> The software churns through previously compromised email addresses and passwords to break into Ring cameras at scale.
Given the sensitive nature of cameras in homes, I think Ring should require 2FA.
Given the sensitive nature of cameras in homes, I think Ring should require 2FA.
To add new tokens to your account, you would have to place them on top of the camera, or something.
This makes the attack described in the article basically impossible, and lets the camera vendor sell you tokens if you have multiple family members that want to log in. A win-win!
Easier to remember, and more secure.
(Of course, bad passwords are bad. One time I exposed a mysql database I use for local unit tests to the Internet with the credentials root:test. It was hacked in hours, with a message saying where to send bitcoins to get the database back. Slightly stronger passwords do help with that sort of thing.)