Ring Doorbell App Packed with Third-Party Trackers
eff.org
eff.org
Consumers increasingly don’t care that “the lawyers said it was OK because it’s on page 73 subsection C line 4 of the use agreement For the product.” Privacy is the new black.
Things like this do take time. New companies are being built right now that plan to base their entire identity on personal privacy and respect. Someone is building the next generation of competing products that offer privacy as a priority feature. I would cite Apple as a potential candidate in this pack with some caveats and unknowns...
Trust is a tricky thing to establish and virtually impossible to regain. For me, it's not hard to initially gain my trust if the intent is clear. If I feel the vendor of my home security product is actually trying to use the best techniques, encryption schemes, etc. to protect me, I will be much more likely to trust the solution. If I see buzzwordy bullshit on the box or get a whiff of negative experience or intent from other users (whom I trust), you are immediately starting out with -10 to charisma. Good luck getting out of that hole.
The bigger challenge is making people care, they don't understand how their private information gets weaponized against them, usually to manipulate them to spend more.
Just look at the popularity of streaming models, "I know Facebook listens to my conversations but what can I do?" type conversations, the prevalence of porn games on Steam (which broadcasts what you're currently playing to friends and anyone who looks at your profile), and the popularity of porn tube sites
This isn't merely "compartmentalizing their dalliances," it's compartmentalization of public vs private (or at least quasi-private) self.
I really don't think that's a fair assessment. Yes, people are comfortable living their lives in the open, and people do prefer convenience, but is that really because they don't care about privacy? Or is it more because we have all the abilities to do this?
If you grew up before that ability, did you really have all that privacy? Or did you only have it because of the lack of technology, and not by choice.
> the prevalence of porn games on Steam (which broadcasts what you're currently playing to friends and anyone who looks at your profile), and the popularity of porn tube sites
What does this has to do with privacy? Maybe the current generation is just more open about the fact that they look at porn, or play some porn game. It's really not a taboo subject anymore, we all know everyone does it, so why hide it?
I'm sure.
My daughters generation isn't fazed in the least by being bombarded by ads, and I've even heard some of her friends express (paraphrased) "why worry...everyone has something embarrassing on the Net".
Ring is (apparently) wildly popular. I know dozens of houses in my neighborhood who have installed it, and many of them think the privacy invading parts are, at worst, a 'necessary evil', and some folks think the parts like "open access for LEA" are awesome. I've only talked to perhaps 2 homes where they were "I'm not comfortable with that".
Trust is a tricky thing to establish and virtually impossible to regain.
I don't disagree, but I don't think 'trust' is still built on the things it used to be built on.
At the end of the day, I think privacy loss will have to have a materially negative impact on people's lives before they start to care enough to change their behavior. Right now, the only material negative impact requires what I would characterize as fear mongering.
Imagine being able to type in anyone's name and see their entire search history for the last 10 years. It would be total chaos. We'd have a constitutional amendment enforcing digital privacy within a few months.
Any one of these on its own should be enough but i'm not convinced the average person on the street could tell you what the deal was with any of these scandals.
E.g.: When a wave of echo users are blackmailed after their private conversations or sexcapades are snooped on, then you’d see outcry.
Incognito mode does literally nothing. You're still doing your Google search from the same IP address so they still know it's you and store it the same as anything else.
The only way something even as bad as what you stated will cause a change is if it affects politicians directly and they have personal messages and DM's with back-door dealings revealed that make them look bad. Sadly this is typically the only way things get done now is if there's some personal vested interest in the lawmaker.
I am honestly not sure what would have to happen. Cynical part of me thinks a powerful senator needs to be seriously compromised, exposed and then, if he/she retains power, things might change a little.
Another option is to attempt to run yourself and be the change you want to see, but I have charisma of a wet blanket so it is not an option for me.
Well, sure, because "a breach" isn't anything scary in-and-of-itself, it's just the possibility of something scary.
If tons of people were suddenly victims of credit-card fraud or identity fraud due to the breaches, I don't think that would have been desensitizing in the same way, because that's a real consequence, not just the possibility of one.
South Park plot, Danish Trolls
From what I've seen the most important factors in customer use and purchasing behavior are user experience, user experience, user experience, user experience, and user experience, in that order. Did I mention user experience?
I've even been a little shocked in the B2B market by how rarely corporate customers ask about privacy or security. Only the most seriously security-conscious customers have ever asked my company about e.g. what kind of crypto we use, and these are people dealing with financial or national security data. Everyone else seems to not even care.
Someone on reddit was making a statement about how they didn't care that X product was secure. So I entered their username into one of these reddit user analyzers. After I asked them how their dog was enjoying the weather in (wherever they were), they promptly deleted those messages and their account.
It absolutely is not. There is no evidence of this. Also, why do I keep seeing privacy stories about only one of the video doorbell vendors?
You can argue how successful their privacy-first search engine is or isn’t going to be. But I think this is yet more evidence that the pendulum of privacy is starting to swing back in the opposite direction.
This is the beginning of change.
When people are willing to pay more for privacy focused products, then we'll know that the tide has turned.
Decentralization seems like the only good outcome for privacy but it seems unlikely. Privacy has a monetary value and the simple fact is that most people are willing to trade it for very little.
The move for decentralization seems dwindling but I have hope. If companies become the target of sophisticated cyber attacks, there will emerge an economic opportunity for decentralization.
Or when politicians realize that people care and start including stricter laws as part of their electoral campaigns. Privacy shouldn't have to come at a cost.
My internet connected device (not factory IoT) goes through extensive lengths to not ask for a password or ask the user to make an account or provide any data outside exactly what I need to do the job. It’s a lot more work.
I can't manage this per device. Some, I don't want to, and most, I can't. Let's move the bandaid from the fingers to the wrist. Sell me a privacy aware router that sends 30% of my packets to 0.0.0.0.
Yes, yes it will be another page from the arm's race. Yes, websites will stop rendering content for not letting the tracking get through. I don't care, I live a year at a time and that is how this race is run. We won't win it, but we can die before we finish.
While an ad-blocker will only work on devices that can install one, a PiHole will drop traffic you don't want regardless of the device requesting it.
Very useful, and no subscription needed.
Is that not sufficient for what you need?
They can easily be connected to zone minder, or any software that can take a rtsp:// URL. Even handles motion detection for specific areas of camera, so you can include the driveway but exclude the sidewalk. You can have it email or upload videos... without access to any reolink related cloud.
So you could easily put them in production with zero network access and let something you control notify you with images or video clips for any activity.
There's numerous cheap products, but the reolink seems to be one of the better ones that play well with others and doesn't require any WAN network access.
Ubiquiti and Axis also have some very nice products, but generally are more expensive.
There's quite a few solutions in this space: free, freemium, and commercial.
Blue Iris seems to be the overall favorite, and it's pretty inexpensive considering the fact that it seems to be so well regarded. I don't have Windows on my network, and I was strongly considering running BI on KVM, but I don't think my old server is beefy enough to reliably run windows with video software. I was also looking into building a box for it, but it turns out buying a used Optiplex on Ebay was cheaper and should be more than enough for tracking a few cameras.
I'll be setting it up this weekend, so I don't have much of my own experience to share, yet.
Maybe even use an esp32 cam board instead of a whole raspberry pi:
https://randomnerdtutorials.com/esp32-cam-video-streaming-we...
Note: one disappointment was that the app automatically reached out to an Amcrest server by default (I assume) on the assumption that everyone wants access to their home doorbell cam from outside the network ... I could not find a setting in the app so just took care of it the usual way—blocked it with the firewall. Regardless, it still works in this config.
Ever since I blocked the outgoing connection via firewall, the app now says my camera is offline. That being said, the camera feed is still working in Home Assistant, which is all I wanted. If you were using HA and wanted more functionality (audio, etc), it does appear to be available.
[0] https://www.theverge.com/2019/12/30/21042974/wyze-server-bre...
At $25 to replace, it's probably worth risking bricking it to try out alternative firmware: https://github.com/openipcamera/openipc-firmware
This is a non-starter for me since none of the places I would want to put a camera have an Ethernet jack available.
Which is still a nonstarter for me, since none of the locations I would want to put a camera have an electrical jack handy, and many of them don't get enough sunlight to make a solar panel a viable option.
Yes.
I don't need constant streaming of video, only when an event occurs that needs to be recorded.
Security cameras will have motion sensors built in. Recording would be elsewhere, the camera would just need to stream video for some configurable time if the motion sensor detects an event.
(This is all functionality built into Ring cameras, so for anyone looking for an alternative to them it doesn't seem at all unreasonable to me.)
See https://www.eufylife.com/products/604/654/battery-camera
It's a nice clean mount, I just use the template, drill a 1/2" or so hole for the PoE cable, and then 3 screws to finish the mount. It looks nice and clean, works great, never runs out of power, and is never impacted by the random Wifi issues.
Sure it's a pain to run cat5 everywhere, but I haven't found a better solution, none of my camera locations had power.
It's a little annoying Protect doesn't have a software install but the legacy unifi video still work fine. I put in ~5 cameras over the last few weeks and been really happy with them.
I was this || close to not going unifi because it wasn't clear what the longtime support for unifi video was. I'm still not super-happy with that aspect as it's not clear if the hardware is tied to protect or not.
I lose that if I switch to their custom hardware. I've also heard it doesn't scale well to multiple users or larger numbers of cameras.
I'm probably not a good example, I live in a small apartment, don't have any valuables besides passports and loose change. I just don't see much of a point for having cameras. Instead I focus on deterring casual burglars by using semi-intelligent timer-based lights plus a simple radio tuned to a station with lots of talking when we're away from home. Perhaps a security cam has a deterring aspect, but not sure of the legality of it in Germany where I live, and I guess a dummy camera would achieve a similar effect as a real one?
What am I missing? :)
The cameras can read the license numbers of cars going up and down my dead end street, and have a NTP synced time stamp on them. So I have reported license plate numbers to the police a few times when various neighborhood issues have come up.
But no, I don't think it will magically arrest someone breaking into my house. But they are still pretty useful. Did someone leave a package on my front door? Is my kids friend's parent here for pickup/drop off? Did the garbage truck get here yet? WTF is that loud truck noise out front? Is that knock at the door someone with a clip board? Or someone trying to get me to believe in their god?
One thing it does help, is that at least in my area it's common for a thief to knock to see if anyone is home, then break down that door or force a rear door to enter the house is nobody answers. So being able to see and even respond to the knocker might well prevent a breakin, even if you aren't physically there.
But at least if you know something is happening in real-time, motion triggers being the most important, there is at least some chance to intervene or call the police depending on the circumstances. Even if you can't stop them, speed is key, and if they are on foot they could be caught in the area afterwards with vague id such as clothing only. Capturing a license plate is probably optimal though, if they aren't on foot. Cameras are very good these days - HD and higher 30/60fps video - not the pixelated/blocky/useless recordings of 10 years ago.
Also good to know ahead of time if there is anyone snooping around looking for easy targets (as small-time burglars do). Some systems do also have monitoring services.
Otherwise yeah, cameras are at best a deterrent and source of evidence, nothing more as a passive device. Best security system I've ever had was a German Shepherd. Fully autonomous deterrent + active response if necessary :)
And if it's just a security camera watching my property/car, then a dumb one sounds fine and cheaper. Not to mention it'll actually look like a security camera which is arguably more valuable as a deterrent.
* rarely that local.
But if you live in a rural area, things are completely different. Which from my understanding is the same as EU for the most part.
Over literally thousands of deliveries during that time, the number that have disappeared mysteriously is under 1%. In fact, more have not been delivered at all (i.e., fraud on the part of the delivery person) than have been stolen.
https://www.nytimes.com/2019/12/02/nyregion/online-shopping-...
So, it's pretty much priced into their margins already.
When I bring the card to post office they scan the barcode then send someone out back to fetch my package they ask me for some ID and check the name and address on the id with the name + address on the package. No fuss no drama. The idea of leaving package on doorstep seems bizarre.
In most of Europe a mailbox looks like this: https://imgur.com/ppSrO1W
[0] https://www.lesswrong.com/posts/Hifamb4LTgQooDBYj/worth-reme...
I speak from experience when I say they tend not to care about traditional 'dumb' cameras as, generally, nobody is going to be watching them until after the act.
Neither is really a great option in the US because:
most families have both adults working.
Other than a handful of cities, people are so spread out that having enough secure depot's in the right locations would be astronomically expensive.
...like a Post Office?
https://www.quora.com/Will-FedEx-deliver-my-package-to-my-lo...
When I last lived in a rural area, the UPS guy would leave packages inside my unlocked car.
-send it to your workplace if it is allowed
-send it to an amazon locker and pick it up on the way home.
If you have it sent to your house and you're not in, a lot of the time it gets dropped off at a neighbours house. I've taken in a few parcels when I've been working from home.
It is true that the local depot for other parcel service (DPD etc) can be quite far away, but those services usually offer a a number of repeat delivery attempts or an option to leave with a neighbour.
The number of working adults in a household is irrelevant to delivering parcels securely.
That's not always a realistic option. I'd have to go pretty far out of my way to get to the nearest Amazon locker. And it only works if your packages are coming from Amazon.
Nowadays there are companies that offer evening time home delivery so that you can always be there.
It's just mostly people aren't used to doing that and are hard to change. People often just send packages to work or a friends house instead. With access points, they can and will return a package to sender beyond a certain time.
I'd say that about half of the packages that get delivered where I work are for individuals getting their personal stuff.
Most people prefer to have it left on their doorstep because the other options are a bit of a hassle.
It's not the lack of localness that's the problem for me in the UK, it's more that most depots are only open 9-5 when people are at work. If you have anything resembling a long commute (particularly by public transport) then you can get really screwed over, especially if you can't drive for whatever reason you pretty much have to take half a day off to collect your package in many cases.
I try to avoid using UPS when I can, since they are the most user hostile delivery service in my area. I have more of a chance of getting a package on time when they leave it on my porch unattended.
Amazon has "Amazon Lockers" that are available in many places in the US, many of which are open extended hours, and some of which are open 24x7.
These are not the only options.
Even the USPS has Post Office Boxes, and many US Post Offices have external spaces where the PO Boxes are accessible 24x7.
I think it's true that across most of the U.S. if it weren't safe to leave a package at one's house then people would be up in arms demanding that the police do their jobs. ISTR that the U.K. crime rate is about 2½ times that of the U.S.
This was such a terrible experience the 2 times in my life that I've been forced to do it, that I still remember both of them vividly almost 15 years later. You can be sure I'll never do that again regardless of the purchase or price. There is nothing for sale anywhere on this earth that would be worth it.
> If they decide to leave it outside my door and it gets stolen, I fully expect (and will get) another one delivered at no cost to me, other than the time penalty.
That's exactly what happened the one and only time I've had a package stolen from my porch. It was an external hard drive worth around $100. Amazon sent me a new one immediately. I even tried getting the serial number out of them (at the request of the police) and they were like "haha, no. Here's free one day shipping on your replacement, and we consider this matter closed."
What’s more interesting is that it could be argued these fall under the intent of the EU cookie directive (even though in a lot of cases they don’t actually use cookies). The only app I have seen asking for cookie like consent is Airbnb (who use all of these same services and more)
Says who, the company itself? Why install trackers if you're not going to use them?
It’s the equivalent of Google Analytics.
Now how those companies then use the data they collect as part of providing analytics is another question (and why lots of people prefer to block Google Analytics for example)
True. This is why I have to firewall off all apps so that they can't communicate out without my permission. This is also the primary reason why I'm leaving the smartphone ecosystem entirely.
The invasiveness of apps is intolerable to me, getting worse, and getting increasingly hard to mitigate.
Wait until the BBC finds out how many of us are giving Amazon user data. (I mean, it's s3 and RDS, but that clarification would be overly pedantic)
Facebook and Google on the other hand make their money from stalking people and developers are giving them data in a nice standardised format.
Amazon is very much the latter and that would seem to provide plenty of incentive to do dig through data / recognize the value / use it as they wish.
I'm sure they do plenty of analytics on data from their own platforms and that considerable effort could easily be extended to include any other data that they have access to.
[1] https://www.geekwire.com/2019/amazon-gaining-google-search-a...
Yet React and Angular are quite popular
they definitely do this for physical goods so i'm not naive enough to think they aren't talented enough to do it digitally.
But I don't think Amazon will try to dumpster dive your encrypted S3 buckets in the process of doing the above. At least, not yet.
Google and Facebook only have advertising; they have nothing to lose by being unethical and/or breaking privacy laws like they do with the GDPR.
Do we know that the privacy policy/terms of service for these services allow Google/Facebook to use the data in the way that the BBC article seems worried about?
And before you say that "it doesn't matter what the ToS says", it does very much matter, breaking a ToS would paint a very big target no these companies, there are tons of lawyers out there that would love to catch companies at this, easy money.
There are thousands of companies breaking the GDPR (Facebook and Google included) and yet I have yet to see the tons of lawyers going after the easy money. Companies keep doing it because they know the regulation isn’t enforced.
Tracking everything you can about your users so advertisers can better target you is evil.
Capturing all the local variables during some unexpected Exception (that might happen to include some user data) for the purpose of debugging is not even remotely evil.
User-data is totally fine to have, it's what you _do_ with it that matters
Unless the user explicitly opts into having that data recorded, it isn't ok to stockpile it, regardless if the intent behind it.
The path to hell is paved with good intentions.
I agree that using user-data outside of some agreement is bad (and illegal under the GDPR), but I believe that an implicit agreement exists between web-server provider and user that their data will be used for the mechanical operation of the website, including logging stack-traces. Otherwise TCP/IP wouldn't work.
I've love to get a hangout/signal/IM text identifying anything approaching my door without having to look at a picture. Bonus if the face recognition is good enough to recognize family.
Our decision to use the Raspberry Pi 4 and not a proprietary development board was due to the ease in which AIKEA can be recycled into other projects and devices, should backers no longer need a home security device.
nice
Even though BBC purposefully puts the wrong thing in the title for clicks, I would hope that HN users would pay more attention to detail.
In other news, smartphones spy on you.
I hope I really don't have to explain the implication in this statement of how the doorbell sits there, records/listens, and then sends out data to FB/Google.
Versus saying that a smartphone app collects tracking analytics, like pretty much every other major app out there.
Is there an opt-out? Or, more importantly, was there an explicit opt-in?
Data from crashes on my device is still my data, not Google's. Google can pop up an alert telling me things went pear-shaped, and then ask to send it back to the devs for analysis.
You're not wrong about ownership of data. But highlighting Ring and Google in this manner is some seriously biased and dishonest reporting.
If it really were just crash reporting, this would have probably gone unreported on.
The bar to deciding that Google is getting user's data somehow and this is newsworthy is lower, and requires no grasp of underlying details. Technology journalists are often journalists first, and technologists second if at all. I don't blame them, it's the nature of the job.
How do you know this?
Is it "pedantic hand-wringing" to not want my DNA analyzed by an advertising company as well?
The bar should be a lot higher for them, it's not some free tic-tac-toe app.
Not by me. I'm not going to debug the app; I'm just going to kill it and restart it. If the developer of the app wants my data to help his debugging, he needs to ask.
> if an action you took on the client causes a crash on my server I'm not going to ask you for permission to look at my crash logs.
Of course not, but your crash logs aren't coming from my phone. If you want to look at data from my phone, you need to ask.
https://reports.exodus-privacy.eu.org/en/reports/com.ringapp...
Still sucks, but to iPhone users, this just validates their Apple purchase even more.
No claims in the article were made regarding the iOS version of the app, so I don't know why we should jump to the conclusion that the iOS version doesn't track what you do and report to 3rd parties.
It looks like the iOS app was not included in the test at all, so no conclusion can be assumed.
Likewise, if the reverse were true, and it only dealt with iPhone, then it should say iPhone in the headline because it didn’t address Android.
This isn’t a preference argument for one phone or the other - it’s about clarity of what the article is about.
Those trackers are commonly used across platforms.
Growth at all costs.
A growth at all costs mindset in many cases leads to redundant and irresponsible overuse.
Instructions on changing DNS settings https://joyofandroid.com/how-to-change-dns-on-android/
What do people on HN find acceptable in the apps they use? As a developer I want some basic analytics and crash reporting so I'm not just stumbling in the dark but I would hate for my users to say that I'm tracking them involuntarily. Is there a way to strike a balance that seems fair? Are there particular services people trust?
But as soon as that data is sold, or used to somehow push sales or content, then it becomes a problem for me.
I've already mostly dropped Facebook and Google, it'll be harder for me to ween myself off of Amazon.
It's one thing to have a business model where it's understood that a service is free in exchange for user data but what we are seeing increasingly is this greed where its not enough to sell a good or service for cash because that would be leaving money on the table. These companies seem to have an expectation and entitlement that your data is part of the business model despite not disclosing that to their customers.
- creates GIF for faster viewing through the nextcloud app. - updates info for current status of the ring devices.
https://gist.github.com/parvez/f8375438070fa3b0572013efbe72c...
It could be enhanced to support SIP for live viewing.
I’m a long time Ring customer and this is completely unacceptable.
The various privacy commissions (PC) in the EU are actually talking to each other. The privacy invading companies are testing whether or not they can force their case to be decided only in the jurisdiction of the PC in Ireland. (legally, this is just nonsense... )
I've seen many try this tactic and it has always failed. I'm guessing they are using this as a delay tactic to prevent it being decided by the courts.
Let's say Apple pre installs Google+ on all its phones. Then I want to know how much apple got paid for this, i.e. how many cents is a users privacy worth to them. And how much money did Google make by using this data, i.e. how much was the data really worth.
Because until we have such data, companies can always hide behind phrases such as "... share with partners ... to provide relevant services" and all that nonsense.
Having said that, I’ve always wondered the same for TV ads. Let’s say I wanted the option to pay extra to never see ads, how much would that be? Why doesn’t the market give me that option?
Note: Maybe all apps shouldnt be tracking this. But this is currently how analytics in apps work.
But I get your point. A lot of this IoT stuff is mostly pointless and serves only to make people feel like they are living in the future.
I...huh? How?
Are you a darknet dropshipper? (Nothing wrong with that, just can't imagine what carrier doesn't give you a tracking number that you can get alerts on delivery/check status of.)
However, it and the other cameras I have (including an actually decent one in the entryway) almost eliminated the random door-to-door solicitors and people leaving flyers all over my front door!
It's also really funny because people hate cameras. I've seen someone cover their face before pushing the doorbell button and then walk away because they felt too afraid to be seen on camera.
OTOH, the ring app is really, really terrible. Woof! If you install it and leave it on defaults, it'll notify you about anything your neighbors post. And boy the things they post lol. Kid riding their bike by? SUSPICIOUS! EVERYONE KEEP AN EYE OUT! Random dog?
Not really. If you aren't paying for the product, then you certainly are the product. If you are paying for the product, then you may still be the product, but you also may not. It all boils down in that case to how trustworthy and greedy the vendor is.
I remember buying a PS4 and still had to opt-out of data collection and then change like 20 settings on their bullshit social network I don't even want to use.
Windows 10 is paid and yet it has ads and insane data collection.
When I made the GPT-2 Chess notebook (sigh... do I link to it and risk seeming like I'm plugging my stuff, or let people google for it? Whatever: https://colab.research.google.com/drive/12hlppt1f2N0L9Orp8YC...) one of the first questions a reporter asked me was "How many people played it?"
I had to be like "I have no idea. A few thousand at least, based on bandwidth bills."
Then they started asking if I was tracking the games. "Nope. I don't like apps that track data, so I didn't want to make one here."
And at the end of it, I was like... this is stupid. I should have tracked clicks and tracked the games.
We should have a clear distinction between "user data" and "data that common people might reasonably care about being tracked." The headlines are a strange game of telephone. Every app tracks data. That's what most apps are for.
Why do you feel this way? I agree with your positions at the beginning ("I don't like apps that track data, so I didn't want to make one here.") and the end ("Every app tracks data. That's what most apps are for."), but I don't see why that would cause you to want to have tracked games and interaction data on your own project.
Perhaps if I'd ever built something that got popular I'd know the feeling better.
Can't use the human inputs to improve anything if the data doesn't exist.
Lichess tracks all games, for example, and I don't think they ask for permission. Is that a bad thing? I was forced to conclude it's probably fine, but perhaps an argument could be made.
A developer might react differently if 10 people used their software or 10,000. Or even if 10 people used the program 1000 times vs 10,000 people using it once.
Not to mention that it's hard to iterate on something and make clear improvements if you can't tell how the software is being used. Sure you can read forums, tickets, issues, etc. But if your settings allow 1000 different configurations and 99% of your users use one of 5 different configurations that can be a very useful thing to know.
Nice idea in theory, exploitive data mine in practice. I hate it.
You could argue that the doorbell transmits the video/audio over the internet, but that transport is encrypted to the Ring app, and its deleted off of AWS after its viewed on the App.
If you really want privacy, you should also return your cellphone and go back to using a flip phone.
How do you know this? And how are you sure that information isn't shared before being deleted?
Also, it's not only about privacy (although I do think people should care a bit more about it than they do on average). Data stored and sold makes money that is dependent on you to produce, yet you get no compensation for it. Many people have a problem with that, including myself.
Ring states it on their website. https://shop.ring.com/pages/privacy
I mean, nobody REALLY knows, but if that's the standard you are going to use, then you pretty much have to assume that any company can and will spy on you, and apply the same critique to them.
Based on reports and news, Amazon has been perhaps the best out of the big companies when dealing with privacy, as they are fairly transparent on the data they collect for what use, and had not had any major cases of leaks despite them perhaps having the best data set of peoples behavior with shopping history which is the most relevant to advertisers.
Being that Ring uses AWS for back end, as can be verified through network traffic inspection, I personally don't see any red flags with them saying they delete the data.
>Data stored and sold makes money that is dependent on you to produce, yet you get no compensation for it.
This is HORRIBLY wrong. Gmail, youtube, reddit and most everything that is free on the web and on mobile is your compensation for your data. Yes, companies make profit, but they still spend that advertising revenue on hosting and maintaining that service, and recouping the initial investment they put into building the thing.
That is the standard I use and I do apply the same critique to every company.
> Gmail, youtube, reddit and most everything that is free on the web and on mobile is your compensation for your data.
First off, I don't use all of those services. According to your logic, you and every other person who has data in their system and is not using a service is owed cold hard cash. Secondly, the value that I get out of using them is not commensurate with the profit they are making. These companies are making EXORBITANT amounts of money off of peoples data. It is in no way acceptable compensation. Third, I can't opt out of them using the data, even if I stop using a service or if I never used their service at all.
Then why are you on HN? They could be collecting your IP and data on you.
>First off, I don't use all of those services. According to your logic, you and every other person who has data in their system and is not using a service is owed cold hard cash.
The only data that exists for people that don't use services is 3p tracking data, which is from people visiting websites, that are supported by ads. So yes, if you view content on a website and a tracking cookie or pixel records you, that is you using the website, and the advertiser is paying the host for this which allows the host to continue hosing the website.
> These companies are making EXORBITANT amounts of money off of peoples data
Whoa, this is like almost a communism argument. Dictating how much money anyone should make is not a good road to go down on. There is nothing wrong with companies generating profit, they are capitalizing on supply versus demand.
They pitch their Ring doorbells as a surveillance network to police departments, provide law enforcement with an easy to use interface and map of their camera network, and allow police to go after people who choose not to share their recordings without a warrant.
With a warrant or subpeona, all police have to do is serve it to Amazon, and the company can hand over your recordings without ever letting you know.
Or how about an iPhone with minimal or no 3rd party apps?
Which is practically impossible unfortunately because in order operate in the modern world you need at least a few 3rd party messenger apps, your bank's app and maybe a few more. Theoretically, however, I can have a phone free from social platforms and 3rd party analytics platforms like MixPanel or AppsFlyer, with regard to whom I have absolute zero trust.
I think that this may be true for convenient operation, but not for operating period. I have none of these apps on my phone and, in fact, don't regularly use my phone for anything but receiving calls and listening to audiobooks. (Oh, and alarms, and probably some other stuff I'm forgetting; but not otherwise for interacting with the outside world.)
If you ever take a brand new iPhone and connect it to wifi and inspect the traffic in this manner, you will see all the crap it sends to apple servers.
On the other hand, I also have a custom rooted android phone, with no google apps and minimal 3d party apps (use the mobile browser for most stuff). If you inspect it in the same manner as above, the only requests it makes when it turns on is to the ntp time server, which I could probably kill with a firewall if I cared enough, making it 100% silent until I use an app.
If you want privacy, you get it yourself.
If you are remotely concerned about handing data to a 3rd party then I would just not use this doorbell. You can probably find a "dumber" one or construct one yourself. I might end up doing it, too, tbh.
I won’t apologize for Ring being a bad product while this and every other related article supports that they take ownership and share your data without your approval.
Mine was a gift otherwise I’d have returned it too.