What to know before you buy or install an Amazon Ring camera
eff.org
eff.org
That's a pretty uncommon edge case considering that it's usually easier to disable the camera to begin with, e.g. with a paintball gun, than to track down and remove a DVR which could be in an unknown and arbitrarily well-secured location within the building -- or even outside of it. Just because the video storage isn't in the cloud doesn't mean it can't still be offsite.
And it also depends on how serious of crime one is committing. When working for defense attorneys years ago, it was not uncommon to be on a case involving data recovery by the FBI because a person lit the building on fire because there was a camera in their somewhere.
Right. Ring is usually placed in homes. Where is the well-secured location in your average home?
A DVR can be smaller than a Raspberry Pi. Remove any random electrical outlet in the house, put the DVR in the wall behind it and then replace the outlet. Or put it on the underside of your washing machine etc. Can't remove it if you have to disassemble the whole house to find it.
Or just put it inside a safe which is bolted down. There are safes with interior electrical outlets.
I have a Eufy camera setup that uses in-home storage. There’s about a year of data on a 64GB SD card that cost maybe $30.
You’re buying a camera. Amazon is getting a perpetual license to everything that happened in front of your home, forever. The cloud story is about analytics and data mining. You buy a camera, they get a feed.
Did you have to Port forward or set up a VPN for local viewing? Just that will stop 95% of users.
Same box would decrypt data on read for authorized user.
AMZN wants to monetize your feed?
Sell them subscription for access the feed with clear usage license. No sneaky, default, subtle crap "we will use your data and monetize it forever at our will without your concent"
You don't need anywhere near 1TB of storage if you're only storing video when there's motion, and that smaller amount of storage has minimal cost. You also can't really dedup a series of unique videos anyway. And processing and playback cost nothing when done locally; pretty much all the rest of it is software.
All "cloud" really gets you is backups, which is more of a nice-to-have than a necessity for video which is going to get auto-deleted on a schedule regardless and can be manually backed up any time it becomes relevant to retain. You could also get automatic backups without "cloud" for any system that spans multiple sites, which is the case for most businesses and even an individual with any family member or friend who uses the same system.
If the threat model is burglary, no I don't want footage on a local device at all. Or more specifically, I don't want footage only on a local device and, ring or not, the first thing I'll want to do is ship it offsite.
If this is a business or it otherwise has people managing a security office, then local storage (ideally shipping to an offsite location later) should be adequate. Or if the system is well-protected enough that it would take longer to tamper (or destroy it) than law enforcement's response.
If your threat model is this fantasy burglary, the burglars are going to know to simply cut your Internet line before they rob the house to render the cloud-connected shit useless. Then they will just steal the cameras to ensure no local caches push data back up when the Internet is restored.
I don't want to configure, monitor and manage a local DVR -- what do I do when I'm away from home and it fails? What do I do if the burglar finds that expensive looking DVR and steals it? How would I even know if it fails without some external (cloud?) service monitoring it?
These problems are solvable (I use Unifi cameras with a DVR with RAID disks and a hard to find network backup drive, and a monitoring process on my home router that will tell me if the DVR is offline but I'm still subject to failure when I'm away from home), but does the average consumer want to expend the effort to solve them?
- An aggregate of the various security issues that came up so far (with unvalidated rumors filtered).
- Touches upon social issues and medium-term unintended consequences: “instilling paranoia”, and by association social/racial profiling.
- Manages to discuss sensitive topics gently without implicit shaming or talking down to the reader. I think Matthew from EFF has done a good job here
- Both technically correct and easy to understand by non-technologists.
- Easy to link to, from credible source.
Shame that most people who should read this probably won’t stumble across it, at least their technologist friends have a readable article to share.
> Do you want strangers being able to learn your routines by watching you leave and return to your house every day?
But then they follow it up with "a few amazon employees were fired for watching videos" and "the cops might request/warrant your videos" and "some hackers got access and did bad things a few times". That is a comically large gap from strangers watching you every morning and evening to learn your habits.
"Do you want a few amazon employees being able to learn your routines by watching you leave and return to your house every day?" might be more technically expressive but no more accurate and certainly not any more reassuring or comfortable to me.
The part about cops and hackers are separate issues (and lead to more convincing arguments against cops and cloud services more generally) but this seems like an entirely fair assessment.
If you don't trust anybody, the Internet sure is a scary place.
You mean to say this doesn't concern you? That enough PII is being archived in multiple places indefinitely and could be used to build a find grained profile on you?
Imagine how much you can infer just from location data. Sexual orientation. Political affiliation. Religious affiliation. Now imagine what happens when authoritarian regime gains control of such databases. The largest nation on Earth has such a system already - it isn't far fetched.
Likewise for videos of and around my house. The only people capable of watching those feeds are me and those I explicitly choose to share it with. Ring should be E2E encrypted, with any video processing being done before upload or after download. Sharing with the police shouldn't be possible without the police coming to my home asking me for video of a given time period, preferably with a warrant.
I have no problem with storing encrypted video in the cloud, assuming that it's reasonably hard to decrypt and my keys aren't stored anywhere nearby (they should strictly be on the client, out of reach of the cloud service). If I want to send a video to someone, the service should download it, decrypt it locally, and then send it over my encrypted channel of choice.
I really don't understand why we put up with anything less. It's incredibly cheap to do get a chip these days that can do video processing on the client, so why is the cloud used for anything other than encrypted video storage and retrieval?
Based on talking to your neighbours, or is this an assumption based on only being able to see the outside of your neighbours houses?
Why should we go through the risk? Just encrypting everything on the client makes the system way more robust, and features can be rolled out to a device that does local processing. I don't own any big home automation systems because I don't trust them, so as soon as a company builds something privacy centric, they will get my money.
I remember when Apple first announced that they were removing the headphone jack from their phones, Elliot Harmon posted a long, horribly misinformed diatribe about how it basically meant the end of DRM-free audio, which totally ignored how audio over Lightning and Bluetooth actually works, essentially rendering the entire article moot.
Harmon later revised the article with more accurate information, but conveniently, he neglected to correct any of the misinformation that the article was built around. One can’t help but conclude that maybe the EFF is more concerned with attacking technologies based on their emotional response to them than they are with understanding those technologies and the issues to the table.
Unfortunately fear is what gets people to donate money, not reason.
For the Ring doorbell, I am less worried about an Amazon employee misusing my data than a group of thieves hacking WiFi networks (really not hard) to steal Ring videos in transit to be able to stake out multiple neighborhoods at once. If an Amazon employee has access, it's (probably) not E2E encrypted. So the question is, do you trust Amazon to make their devices, servers, and communication between both secure? I don't because it's not really in their interest to do so.
I'm putting something together for work with off-the-shelf cameras, maybe it'll be similar enough that it can be adapted for home use.
I think there is a moral good produced by some amount of private surveillance, on and near a person's own property, controlled by that private person; so we just need to fix people's expectations from these companies which subsidize their services by selling out their customers.
- does all video processing on the client (e.g. as it's generated) - optionally uploads encrypted video to the cloud - stores encrypted video locally - allows sharing video by downloading and decrypting that video on your device - never stores the key in the cloud
Ideally, it would be a drop in replacement for Ring, but with the complicated logic done on the camera or your viewing device. I'm happy to pay extra for that, though I think it can be competitively priced. It should also come with an optional VPN device/service to access your cameras when outside your network.