Amazon's Ring Neighbors App Exposed Users' Precise Locations and Home Addresses (techcrunch.com) 19
A security flaw in Ring's Neighbors app was exposing the precise locations and home addresses of users who had posted to the app. From a report: Ring, the video doorbell and home security startup acquired by Amazon for $1 billion, launched Neighbors in 2018 as a breakaway feature in its own standalone app. Neighbors is one of several neighborhood watch apps, like Nextdoor and Citizen, that lets users anonymously alert nearby residents to crime and public-safety issues. While users' posts are public, the app doesn't display names or precise locations -- though most include video taken by Ring doorbells and security cameras. The bug made it possible to retrieve the location data on users who posted to the app, including those who are reporting crimes. But the exposed data wasn't visible to anyone using the app. Rather, the bug was retrieving hidden data, including the user's latitude and longitude and their home address, from Ring's servers. Another problem was that every post was tied to a unique number generated by the server that incremented by one each time a user created a new post. Although the number was hidden from view to the app user, the sequential post number made it easy to enumerate the location data from previous posts -- even from users who aren't geographically nearby.
What a toxic thing (Score:4, Interesting)
Re: And this is a prob? (Score:2)
Completely missing the point.
Deliberately so.
Go back to your owners, drone.
Re: (Score:2)
The Stasi would have blown a load for this device. Neighbors tattling on neighbors, and they PAY for this "privilege".
Pay? In that form of government, the people are already paying for the security apparatus that enables the Stasi to exist, cameras will be provided free of charge comrade.
Plus, they would have gone dry when cordless phones exploded in the 90's, or cheap internet based security cams were available twenty years ago. They wouldn't have anything left by the time cellphones were widely available, much less smartphones... or drones, for crying out loud.
The problem with the Stasi is always the Stasi, not every n
Bug? (Score:2)
Re: (Score:2)
Re: (Score:3)
Re: (Score:2)
Your name and address are a matter of public record.
Not as it applies to companies' use, especially in California. Name and address are regarded as protected information, and companies can get it big trouble for disclosing it.
The California Consumer Privacy Act (CCPA) in particular provides fines of $750 per record for unauthorised disclosure, and name and address are part of the list of protected attributes.
Re: (Score:2)
https://slashdot.org/comments.... [slashdot.org]
I have something. Consider it an alpha build and I wanted to get your feedback/opinion/etc, if you don't mind. You can reach me at gmail (same username, no spaces).
Thank you.
Neigborhood watch? (Score:3)
Is that what we call instrumenting the population for totalitarian surveillance nowadays?
Why not go all the way?
"Glorious children-protecting anti-terrorist anti-Russian-hacker safety for you and the Oceania motherland". Gcpatarhsfyatom!
Confusing summary (Score:2)
"But the exposed data wasn't visible to anyone using the app. Rather, the bug was retrieving hidden data, including the user's latitude and longitude and their home address,"
So was this data being sent to the camera's owner app, or everyone viewing their posts through their app, and those users were slurping this data through 3rd party tools?
"Another problem was that every post was tied to a unique number generated by the server that incremented by one each time a user created a new post. Although the numbe
A neighbors app that show you: (Score:2)
Dumb & Dumber (Score:2)
If you're dumb enough to use "Cloud connected cam, doorbells, locks, ..." in your house, you deserve this. It's that simple.
A tech-savvy man... (Score:3)
Has a dumb TV.
Has a dumb car.
Has a dumb fridge.
Has a dumb cooker.
Has a dumb doorbell.
Has a router that he bought.
Has a computer he personally build.
Has a firewall and a mile-long hosts list.
Has a browser with maximum security settings.
Has never uttered the word "Alexa" in his house.
Has never uttered the phrase "OK Google" in his house.
Has never uttered the phrase "I have nothing to hide."
Has never entered his phone number into a website.
Has never used his real name on the internet at all.
Has never used Facebook, MySpace, or Twitter.
Has never used the same alias twice.
Has never alluded to his location.
Has never shown his face.
Has never faltered.
Re (Score:1)