8 ms·
You've taken that phrase completely out of context. The author is clarifying that their friends were only able to access it because the author gave them the em
by addicted44 7y ago
You've taken that phrase completely out of context.
The author is clarifying that their friends were only able to access it because the author gave them the email/password, because the author wants to illustrate what someone who did have your email/password could see.
What's relevant are the sentences that come immediately after:
>, but Amazon-owned home security company Ring is not doing enough to stop hackers breaking into customer accounts, and in turn, their cameras, according to multiple cybersecurity experts, people who write tools to break into accounts, and Motherboard's own analysis with a Ring camera it bought to test the company's security protections.
Then the author goes through some instances and tools built to hack Ring passwords.
IOW, the author isn't claiming that Ring is insecure because someone who he gave the email/password to is able to login. The author is showing the kind of information a person who has your email/password can access, and then is showing how easily it is for someone nefarious to get that information.
- tinus_hn 7y agoThe article is just fear mongering bs, suggesting useless solutions like sms two factor authentication. The problem is with people using stupid passwords which is a problem on just about any service and has nothing to do with Ring. Yes it could be better but so could a lot of services.
- shermozle 7y agoThe level of security you provide should be commensurate with the risk. Perhaps you don't need 2FA and IP checking for your smartwatch but you probably need it for your x-ray machine. This is a device people are encouraged to put into their homes, with access to their most intimate moments. And sold to untrained consumers who probably won't even read any documentation you supply. And, as the article highlights, there are active attacks. Ring need to up their game.
- caf 7y agoYes, this seems like exactly the kind of service that should be checking passwords against known compromised password sets.
- caf 7y agoSMS 2FA is not useless against credential stuffing which is largely what is going on here.
- rumanator 7y ago> The article is just fear mongering bs, The article cites plenty of cases demonstrating how insecure the devices are. Are those cases BS? > The problem is with people using stupid passwords Your comment makes no sense at all. A flimsy lock doesn't become automatically secure if you argue that the lock owners have mishandled the key. The fact is that the system has been demonstrated that the system's security is lacking and at best is very vulnerable. The fact that all you need to penetrate their system is an email address and a password is more than enough to demonstrate the depth of the problem.
- SahAssar 7y ago> The fact that all you need to penetrate their system is an email address and a password is more than enough to demonstrate the depth of the problem. You do realize that is true for the default account for 99.9% of all web services? They do support basic 2fa (SMS based), which is not the best (Webauthn would be a lot better), but one of the biggest complaints in the article is easy brute-forcing, and they support fixing that. Some of what they suggest is even downright wrong and bad practice (like blocking certain user-agent headers). The only legitimate feature they suggest that I could see is rate-limiting based on IP, but even that is not always a good idea (since you never know how many legitimate users share an IP). Perhaps a better title would be "Ring does not do enough to advise their users on how to secure their accounts". The actual content is FUD and I'd bet that basically every VMS with a web API would have the same "vulnerabilities" in a default setup. Source: Having worked on security for similar systems.