Cybersecurity

Solar Security Cameras vs Ring: Skip the Subscription

Solar Security Cameras vs Ring: Skip the Subscription
Illustration · Newzlet

Updated 23 August 2026 — this article was rewritten with primary sources added and unsupported claims removed.

Subscription-free solar cameras are sold on two promises at once: you stop paying a monthly fee, and your footage stays yours. The first is a pricing question and easy to verify. The second is a security question, and the enforcement record of the last few years suggests it is decided by something other than the subscription — every documented failure in this category turned on a gap between what a vendor said it did with video and what it actually did.

What the subscription actually buys, and what it does not

A monthly plan usually buys cloud retention: the vendor stores clips for a rolling window so you can scroll back. Dropping the plan generally means clips live on an SD card, a base station, or a local NVR instead. That is a genuine architectural difference and it does reduce exposure — footage that never leaves the house cannot be handed to anyone by the vendor.

What it does not do by itself is guarantee that nothing leaves the house. The camera still has an account, an app, a firmware update channel and, in most cases, a thumbnail or notification path that touches the vendor’s servers. Whether that path carries more than it claims to is not something a buyer can determine from the packaging, which is precisely where the documented cases start.

The record, by architecture

These are the incidents with regulator or advocacy documentation behind them, arranged by the storage model involved rather than by brand.

Storage model Example Who could reach the footage What was documented Source
Vendor cloud, subscription Ring Vendor staff and contractors FTC alleged every employee and contractor could access customers’ private videos; one employee viewed thousands of recordings of female users before another employee stopped him FTC
Vendor cloud plus police portal Ring Neighbors Law enforcement, on request Ring disclosed it had provided videos to police without a warrant or the owner’s consent EFF
Vendor cloud, bulk requests Ring Police sourcing footage of public events LAPD requested Ring footage of Black-led protests against police violence EFF
“Local storage” with an undisclosed cloud path Anker / eufy Vendor, via a path customers were not told about New York settled with Anker for $450,000 over misleading claims about the security of its cameras and unencrypted cloud uploads NY Attorney General
Genuinely local, no vendor account for storage SD card or on-site NVR Anyone with physical access to the device, or access to your network By definition there is no vendor-side disclosure path; the risk moves to your premises and your network

Reading the table

Two things stand out. The first is that the concentration of cases around one brand is partly a measure of scrutiny rather than relative virtue — Ring is the market leader and has attracted the most regulatory and journalistic attention. Treating an absence of enforcement actions against a smaller vendor as evidence of better practice is a mistake; it may only mean nobody has looked.

The second is the eufy row, which is the one that matters most for anyone shopping on the no-subscription promise. That case is not about a company charging for cloud storage. It is about a company selling local storage and, according to the state’s action, misrepresenting what was happening to the data anyway. A subscription-free product made exactly the claim buyers are told to look for, and the claim was the problem.

What changed, and what did not

One thing did improve. In January 2024 Ring announced it would stop facilitating police requests for footage through its Neighbors app, which the EFF — a persistent critic — described as a victory while noting the limits of what it changes (EFF). Police can still obtain footage through legal process, and the underlying database still exists. The convenient bulk-request path is what closed.

The FTC’s Ring order also imposed obligations rather than just a payment: the case record and the $5.8 million judgement sit in the Commission’s public file (FTC case file). Enforcement of this kind is retrospective by nature. It does not tell you which vendor is safe now; it tells you which claims were false then.

Consumer cameras are only one source feeding this pattern. The municipal equivalent is a nationwide licence-plate-reader network whose audit controls arrived after the documented misuse, not before it. In both cases the question that decides your exposure is not the hardware but who holds the record and what process reaches it — the same question that governs health data a wearable collects.

The threat most buyers actually face

Police requests and insider snooping dominate the coverage because they are documented and dramatic. For a typical household neither is the likeliest exposure. The likeliest is an account takeover: a reused password, no second factor, and someone else watching a live feed from a device you are still paying attention to. The FTC’s complaint against Ring covered this too, alleging the company failed to implement protections that would have stopped hackers taking control of customers’ accounts and cameras.

That failure mode does not care about your storage architecture. A local-only camera with a weak app password and no multi-factor authentication is reachable by anyone who guesses the password, because the app is the access path regardless of where the bytes sit. It is also the one risk entirely within your control, which makes it the first thing to fix and the cheapest.

The second under-discussed exposure is the device’s afterlife. Cameras get resold, returned, or handed on with a factory reset that clears the app pairing but not always the storage medium. If footage is on an SD card, a reset that does not wipe the card leaves the archive in the next owner’s hands. Local storage moves the disclosure risk from a vendor’s server to a physical object that can be posted to a stranger.

What “encrypted” is doing in the marketing

The word appears on nearly every product in this category and covers at least three different guarantees. Encrypted in transit means the link between camera and app is protected — table stakes, and it says nothing about who can read the footage at the other end. Encrypted at rest means the stored file is protected on the vendor’s disks, where the vendor typically holds the key, so it protects against a stolen server and not against the vendor or anyone who compels it.

End-to-end encryption is the only one where the vendor cannot read the video, and it is usually optional, off by default, and comes with real costs — it commonly disables features that require server-side processing, such as person detection or web viewing. Vendors rarely make that trade-off explicit at the point of sale. A product advertising “bank-level encryption” without specifying which of the three it means is not answering the question a buyer is asking.

How to choose, given all that

The useful buying questions are narrower than the marketing. Does the camera function fully with no internet connection at all, and can you verify that by unplugging your router and testing it? Where does a motion notification’s thumbnail go, given that a preview image is still an image of your home? Can you export and delete everything, and does deletion cover the vendor’s copies as well as yours? Is the footage encrypted at rest on the local medium, so that stealing the SD card is not the same as stealing the archive?

Solar power is orthogonal to all of this. It changes where you can mount the camera and removes a wiring job; it has no bearing on who can see the video. A solar, subscription-free camera from a vendor whose local-storage claims do not hold is worse for privacy than a subscription camera from one whose claims do.

The honest summary is that the no-subscription label answers a billing question and gestures at a privacy one. The privacy question is answered by architecture you can test and by a vendor’s record when regulators have looked — and on the current evidence, the second of those has been the better predictor.

AI-Assisted Content — This article was produced with AI assistance. Sources are cited below. Factual claims are verified automatically; uncertain claims are flagged for human review. Found an error? Contact us or read our AI Disclosure.

More in Cybersecurity

See all →