5 ms·
> It says three employees can currently access stored customer videos. I can't think of a legitimate reason for 1 employee at Ring to have the capability of vi
by cabaalis 7y ago
> It says three employees can currently access stored customer videos.
I can't think of a legitimate reason for 1 employee at Ring to have the capability of viewing customer videos.
1. Law enforcement requests? Blind-forward what the warrant asks for.
2. Verifying service is functioning? Canary devices utilizing the normal application workflow. Login to your canary account and make sure the video is working.
3. Customer asks you to review something? Just say you can't. The world will be happier.
- jayd16 7y agoFor scenario 1. the employee would still have access they just wouldn't be using it.
- teraflop 7y agoThere's always somebody with root access to the servers.
- mrmonkeyman 7y agoEnd-to-end encryption.
- bshacklett 7y agoEncryption with customer managed keys solves that pretty easily. It also solves any ethical questions with regards to furnishing data to comply with warrants. This creates a new problem of managing keys, of course, but that's been solved many times now in other parts of the industry.
- jodrellblank 7y agoHow are you going to datamine and AI train and sell customer data for to advertisers for profit, if you can't read the customer data? Google makes billions from doing this, if we wanted Google to not be able to do this at all, we would have to pay them the same money (more!) collectively to incentivise them to do that instead. And I don't see any movement to take that into account and be willing to do it. I don't know much about Ring, but I would be amazed if there was no plan or dream in their business model for things like "face recognition to let your friends in", or "tracking suspicious people around your neighbourhood" as a police contractor, or "selling info to FedEx about what their drivers are up to as seen from the customer side", or "selling data to real estate sites about which roads are busiest or quietest", or anything else they can gather. Saying "my data, my property!" is a principle I can support, but without facing up to this, Ring's answer is very likely to be "we're secure don't worry about a thing .. behind you! a three headed monkey!".
- tensor 7y agoThere are numerous logistic issues with this approach. How would you implement a feature where users could log in to view the footage while away from home? They would need the decryption key, and if the server doesn't have it how would they get it? The only secure option is from the device itself, which is a pretty big UX challenge. However, worse, features that use AI to detect movement/people/etc can't be implemented without access to the underlying video stream. The only remotely viable way would be via homomorphic encryption, which has serious limitations still. It's far easier to do what they did, and just limit root access to a very small number of trusted people.
- jerf 7y ago"How would you implement a feature where users could log in to view the footage while away from home?" The "decryption key" can be a password-like object rather than an AES key, though that does require some security, and browsers are, if not quite ready to decrypt a stream and then render it as a video file, getting pretty close to that. However, any client provided to the user by the video company itself, web or app, has the risk of exfiltrating the key back up to the video company, and I don't think the market will support a video company where you have the inconvenience of being required to get a third-party client to use it. "However, worse, features that use AI to detect movement/people/etc can't be implemented without access to the underlying video stream." The hardware to do this locally isn't that expensive, but again, the market would have a hard time standing for it, because this is inevitably going to be more expensive than the competition.
- claudiulodro 7y agoWhat about to verify that video backups/storage are working correctly, to prevent an issue like the Gandi one on the front page right now?
- michaelt 7y agoIn an ideal world, sure. But it's easy enough to imagine how you'd end up with this situation. For example, you have a customer support phone number, and you want your call centre workers to be able to see exactly what the user sees, and help the user do anything the user can do through the website. After all, if you're keeping your support costs down, the website should be able to do 99% of what users call support for already. So you give your call centre workers a 'log in as customer' option. And you justify to yourself that there's access logging, and staff are under strict orders. Maybe it's before you've released any indoor cameras, and it's not like people are putting doorbells in their showers. Sure, it'd be a sensible extra feature if log-in-as-customer was a special mode that didn't show videos. But is that really a minimum viable product? We'll put that on the backlog to attend to later. Et voilà, your call centre workers can watch customer videos.
- bluejekyll 7y agoEven if you offered a “log-in as customer” feature, that could incorporate a notification and/or authorization request to the user so that it can’t be abused.
- james_pm 7y agoWe implemented this at my work. In order to sign in as the customer, the customer must first explicitly consent to this and can withdraw that consent (and the ability to sign in as the customer) at any time. Without the consent, the sign in as customer function in our support tools doesn't work. There are some agents/admins with override abilities but the overrides are logged and reason (with ticket number) is required to create the override.
- 98codes 7y agoSure, but with just-in-time approvals for a specific time window, for a specific customer, with approval coming from management. Anything else is asking for abuse.
- JshWright 7y ago
- gjs278 7y ago1. if law enforcement can view it, so can you 2. “it works on my end” really now 3. you just said the police can view it. let me view it. you can’t just becomes you won’t.