According to a recent report, the Anker Eufy security camera is sending unauthorized data to the cloud.
Some of Anker 's popular Eufy -branded security cameras appear to be sending data to the cloud , even when users have disabled cloud storage and enabled local-only storage settings.
Anker Eufy security cameras have long been touted as protecting users' privacy by storing videos and other related data locally. However, a security researcher is raising suspicions that some Anker Eufy cameras are actually uploading photos, facial recognition images, and other personal data to cloud servers without the user's knowledge or consent.
Paul Moore discovered that the Anker Eufy camera uploads thumbnails of users' faces as well as personal information to cloud storage, even when the user has not enabled the cloud feature.

See also: Anker USB-C Docking Station: Triple Display Support on M1 Mac
Moore demonstrates the unauthorized cloud upload by allowing his Anker Eufy camera to capture his footage and turning off his Eufy HomeBase . The website still has access to the content via the cloud integration, even though Moore had not signed up for the cloud service, and the content remains accessible even when the material is removed from the Eufy app. Note that the full streaming video does not appear to be automatically uploaded to the Cloud – rather, it is the thumbnails of the downloads that are uploaded.
The thumbnails are stored in the Eufy app and are used to start streaming video from the Eufy HomeBase. This allows users to watch their videos while away from home, as well as send photo. The problem is that even when the cloud feature is turned off, the thumbnails are still automatically uploaded — including facial recognition data. That data also included certain identifying information, like username and location. As proof, Moore points to Anker Eufy that are encrypted with only AES 128 and a simple key instead of a proper random string. In the example given, Moore’s videos were saved with “ZXSecurity17Cam@” as the encryption key — something that could easily be cracked by anyone who really wants your footage.
Since Eufy proclaims "No Cloud," some users are unhappy with the company's recent initiative to block unauthorized cloud uploads. In the past, this privacy-focused camera solution was a popular choice among those looking to avoid third-party storage services.
Moore claims that Eufy can link facial recognition data from two different cameras and apps to users without the camera owners knowing.
Many other Anker Eufy users responded to Moore’s tweet , seeing the same problem. There’s also a dedicated thread on Reddit discussing the issue. Moore not only tested Eufy’s doorbell camera, but he found that this is how all Eufy cameras seem to work. As Moore pointed out, once you’re logged in, you can access the footage via a simple URL — a major security concern for anyone using these products. Even after Moore ’s tweet , Eufy only removed the background call that reveals the stored footage — not the footage itself.

In response to Moore, Eufy stated that while event lists and thumbnails are uploaded to AWS, the data is secure and cannot be “leaked to the public” because the URL is controlled, time-limited, and requires an account login.
See also: UK: Bans use of Chinese Hikvision surveillance cameras on govt sites
Additionally, Moore noted that the Anker Eufy camera footage can be live-streamed using an app like VLC , though few details about the exploit are currently public. Without encryption, Moore pointed out that anyone could access the Eufy camera’s content without having to go through any authentication process — something that will surely worry Eufy users.
Moore said he is in contact with Eufy's legal department and will give them time to "investigate and take appropriate action" before making any additional comments.
Anker provided a statement to MacRumors , explaining why the images are being collected and how the issue will be addressed in the future.
Eufy Security was created as a local home security system. This means that all videos are stored and encrypted on the user's device, not in the cloud. Eufy Security 's facial recognition technology also processes and stores information locally on the user's device. To ensure we are fully compliant with GDPR standards, our products and services go through several processes, including ISO 27701/27001 certification and ETSI 303645 compliance . This helps us protect your data and keep it safe. Our security solutions use push notifications to notify users of activity on their mobile devices. To create these previews, we host short, encrypted videos on an AWS -based cloud server. - - In accordance with Apple Push Notification Service and Firebase Cloud Messaging standards , these videos are automatically deleted after they are no longer needed. Users must be logged into their Eufy Security account to access or share video previews. While the Eufy Security app allows users to receive text-based or thumbnail-based push notifications, opting in to thumbnail-based notifications requires that preview images be hosted in the cloud for a short period of time. We apologize for the misunderstanding and have a plan to improve things in the future. We will do this differently: 1) We recognize that the current reporting of push notifications in the Eufy Security app is unclear and could be misinterpreted. To fix this, we are changing the wording to better explain that push notifications with opt-in thumbnail previews require images to be cached in the cloud. 2) In our marketing materials that we use to reach consumers, we will more clearly mention the use of the cloud for push notifications. Eufy Security values the privacy and data protection of its users and we are grateful to the community of security researchers who brought this issue to our attention.

Anker Eufy Security has previously stated that its products are GDPR compliant. GDPR certification requires companies to demonstrate to the EU that they are secure and manage data. Certification is not an easy process of approval from a governing body, but is instead regulated by the ICO .
With your Anker Eufy camera 's notifications set to text only, no thumbnails will be automatically created or uploaded. So if you have one of these cameras, this setting might be the best option.
Right now, this looks pretty bad for Eufy. The company has built its reputation on only storing user data locally and never uploading it to the cloud. While Eufy does have some cloud services, no data should be uploaded without the user's explicit permission.
Source: macrumors.com
