Home Security Devices, Ranked by What Regulators Actually Found
Ring paid 5.8 million dollars in FTC refunds, 1,504 people watched strangers' Wyze feeds, and eufy's distributors settled with New York for 450,000. Here is what is still worth fitting.
Every major brand in home security has a file. The Federal Trade Commission ordered Ring to pay 5.8 million dollars in consumer refunds and to delete face embeddings in May 2023. Wyze confirmed in February 2024 that around 13,000 accounts could reach other people’s camera feeds and that 1,504 of them did. The New York Attorney General settled with eufy’s distributors for 450,000 dollars in February 2025. Bitdefender found the encryption key inside an August lock hardcoded. None of that makes the category unbuyable. It does change the order.
Four documents worth reading before you spend anything
Resolution and field of view are the numbers printed on the box. The numbers that separate these brands from one another are in agency press releases and court records, and all four below are public.
- FTC press release, 31 May 2023: Ring pays 5.8 million dollars, deletes pre-2018 customer videos, face embeddings, and models derived from unlawfully reviewed footage
- The Register, 20 February 2024: roughly 13,000 Wyze accounts exposed, with 1,504 clips actually opened by strangers, about 0.25 percent of users
- Consumer Reports: three Wyze vulnerabilities reported in March 2019 and not fully patched until January 2022
- New York Attorney General, 4 February 2025: 450,000-dollar settlement with the distributors of eufy products over unencrypted video and unauthenticated feed URLs
The FTC made Ring delete its face embeddings, and police requests came back anyway
The FTC’s allegations are worth stating in full because summaries soften them. One employee viewed thousands of recordings belonging to female users over several months, including footage of bathrooms and bedrooms. Around 55,000 US customers were affected by hacking in which attackers taunted children with racist slurs, sexually propositioned people and threatened a family with physical harm over a ransom demand. Ring had suffered credential-stuffing attacks in 2017 and 2018 and did not implement multi-factor authentication until 2019. The Commission voted three to nil.
The order is the reason Ring is not last in this ranking. It compels deletion of pre-2018 videos and face embeddings, deletion of models and algorithms derived from the reviewed footage, mandatory multi-factor authentication, and notification to the FTC of unauthorised access. Those are binding obligations rather than a press statement, and no other brand here operates under an equivalent.
What has moved in the other direction is police access. Ring removed the Request for Assistance button from Neighbors in January 2024. In July 2025 it announced a partnership with Axon that restored the ability of agencies to ask for footage, and Community Request formally launched on 19 October 2025, with geo-targeted requests logged in the Neighbors feed and submitted clips flowing into Axon Evidence under chain of custody. Axon says participation is voluntary, that people who decline stay anonymous, and that agencies cannot see who ignored a request. Whether that is acceptable is a judgment, not a spec, and it belongs in the purchase decision.
Wyze exposed 1,504 strangers’ camera feeds and took three years to close three flaws
The February 2024 incident was not a breach in the usual sense. A recently integrated third-party caching client library failed under unprecedented load as devices reconnected en masse, and it mixed up device ID and user ID mapping, connecting data to the wrong accounts. Wyze revoked access to the Events tab, added a verification layer, forced token resets and removed the library. Co-founder David Crosby said the company would not use caching again until it found a new client library. People reported seeing other households’ porches and living rooms, some in other time zones.
The pattern behind it is the more useful signal. Consumer Reports documented three flaws reported to Wyze in March 2019: an authentication bypass, remote code execution, and unauthorised access to video on the SD card. The bypass was patched in September 2019, the code execution in November 2020, and the SD-card flaw on most models in January 2022, at which point Bitdefender went public. Wyze then discontinued the Cam V1 in February 2022, citing hardware limits that made the flaw unpatchable, gave owners minimal notice, and offered a 3-dollar discount on a replacement. Consumer Reports called that too little, too late, and said V1 owners should have been given free replacements.
This is the recommendation against. Wyze makes the cheapest usable camera in this guide and has the longest documented record of getting security wrong slowly. A Wyze camera pointed at a driveway is a reasonable purchase. A Wyze camera as the only camera inside a home is not what we would fit.
eufy’s settlement was about the exact claim on its own packaging
eufy sells against subscriptions, and the argument rests on video staying local and encrypted. The New York Attorney General’s February 2025 settlement with Fantasia Trading, Power Mobile Life and Smart Innovation, the distributors of eufy products, found otherwise: video data was not protected by end-to-end encryption, parts of the transmission were unencrypted, live feeds could be reached without authentication by anyone holding the right URL, some of those URLs were derivable without authorisation, and security testing had not been sufficient to catch any of it.
The required remedies are specific and worth weighing on the other side of the ledger: a comprehensive information-security programme, a secure development lifecycle with third-party testing, vulnerability management with regular penetration testing, and strengthened encryption for video both stored and in transit. A brand under a remediation order is a different proposition from a brand that has never been examined. It is not the same as a brand whose original claim was accurate.
A hardcoded key in the lock, and the distinction most coverage loses
Bitdefender published CVE-2019-17098 on 10 August 2020 and updated it on 20 May 2021. The encryption key used between the August Smart Lock and its configuration app was hardcoded, which allowed an attacker within radio range to eavesdrop, intercept the home Wi-Fi password and use it to mount further attacks against the network. Both the lock and the Connect Wi-Fi Bridge were affected.
Bitdefender is also explicit that the flaw would not let an attacker unlock the door, and that distinction survives almost none of the secondhand coverage. What was exposed was the network the lock sat on, not the deadbolt it controlled. Whether that reassures you depends on what else is on your network, which is the right question to be asking about any of these devices.
The two we would fit, and the one we would leave on the shelf
A doorbell from Ring, on the understanding that recordings mean a subscription and that police can ask for footage through Community Request, remains the most defensible pick here purely because the FTC order gives it obligations the others do not have. A eufy camera in a location where local storage genuinely matters is defensible on the same logic, one year into a remediation programme with dated requirements attached.
What we would not do is build an interior camera network on the brand with two documented cross-account exposures and a three-year patch cycle behind it, however good the price is. And what none of the above fixes is the shape of the category: three of the brands in this guide carry a regulator action or a court filing, and two of them have moved a capability owners already paid for behind a new charge. That pattern, rather than any individual specification, is the buying advice.
Sources: Federal Trade Commission · Tom’s Guide · The Register · Consumer Reports · Hunton Andrews Kurth · Bitdefender
Articles on Read Vault are researched and written by the site’s editorial team.