3 ms·
Encryption with customer managed keys solves that pretty easily. It also solves any ethical questions with regards to furnishing data to comply with warrants.
by bshacklett 7y ago
Encryption with customer managed keys solves that pretty easily. It also solves any ethical questions with regards to furnishing data to comply with warrants.
This creates a new problem of managing keys, of course, but that's been solved many times now in other parts of the industry.
- jodrellblank 7y agoHow are you going to datamine and AI train and sell customer data for to advertisers for profit, if you can't read the customer data? Google makes billions from doing this, if we wanted Google to not be able to do this at all, we would have to pay them the same money (more!) collectively to incentivise them to do that instead. And I don't see any movement to take that into account and be willing to do it. I don't know much about Ring, but I would be amazed if there was no plan or dream in their business model for things like "face recognition to let your friends in", or "tracking suspicious people around your neighbourhood" as a police contractor, or "selling info to FedEx about what their drivers are up to as seen from the customer side", or "selling data to real estate sites about which roads are busiest or quietest", or anything else they can gather. Saying "my data, my property!" is a principle I can support, but without facing up to this, Ring's answer is very likely to be "we're secure don't worry about a thing .. behind you! a three headed monkey!".
- tensor 7y agoThere are numerous logistic issues with this approach. How would you implement a feature where users could log in to view the footage while away from home? They would need the decryption key, and if the server doesn't have it how would they get it? The only secure option is from the device itself, which is a pretty big UX challenge. However, worse, features that use AI to detect movement/people/etc can't be implemented without access to the underlying video stream. The only remotely viable way would be via homomorphic encryption, which has serious limitations still. It's far easier to do what they did, and just limit root access to a very small number of trusted people.
- jerf 7y ago"How would you implement a feature where users could log in to view the footage while away from home?" The "decryption key" can be a password-like object rather than an AES key, though that does require some security, and browsers are, if not quite ready to decrypt a stream and then render it as a video file, getting pretty close to that. However, any client provided to the user by the video company itself, web or app, has the risk of exfiltrating the key back up to the video company, and I don't think the market will support a video company where you have the inconvenience of being required to get a third-party client to use it. "However, worse, features that use AI to detect movement/people/etc can't be implemented without access to the underlying video stream." The hardware to do this locally isn't that expensive, but again, the market would have a hard time standing for it, because this is inevitably going to be more expensive than the competition.
- aratakareigen 7y agoThe market can be easily scared by the thought of random employees spying on them. I'd easily pay $50 for that peace of mind.
- jahlove 7y ago> The hardware to do this locally isn't that expensive Wyze cams do "edge detection" AI in-camera, and those cameras are only $20-25. It seems to work pretty well to me. Although, the company that developed the AI is pulling out of the contract with Wyze. Nonetheless, it shows that it can be done cheap.
- defanor 7y ago> They would need the decryption key, and if the server doesn't have it how would they get it? Either carry it with them or enter a passphrase (for use with a key derivation function; I guess/hope that Ring requires some passphrase to view video via their website anyway). That's a rather common problem. As for "AI", depending on what you mean by that, it can be implemented in the device itself (unless it's something particularly fancy, requiring more resources than viable to dedicate there). It's indeed easier and slightly more convenient to not care about security, but that's also a general/common case.