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/please-dont-buy-this\/2019\/12\/please-dont-buy-this-smart-doorbells\/\">Please don&#8217;t buy this: smart doorbells<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[5588,23665,23666,11014,397,11015,23667,22368,23668,9671,1726,16778,23437,23669,21975,23670,23671,2127],"class_list":["post-17131","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-amazon","tag-august-view","tag-bitdefender","tag-black-friday","tag-christmas","tag-cyber-monday","tag-el-monte","tag-gizmodo","tag-google-nest-hello","tag-jeff-bezos","tag-motherboard","tag-please-dont-buy-this","tag-ring","tag-senator-ed-markey","tag-senator-ron-wyden","tag-smart-doorbells","tag-the-intercept","tag-vice"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17131","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=17131"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/17131\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=17131"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=17131"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=17131"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}