What we found
Eufy Security Cameras: FEufy sold millions of cameras on a single promise: your footage stays home, period.
The Verge proved in November 2022 that Eufy cameras were uploading facial recognition thumbnails to AWS cloud servers without user consent. Worse, camera feeds could be accessed remotely via a URL with no authentication — anyone with the link could watch live footage. The URLs used a predictable pattern based on device serial numbers.
Furbo Dog Camera: FFurbo is not a dog camera.
Furbo is a 1080p/360-degree camera with full audio recording, night vision, two-way audio, and AI-powered behavioral analysis that runs continuously in your home. It captures everything the camera and microphone can reach — conversations, visitors, daily routines, arguments, intimate moments — all processed through cloud AI. The pet framing obscures that you're installing a comprehensive surveillance system with cloud processing in your living room.
Tapo Smart Home: FThe Tapo C200 — one of the best-selling budget security cameras on Amazon — had a CVSS 9.8 vulnerability.
Multiple critical CVEs affect Tapo cameras. CVE-2021-4045 (CVSS 9.8) revealed the Tapo C200 camera had a command injection vulnerability allowing unauthenticated remote code execution. An attacker on the same network could take full control of the camera without any credentials. Additional vulnerabilities (CVE-2023-27126) exposed WiFi credentials in plaintext during setup.
Eufy HomeBase 3: FEufy promised "local storage only." Caught uploading thumbnails to AWS with facial recognition data.
Security researcher Paul Moore discovered in November 2022 that Eufy cameras connected to HomeBase were uploading facial recognition thumbnails to AWS cloud servers (s3.amazonaws.com). The Verge independently confirmed that live video feeds were accessible via unencrypted cloud URLs without any authentication. Anker denied the findings for months before admitting in January 2023 that cameras did not offer end-to-end encryption as promised.
Eight Sleep Pod: D$2,000 mattress cover that tracks your sleep, heart rate, and breathing — requires $15/month subscription or it stops working.
Truffle Security researcher Dylan Ayrey discovered in February 2025 that Eight Sleep engineers can remotely SSH into every customer's Pod via remote-connectivity-api.8slp.net using a shared engineering key ([email protected]), bypassing all code review. Hardcoded AWS credentials were also found in firmware enabling access to Kinesis data streams. Eight Sleep dismissed these as 'not a legitimate security vulnerability.'
Ring Alarm Pro: DHome security system that shares your data with police and insurers. Guard the guards.
Amazon admitted to sharing Ring footage with police without owner consent at least 11 times in 2022 using an emergency request process that bypasses warrants. FTC settlement (2023) confirmed Ring failed to implement adequate privacy safeguards. In July 2025, Ring quietly reintroduced police video sharing through partnerships with Axon and Flock Safety after publicly announcing it would stop in January 2024.
Granary Camera Monitoring Feeder PLAF203: DPetlibro admits they use photos and video clips from customers' cameras to train their AI systems — including images of pets, feces, and whatever else the ca...
Google Play Store data safety states: 'The developer says this app doesn't collect user data' and 'No data shared with third parties.' Using customer images and video clips to train AI models is data collection and processing by any definition.
Hub 2 (W3202100): DA critical security flaw lets attackers steal sensitive data when your SwitchBot devices update their software — no hacking skills needed, just being on the ...
The critical vulnerability in the firmware update process (CVE-2024-48786) means device credentials, cloud tokens, or other sensitive data can be intercepted during updates. This is compounded by CVE-2025-53649, which shows the app logged sensitive user information to files for nearly three years (versions V6.24 through V9.12). Together, these vulnerabilities demonstrate a pattern of poor security practices: sensitive data leaks during updates AND sensitive data written to logs. SwitchBot's vulnerability disclosure policy claims to fix critical issues within three working days, but CVE-2025-53649 persisted across years of app releases.