BlackGold09 t1_iybpc6z wrote
Updated Story with Eufy response:
https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/
“Eufy Security is designed as a local home security system. All video footage is stored locally and encrypted on the user's device. With regard to eufy Security’s facial recognition technology, this is all processed and stored locally on the user's device.
Our products, services and processes are in full compliance with General Data Protection Regulation (GDPR) standards, including ISO 27701/27001 and ETSI 303645 certifications.
To provide users with push notifications to their mobile devices, some of our security solutions create small preview images (thumbnails) of videos that are briefly and securely hosted on an AWS-based cloud server. These thumbnails utilize server-side encryption and are set to automatically delete and are in compliance with Apple Push Notification service and Firebase Cloud Messaging standards. Users can only access or share these thumbnails after securely logging into their eufy Security account.
Although our eufy Security app allows users to choose between text-based or thumbnail-based push notifications, it was not made clear that choosing thumbnail-based notifications would require preview images to be briefly hosted in the cloud.
That lack of communication was an oversight on our part and we sincerely apologize for our error. This is how we plan to improve our communication in this matter:
-
We are revising the push notifications option language in the eufy Security app to clearly detail that push notifications with thumbnails require preview images that will be temporarily stored in the cloud.
-
We will be more clear about the use of cloud for push notifications in our consumer-facing marketing materials.
eufy Security is committed to the privacy and protection of our users' data and appreciates the security research community reaching out to us to bring this to our attention.”
TheFriendliestMan t1_iyc99he wrote
But according to the youtuber who figured it out this is bs. You can access it without authentication and the pictures are still there after being 'deleted'.
https://mobile.twitter.com/paul_reviews/status/1595421705996042240
stillrocking3770k t1_iybs5l7 wrote
Explanation sounds reasonable.
You can disable the preview feature any time, and they'll add labelling if you use the preview feature.
Guess we put the pitchforks down (for now).
8Eternity8 t1_iybwhrs wrote
Except the APIs aren't encrypted and you can access the video feeds from cameras using VLC without any authentication.
TheFriendliestMan t1_iyc9ag9 wrote
You mixed up your youtube links.
Edit: Correct link: https://youtu.be/qOjiCbxP5Lc
[deleted] t1_iydmlkf wrote
[removed]
qqanyjuan t1_iyc2m80 wrote
This is literally an ad?
8Eternity8 t1_iydmeii wrote
So apparently if you shared a YouTuve video before the ad finishes it just shares the ad. I have just learned this.
TheFriendliestMan t1_iyc9cpc wrote
Not really: https://youtu.be/qOjiCbxP5Lc
OCedHrt t1_iybsysq wrote
The headline reads like anyone can access the thumbnails.
Viewing a single comment thread. View all comments