/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Ring device testing shows it lacks safeguards that would deter credential stuffing and brute force attacks, making 2FA a key part of securing accounts

It's not so much being watched.  It's that I don't really know if I'm being watched or not.  —  From across the other side of the world …

VICE Joseph Cox

Context & Ripple Effects

VICE's device testing lands in the middle of a long-running argument about how consumer companies actually implement authentication: as far back as 2017, coverage flagged that two-factor authentication is a mess, with SMS and email recovery routes that determined attackers can defeat. The finding here is the concrete case study — Ring's login flow apparently lacks even basic safeguards against credential stuffing and brute force, leaving reused passwords as the main line of defense.

The pressure this reporting created was visible within weeks: by February 2020, Ring made two-factor authentication mandatory and paused most third-party analytics while it reworked data sharing. That sequence — expose the gap, then ship the fix — is why this article matters beyond one product.

First-order effects

  • Ring customers whose email-password pairs were already breached become directly exposed to account takeover, since the tested login flow offers no rate limiting or lockout to stop automated guessing.
  • Ring itself faces immediate reputational and support costs: every takeover incident lands on it, pushing the company toward shipping 2FA rather than leaving it opt-in.

Second-order effects

  • Competing smart-camera makers get audited by the same researchers and press playbook, forcing them to check whether their own logins throttle credential-stuffing attempts before they become the next headline.
  • Mandatory 2FA shifts the attack surface to the second factor itself — fueling the market for bots that steal 2FA codes over SMS services, which later coverage showed being used against Coinbase, Amazon, PayPal, and bank accounts.

Third-order effects

  • If the pattern holds, consumer IoT vendors converge on authentication as a baseline feature rather than an option — while the demonstrated weaknesses of SMS delivery, including the $16 SMS-rerouting attack on a reporter's texts, push the industry toward app-based or hardware-backed factors and invite regulators to look at SMS tooling.

The trend: Consumer device makers are being pushed from optional to mandatory two-factor authentication, with each exposed login flow accelerating the shift and exposing the next weak factor in the chain.

Discussion

  • Vox Rani Molla on x
    Consumer groups issue product warning for Amazon Ring after latest video hack
  • @jason_koebler Jason Koebler on x
    Ring has blamed its users for the spate of hacks over the last week. But our own tests have found that the company doesn't even take the most basic of security precautions. Bottom line: Buying a Ring camera makes you less safe https://www.vice.com/...
  • @josephfcox Joseph Cox on x
    A Ring account is not your average online account. It provides a window into someone's life, and sometime's literally inside their house. That level of sensitivity arguably should encourage more robust security practices than just a password https://www.vice.com/... https://twitt…
  • @josephfcox Joseph Cox on x
    Don't just take our word for it. People who make tools to break into online accounts say Ring could do more to protect users. Even very basic stuff would radically increase the barrier for entry and likely stop the majority of hackers getting into cameras https://www.vice.com/...…
  • @josephfcox Joseph Cox on x
    These lack of security protections are coming from a company that has its cameras all across the country, and which Amazon acquired for over a billion dollars. And apparently they can't do basic IP checks https://www.vice.com/... https://twitter.com/...
  • @josephfcox Joseph Cox on x
    New: we bought a Ring to test its account security. It's awful, making it much easier for hackers to reach cameras in peoples' homes - no checks from unknown IP - no captcha for bruteforcing - doesn't show who is logged in, so hacker can sit silently https://www.vice.com/...
  • @taber @taber on x
    I'm repeating this, again, again: the entire Ring ecosystem is fucked, and can not plausibly be unfucked. - You should not buy Ring devices, and. - If you own Ring devices, you should get up, now, remove them, and put them in the trash. It's a sunk cost. You'll get over it. https…
  • @mozilla @mozilla on x
    If you didn't do it last week, after @VICE reported a stranger using a @ring camera to harass an 8-year-old girl in her bedroom... Secure it now! Because @Amazon won't do it for you. Here's how 👇 https://foundation.mozilla.org/ ...
  • @gossithedog Kevin Beaumont on x
    Ring are going through credential stuffing journey in a very public fashion, but I think it has ability to substantially impact their business. They need to urgent jump on this and throw everything at it.
  • @gossithedog Kevin Beaumont on x
    It's great that Ring support two factor authentication, but they need to add risk based authentication. Eg if somebody suddenly logs in from a different country, send an email to account holder to confirm login first. And block multiple logins from same IP etc.
  • @dinodaizovi Dino A. Dai Zovi on x
    Ring is a physical thing, they could implement something to securely pair it with an app on your smartphone. Then, mobile app approves web logins from untrusted web browsers. There are better UX options than how we do 2FA today. https://twitter.com/...
  • @josephfcox Joseph Cox on x
    Something that could be overlooked: once you gain access to a Ring account, you don't only get to livestream the camera feed. You get to also see the user entered address of that camera. If you're a normal non-tech user, good chance that's the real address https://www.vice.com/..…
  • @josephfcox Joseph Cox on x
    Four of us logged into my Ring camera's control panel from all over the world: U.S., U.K., Spain, Singapore. On different browsers for the web portal, different devices for the app. At no point did Ring think this was an issue, and allowed livestreaming https://www.vice.com/... …
  • @brookejarvis Brooke Jarvis on x
    the strangest thing about the surveillance society is how enthusiastically consumers are enabling it https://twitter.com/...
  • @gossithedog Kevin Beaumont on x
    This is what I'm talking about. Before you even get to MFA, you still have a responsibility to address credential stuffing. It is absolutely possible to automate some protection for customers. https://twitter.com/...