Amazon fined for customer spying

Amazon has agreed to pay $5,8 million in a settlement after the Federal Trade Commission found it illegally spied on its customers and failed to stop hackers from taking control of users' Ring cameras.

amazon ring doorbells spy

The FTC's investigation concluded that Ring, which was acquired by Amazon in 2018, "violated customer privacy by allowing any employee or contractor to access private of consumers and failing to enforce basic privacy and security protections."

Ring's violation of user privacy occurred on multiple fronts, as Ring hid this information in its terms of service and privacy policy, so Ring users were likely unaware that the company was using their videos to "enhance and product development". In other words, customer videos were not only used to train algorithms, but were also viewed by Ring employees and contractors.

The FTC found that Ring employees had shown thousands of videos of female customers in their bedrooms and bathrooms in several months. The employee was only stopped when other employees discovered what he was doing—Ring did not monitor employees' access to the videos, and therefore could not determine whether other employees were violating users' privacy in the same way.

Further privacy breaches occurred due to a lack of security: the FTC found that hackers used a combination of credential stuffing and brute force attacks to gain access to customer accounts. Essentially, the hackers used credentials leaked in other security breaches to discover passwords for Ring accounts using an automated password estimation.” Ring didn't implement multi-factor authentication until 2019, and even then, "the sloppy implementation of additional security measures hampered its effectiveness" It wasn't a good idea to do so.

In total, about 55.000 Ring customers in the US had their accounts and video views compromised by hackers. However, in some cases, the “bad actors” harassed, threatened, and insulted customers, including children and the elderly—the FTC stated that “the hackers racially taunted many children, made sexual advances to individuals, and threatened physical harm to families.” if no ransom was paid".

Amazon has now imposed a privacy and security program on Ring, requiring the company to delete all customer data (acquired before 2018), the and algorithms derived from videos it has illegally detected. The FTC is also calling for “new safeguards for human review of videos” going forward, as well as multi-factor authentication on both customer and employee accounts. The $5,8 million paid by Amazon will be used to refund customers.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Anastasis Vasileiadis

Translations are like women. When they are beautiful they are not faithful and when they are faithful they are not beautiful.

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).