Ring device testing shows it lacks safeguards that would deter credential stuffing and brute force attacks, making 2FA a key part of securing accounts
It's not so much being watched. It's that I don't really know if I'm being watched or not. — From across the other side of the world …
VICEJoseph Cox
Context & Ripple Effects
VICE's device testing lands in the middle of a long-running argument about how consumer companies actually implement authentication: as far back as 2017, coverage flagged that two-factor authentication is a mess, with SMS and email recovery routes that determined attackers can defeat. The finding here is the concrete case study — Ring's login flow apparently lacks even basic safeguards against credential stuffing and brute force, leaving reused passwords as the main line of defense.
The pressure this reporting created was visible within weeks: by February 2020, Ring made two-factor authentication mandatory and paused most third-party analytics while it reworked data sharing. That sequence — expose the gap, then ship the fix — is why this article matters beyond one product.
First-order effects
Ring customers whose email-password pairs were already breached become directly exposed to account takeover, since the tested login flow offers no rate limiting or lockout to stop automated guessing.
Ring itself faces immediate reputational and support costs: every takeover incident lands on it, pushing the company toward shipping 2FA rather than leaving it opt-in.
Second-order effects
Competing smart-camera makers get audited by the same researchers and press playbook, forcing them to check whether their own logins throttle credential-stuffing attempts before they become the next headline.
Mandatory 2FA shifts the attack surface to the second factor itself — fueling the market for bots that steal 2FA codes over SMS services, which later coverage showed being used against Coinbase, Amazon, PayPal, and bank accounts.
Third-order effects
If the pattern holds, consumer IoT vendors converge on authentication as a baseline feature rather than an option — while the demonstrated weaknesses of SMS delivery, including the $16 SMS-rerouting attack on a reporter's texts, push the industry toward app-based or hardware-backed factors and invite regulators to look at SMS tooling.
The trend: Consumer device makers are being pushed from optional to mandatory two-factor authentication, with each exposed login flow accelerating the shift and exposing the next weak factor in the chain.
Ring has blamed its users for the spate of hacks over the last week. But our own tests have found that the company doesn't even take the most basic of security precautions. Bottom line: Buying a Ring camera makes you less safe https://www.vice.com/...
A Ring account is not your average online account. It provides a window into someone's life, and sometime's literally inside their house. That level of sensitivity arguably should encourage more robust security practices than just a password https://www.vice.com/... https://twitt…
Don't just take our word for it. People who make tools to break into online accounts say Ring could do more to protect users. Even very basic stuff would radically increase the barrier for entry and likely stop the majority of hackers getting into cameras https://www.vice.com/...…
These lack of security protections are coming from a company that has its cameras all across the country, and which Amazon acquired for over a billion dollars. And apparently they can't do basic IP checks https://www.vice.com/... https://twitter.com/...
New: we bought a Ring to test its account security. It's awful, making it much easier for hackers to reach cameras in peoples' homes - no checks from unknown IP - no captcha for bruteforcing - doesn't show who is logged in, so hacker can sit silently https://www.vice.com/...
I'm repeating this, again, again: the entire Ring ecosystem is fucked, and can not plausibly be unfucked. - You should not buy Ring devices, and. - If you own Ring devices, you should get up, now, remove them, and put them in the trash. It's a sunk cost. You'll get over it. https…
If you didn't do it last week, after @VICE reported a stranger using a @ring camera to harass an 8-year-old girl in her bedroom... Secure it now! Because @Amazon won't do it for you. Here's how 👇 https://foundation.mozilla.org/ ...
Ring are going through credential stuffing journey in a very public fashion, but I think it has ability to substantially impact their business. They need to urgent jump on this and throw everything at it.
It's great that Ring support two factor authentication, but they need to add risk based authentication. Eg if somebody suddenly logs in from a different country, send an email to account holder to confirm login first. And block multiple logins from same IP etc.
Ring is a physical thing, they could implement something to securely pair it with an app on your smartphone. Then, mobile app approves web logins from untrusted web browsers. There are better UX options than how we do 2FA today. https://twitter.com/...
Something that could be overlooked: once you gain access to a Ring account, you don't only get to livestream the camera feed. You get to also see the user entered address of that camera. If you're a normal non-tech user, good chance that's the real address https://www.vice.com/..…
Four of us logged into my Ring camera's control panel from all over the world: U.S., U.K., Spain, Singapore. On different browsers for the web portal, different devices for the app. At no point did Ring think this was an issue, and allowed livestreaming https://www.vice.com/... …
This is what I'm talking about. Before you even get to MFA, you still have a responsibility to address credential stuffing. It is absolutely possible to automate some protection for customers. https://twitter.com/...