$10K+ Bounty Offered to Hacker Who Can Disconnect Ring Video Doorbells from Amazon Cloud
## Bug Bounty Program for Ring Video Doorbells
Bug Bounty Program for Ring Video Doorbells
A newly launched bug bounty program is offering approximately $18,000 for a successful method to disconnect Ring Video Doorbells from Amazon’s cloud servers while preserving full device functionality.
The program targets privacy concerns related to Ring’s data-handling practices and aims to provide local storage options. It focuses on Ring doorbells released in 2021 or later, requiring a software or firmware modification for local control.
The bounty fund of $17,924 is sourced from public donations and a matching fund. The solution should integrate the modified Ring doorbell directly with a local PC or server via Wi-Fi or a physical connection , completely severing the device's connection to Amazon servers and eliminating the need for Amazon hardware.
The modification must maintain all on-device hardware features, such as motion detection and color night vision, without replacing the doorbell's hardware. Clear instructions for implementation within one hour by a moderately technical user are required.
Requirement Details
Local Integration Must connect directly to a local PC/server via Wi-Fi or physical connection, ideally supporting Home Assistant.
No Cloud Dependency Must stop sending data to Amazon servers and not require Amazon hardware.
The program targets privacy concerns related to Ring’s data-handling practices and aims to provide local storage options.
Feature Preservation On-device features (e.g., motion detection, color night vision) must remain functional.
No Hardware Replacement Must not replace the doorbell’s hardware.
Accessible Tooling Must use readily available, low-cost tools.
Clear Instructions Must include step-by-step instructions a moderately technical user can complete in under one hour.
Model Eligibility Must work on at least one Ring model released in 2021 or later.
Compliance Must meet the general bounty terms.
The bounty addresses privacy issues associated with Ring, an Amazon subsidiary. In 2024, Ring agreed to a $5.6 million settlement following a Federal Trade Commission complaint regarding unauthorized employee access to customer videos and failure to patch known vulnerabilities, affecting approximately 55,000 accounts.
Currently, Ring doorbell owners cannot store video feeds locally or prevent data transmission to Amazon’s servers, raising privacy concerns. The FULU bounty program seeks to empower users by offering a solution for managing Ring doorbell data.
Submissions for the bounty are open until December 31, 2031. If no viable solution is presented by the deadline, contributors may receive a refund or donate their contribution to FULU.
Based on reporting by Cyber Security News.
