FTC says Ring employees illegally surveilled customers, failed to stop hackers
ftc.gov
ftc.gov
By not building privacy and security aspects they were able to invest in growing marketshare. That growth enabled their $1b Amazon acquisition. Had the company slowed down its growth to build privacy protections they may have missed out on that exit.
A $5m fine does nothing to ensure other companies do the right thing.
This is a great example of both perverse incentives that are inextricably embedded into finance, and the lack of accountability that makes these kinds of judgments absurd.
Its a shame what’ve we’ve given up in the pursuit of “safety”. These types of devices should have e2e encryption turned on by default, and also automatically black out areas outside of the owner’s property.
Amazon.com's Ring mishandled customers videos and will pay $5.8M fine - https://news.ycombinator.com/item?id=36142025 - May 2023 (8 comments)
That’s always been possible, but it requires you rolling your own setup which costs more in both time and money.
What the big companies offer is much less cost in both time and money, but you have to give up your privacy. It would be a fairer trade if they were more blunt about it, but that does nothing to sell products and services
I generally agree with your assessment but I think socializing the effort, being the change more collectively is how actual shifts start. The legion of the willing won't get far if only rolling their own.
> Because of its failure to implement security measures, more than 55,000 U.S. customers faced attacks from hackers that compromised Ring devices between January 2019 and March 2020, the FTC said.
During this time frame, Amazon reported[2][3] raking in $14B net profit on $356B revenue, so the impact of a $30M penalty relative to operations of the period amounts to ~0.2% and ~0.008%, respectively.
Nice rounding error, FTC...unimpressed.
On a related note, I recently replaced my heat pump and part of the contractor's offer was a free Ring-compatible smart thermostat with the purchase of a qualified high-efficiency system...I firmly insisted to keep that garbage out of my home and install a sufficiently dumb one instead (Honeywell T6 Pro variant without wifi).
[1] https://news.ycombinator.com/item?id=36147196
[2] https://www.sec.gov/Archives/edgar/data/1018724/000101872420...
[3] https://www.sec.gov/Archives/edgar/data/1018724/000101872420...
Doorbells are notoriously outside... although you can see who comes and goes or walks by.
That's 99% of my uses.
I want a device that does only that and runs purely offline. I'm sure between Whisper.cpp and LLaMA.cpp I could make this a reality with an old spare laptop.
No phone ? no computer ? no wi-fi ? no internet ? no electricity ? no neighbours ?
Residential security cameras seem less common where I live (Australia) than in the US though. A couple of my friends have “smart” doorbells but I don’t think any have security cameras.
Don't you also have control over your own security cameras ? (you bought them and set them there, they didn't fall from the sky)
I see it in the perspective of phone and computers to be also cloud-connected, always on, with potential camera and mic activated.
For the record I have “hey siri” turned off too, though I don’t consider it particularly risky.
Percentage punishments (x% of illegitimate gains) punish all companies equally and reduce interest in that market sector.
Then there is lethal punishment ala Copa. https://m.youtube.com/watch?v=N3zU7sV4bJE If not deterrable via ablative company structures or other devices, these endavours kill, usually by scaling with the growth of crime.
Are these classification groups correct? Did I miss one?
I have no doubt that every tech company is secretly and illegally surveilling. If data is the name of today’s game, then tech co’s have every incentive to do so and to lie about it, particularly if there is essentially no punishment for doing so.
Everyone knows Instagram is listening. I don’t care what they say. The alternative is a mass scale hallucination that is highly improbable.
Alexa listening was also a conspiracy theory until it was discovered it did just that and Amazon claimed it was a “rare occurrence.”
The incentives speak for themselves.
If Instagram was using private apis that would allow to hear your mic (and I don’t even think they exist), what’s the incentive for apple to cover it up? They have been attacking Facebook/Meta relentlessly when it comes to privacy.
It’s just not a thing. Burden of proof would be on your side to show how this can be done.
What's horrible about this strategy is that it's all the people underneath that bear the weight of these execs' horrible decisions and actions. And for this reason, we should be able to sue these executives, regardless of if they leave the company, for their illegal decisions and actions.
After all, if individual contributors and lower level managers push back against leadership, they get fired. Which is unlawful, however you have to wait years for lawsuits like this one with FTC vs. Ring, and in the course of waiting your statute of limitations on retaliatory firing expires. So yea, I'm totally for suing executives.
[1]https://www.cnbc.com/2023/03/01/amazon-ring-ceo-steps-down-f...
[2]https://www.businessinsider.com/ring-ceo-security-practices-...
Question: How does the FTC ensure the data is deleted?