In February 2024, a cloud outage at Wyze did something strange. As its cameras came back online, about 13,000 users were shown thumbnails from cameras that weren't theirs, and roughly 1,500 of them tapped one. Nobody had hacked anything. A caching error at a cloud provider was enough to put strangers' living rooms on the wrong screens.
The doorbell is a small computer watching your door
A smart doorbell isn't a bell with a lens. It's an internet-connected computer with a camera and microphone, running software its maker updates, or forgets to. The video goes to a company server, then to your phone, and every step in that chain can fail. The device on your wall is the least interesting part. The account, the app and the cloud behind it are where trouble usually starts.
Your password is the real lock
In 2019, dozens of Ring owners had their cameras accessed through brute-force and credential-stuffing attacks, according to a class action lawsuit. Credential stuffing is simple. Criminals take email-and-password pairs leaked from some unrelated site and try them everywhere, betting that people reuse passwords. Ring first pointed at weak passwords, then made two-factor authentication mandatory.
If your doorbell login matches an old shopping-site password, a leak there can become a view of your hallway. Use a unique password, and choose an authenticator app over SMS codes, which can be intercepted.
Who else holds a key?
Shared access is the setting people forget. Most apps let you invite family, a tenant or whoever looks after the house. Years later those invitations are often still active: the ex-flatmate, the former house help, the cousin who borrowed your login for a week.
The viewers list is data too. Wyze's 2019 leak exposed the email addresses of people who had been given permission to watch camera feeds. Give each person their own invited account instead of sharing yours, so you can remove one without changing everything. Then review the list every few months.
Footage stored on someone else's servers
Cloud storage is convenient. A clip survives even if the doorbell is stolen. But it also means a company holds your footage, and you're trusting its internal rules.
In 2023 the US Federal Trade Commission alleged that Ring let every employee and hundreds of contractors view any customer's video, whether or not their job required it. It also said one employee watched thousands of recordings from women's cameras inside their homes. Ring denied breaking the law but settled for $5.8 million, and said it had fixed these problems years earlier. These were allegations resolved by settlement, not court findings. The question they raise still applies to every brand: who inside the company can see my clips?
Privacy against features
Some makers offer end-to-end encryption, where only your enrolled phone can unlock the footage. On Ring it's optional, and when it's on, Ring itself can't access the recordings. The catch is that it switches off shared accounts, person detection, facial recognition and AI video search, according to Consumer Reports. Ring has also added a system called TAKE, which it says deletes its copy of the video keys after 24 hours. That's the company's own description, so treat it as a claim.
The other route is local storage, meaning a memory card or home hub, so footage never leaves your house. The downside is that a thief who takes the camera takes the evidence with it.
A weekend checklist
You don't need to replace anything. Set a unique password and turn on authenticator-based two-factor login. Open the shared-users list and remove anyone who no longer needs access. Decide whether cloud storage is worth it for you, and if you can live without the smart features, try end-to-end encryption. Install pending firmware updates, since old software is a common way in. Finally, check what the camera actually sees. If it covers a neighbour's window or a shared corridor, angle it back toward your own door.
The point isn't to distrust the technology. A doorbell that watches your door should only be watching it for you.