4 ms·
Heh.. I'm glad they resolved the issue quickly but this seems like bad security design, whenever a camera is associated with a new account they should have tota
by mistersys 7y ago
Heh.. I'm glad they resolved the issue quickly but this seems like bad security design, whenever a camera is associated with a new account they should have totally new encryption keys so the old account is locked out regardless of leftover information hanging out in Alexa. Not great to hear from a company with thousands+ of cameras streaming 24/7.
- ttul 7y agoThis was my thought. Someone didn’t design this system with security and privacy in mind at the outset.
- munchbunny 7y agoDefinitely agreed about making something like designing an encryption key per user account type of mechanism to force an error instead of a privacy violation. GDPR requires this sort of "security and privacy by design" practice, but it's going to be a long time before there's any real widespread knowledge of how to do it, because it's actually really hard to do. I know developers who don't really understand that this principle goes beyond just 2fa and password best practices.