Jump to content

Ring Doorbells used? HTTP to pass credentials unencrypted

WillyW

Amazon supposedly fixed this security vulnerability as reported here:

 

https://threatpost.com/amazon-fixes-ring-video-doorbell-flaw-that-leaked-wi-fi-credentials/150029/

 

Quote

The key issue with Ring exists in how users first configure the device, which requires the device’s smartphone app to use a wireless connection to send the wireless network credentials to the smart doorbell, researchers said.

“This takes place in an unsecure manner, through an unprotected access point,” researchers wrote. “When entering configuration mode, the device creates an access point without a password (the SSID contains the last three bytes from the MAC address).”

 

I have had an IoT device and based on how bad the security was on that, I've sworn off all IoT until companies can figure out that patching, security and not being first to market are important.

 

If you ever change your network, or lets say the average user:

- gets a new internet service provider

- gets the default wifi router with their service

- has to change the password as most do

- doesn't pick secure passwords, and doesn't care

 

They would be open to all sorts of attacks.

 

Quote

While no Amazon Ring users at this point appeared to have been affected by the flaw, there was some considerable lag time between Bitdefender’s first disclosure of the problem to the company on June 20 and Amazon’s patch and coordinated disclosure of the flaw on Nov. 7.

Bitdefender found the flaw.

 

Here's another article that is more brief:

 

https://techcrunch.com/2019/11/07/amazon-ring-doorbells-wifi-hackers/

 

Quote

Amazon has faced intense scrutiny in recent months for Ring’s work with law enforcement.

 

The link above from the quote showed how Ring wanted to allow law enforcement agencies to hack your doorbell so they could see crimes, but what would stop the law enforcement from rifling around in your network if they wanted too.

 

That's in addition to this:

https://www.theatlantic.com/ideas/archive/2019/05/amazon-owned-ring-wants-report-crime-news/588394/

 

Where Ring wanted to hire a reporter to report on crime so they could raise fear and make people buy more ring devices.

 

I think that's three strikes.

Link to comment
Share on other sites

Link to post
Share on other sites

I can't wait to rump my Ring doorbell, I am just waiting on the Ubiquiti G4 Doorbell to go to the Early Access store so I can pick it up and have it integrated within Protect. Hopefully any day now...

Link to comment
Share on other sites

Link to post
Share on other sites

Everyone who I know (except people here) who has a Ring is completely clueless when it comes to IT & Security.

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Shadow Bullet said:

Ubiquiti G4 Doorbell

Not sure if serious...

 

Do you have any info on this?

"And I'll be damned if I let myself trip from a lesser man's ledge"

Link to comment
Share on other sites

Link to post
Share on other sites

35 minutes ago, WillyW said:

Everyone who I know (except people here) who has a Ring is completely clueless when it comes to IT & Security.

Because no one who actually cares about security or privacy would own one.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, RejZoR said:

Because no one who actually cares about security or privacy would own one.

Or, those of us who do care and have it are smart enough to wall them off from the rest of the network :P

Current Network Layout:

Current Build Log/PC:

Prior Build Log/PC:

Link to comment
Share on other sites

Link to post
Share on other sites

4 hours ago, WillyW said:

Everyone who I know (except people here) who has a Ring is completely clueless when it comes to IT & Security.

Why use a over priced product when a raspberry pi zero w with a camera module works just fine?

PLEASE QUOTE ME IF YOU ARE REPLYING TO ME

Desktop Build: Ryzen 7 2700X @ 4.0GHz, AsRock Fatal1ty X370 Professional Gaming, 48GB Corsair DDR4 @ 3000MHz, RX5700 XT 8GB Sapphire Nitro+, Benq XL2730 1440p 144Hz FS

Retro Build: Intel Pentium III @ 500 MHz, Dell Optiplex G1 Full AT Tower, 768MB SDRAM @ 133MHz, Integrated Graphics, Generic 1024x768 60Hz Monitor


 

Link to comment
Share on other sites

Link to post
Share on other sites

Ah, another week, another IoT security faux pas

image.png.5b41ac88ded63105bbcf77a724a1c21d.png

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

another day, another IOT security flaw.

i'm running out of memes to put in here...

but here's one anyways:

i can't believe that Cosby is out of jail, i'm gonna pull a T.I to ensure my daughter is safe...

*Insert Witty Signature here*

System Config: https://au.pcpartpicker.com/list/Tncs9N

 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, Velcade said:

Not sure if serious...

 

Do you have any info on this?

Yes, I am serious, it is coming at some point as we have seen it in Protect marketing images and the Ubiquiti Devs have very very slightly hinted at it before, but not much has been heard about it. It is however supposed to have a tiny LCD screen to display text however.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×