Radio Free never accepts money from corporations, governments or billionaires – keeping the focus on supporting independent media for people, not profits. Since 2010, Radio Free has supported the work of thousands of independent journalists, learn more about how your donation helps improve journalism for everyone.

Make a monthly donation of any amount to support independent media.





Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked

Reporting from BuzzFeed News on Thursday revealed the leak of personal information from 3,672 users of Amazon Ring, just two days after a coalition of groups led by privacy advocates Fight for the Future issued a product warning due to the surveillance camera doorbell’s security and susceptibility to hackers.

“This gives a potential attacker access to view cameras in somebody’s home in some of these cases,” Electronic Frontier Foundation security researcher Cooper Quintin told BuzzFeed News, “that’s a real serious potential invasion of privacy right there.”

Ring reportedly sent a security alert to customers recommending they change passwords.

According to BuzzFeed News

Security experts told BuzzFeed News that the format of the leaked data—which includes username, password, camera name, and time zone in a standardized format—suggests it was taken from a company database. They said data obtained via credential stuffing—when previously-compromised emails and passwords are used to get access to other accounts—would likely not display RIng-specific data like camera names or time zone.

After the reporting’s publication Thursday, New York Times product review vertical Wirecutter announced on Twitter that it would no longer recommend Ring and urged customers with the device to take extensive security measures. 

“In light of recent reports about the security of Ring devices, we’re suspending our recommendation of Ring products and updating affected guides as soon as possible,” tweeted Wirecutter. “Ring owners should turn on 2FA and update their passwords with a new, previously unused one.”

“Amazon is not taking the steps necessary to protect their users,” Fight for the Future chief technology officer Ken Mickles said in a statement.

In a statement to BuzzFeed News, Ring denied there was a “data breach” and pinned the blame for the leak on “bad actors.”

SCROLL TO CONTINUE WITH CONTENT

There’s no way around it. No ads. No billionaires. Just the people who believe in this mission and our work.

Please support Common Dreams today:

<!–
BG Options
/sites/all/modules/custom/ctas/images/june2019/cta-content-mobile-june-2019.jpg (newspaper)
/sites/all/modules/custom/ctas/images/june2019/cta-content-mobile-june-2019_3.jpg (cell)
/sites/all/modules/custom/ctas/images/june2019/cta-content-mobile-june-2019_4.jpg (radio)
/sites/all/modules/custom/ctas/images/august2019/mobile-1.jpg

–>

Also on Thursday, TechCrunch reported that there is a separate cache of over 1,500 Ring passwords on the so-called dark web. 

“The list of passwords was uploaded on Tuesday to an anonymous dark web text-sharing site, commonly used to share stolen passwords and illicit materials,” according to TechCrunch. “A security researcher found the cache of email addresses and passwords, which can be used to log in to and access the cameras, as well as their time zone and the doorbell’s location, such as ‘driveway’ or ‘front door.'”

Fight for the Future’s product warning detailed the concerns over the technology’s vulnerability to hackers and other malicious actors:

Last week, a man hacked into a Ring camera to watch an 8 year old girl and speak to her. He introduced himself as Santa Claus and then proceeded to have a conversation with the young girl through a Ring camera her parents had installed in her bedroom. Since this chilling incident, there have been new reports daily of other users and their families being harassed by hackers who’ve broken into their Ring devices.

This isn’t an isolated incident. Multiple security issues with Ring products, which already raised significant privacy and civil liberties concerns, have been reported over the past several months. Amazon’s Ring doorbells leaked user’s Wi-Fi passwords. Ring’s Neighbors app discloses users’ home addresses. In response to Senate inquiry, Amazon acknowledge they have no safeguards in place to protect users’ footage when shared with 3rd parties. 

It’s not the first controversy for the camera. Ring has been linked to worrying trends in the connection between tech companies and law enforcement, including agreements the company makes with police departments around the country that reportedly do not allow law enforcement officials to disclose.

“There have been a number of pretty stunning breaches with Ring devices in the last few weeks, and it seems to me like Ring is more interested in making friends with and providing information to police than it is in actually protecting its customers’ security,” said Electronic Frontier Foundation’s Quintin.

“For too long, we’ve been sold a false choice between privacy and security,” wrote Evan Greer, campaign director for Fight for the Future, in an opinion piece Tuesday. “It’s more clear every day that more surveillance does not mean more safety, especially for the most vulnerable.”

“Talk to your family and friends and encourage them to do their research before putting any private company’s surveillance devices on your door or in your home,” Greer continued. “In the end, companies like Amazon and Google don’t care about keeping our communities safe; they care about making money.”

Print
Print Share Comment Cite Upload Translate Updates

Leave a Reply

APA

Radio Free | Radio Free (2019-12-19T20:45:41+00:00) Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked. Retrieved from https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/

MLA
" » Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked." Radio Free | Radio Free - Thursday December 19, 2019, https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/
HARVARD
Radio Free | Radio Free Thursday December 19, 2019 » Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked., viewed ,<https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/>
VANCOUVER
Radio Free | Radio Free - » Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked. [Internet]. [Accessed ]. Available from: https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/
CHICAGO
" » Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked." Radio Free | Radio Free - Accessed . https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/
IEEE
" » Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked." Radio Free | Radio Free [Online]. Available: https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/. [Accessed: ]
rf:citation
» Just Two Days After Product Warning Issued for Amazon Ring, Reporting Reveals Data of 3,000 Users Leaked | Radio Free | Radio Free | https://www.radiofree.org/2019/12/19/just-two-days-after-product-warning-issued-for-amazon-ring-reporting-reveals-data-of-3000-users-leaked/ |

Please log in to upload a file.




There are no updates yet.
Click the Upload button above to add an update.

You must be logged in to translate posts. Please log in or register.