home.social

#robovacs — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #robovacs, aggregated by home.social.

  1. #DJI will pay $30K to the engineer who accidentally hacked 7,000 #Romo #robovacs. All he wanted to do was drive his #robot #vacuum with a PS5 controller
    DJI would also not tell us which discovery it’s paying him for, but says it has already addressed the extra #vulnerability Azdoufal found where someone can view a DJI Romo video stream without needing a security pin. “We can confirm that the PIN code security observation was addressed by late February."
    theverge.com/news/890982/dji-p

  2. #DJI will pay $30K to the engineer who accidentally hacked 7,000 #Romo #robovacs. All he wanted to do was drive his #robot #vacuum with a PS5 controller
    DJI would also not tell us which discovery it’s paying him for, but says it has already addressed the extra #vulnerability Azdoufal found where someone can view a DJI Romo video stream without needing a security pin. “We can confirm that the PIN code security observation was addressed by late February."
    theverge.com/news/890982/dji-p

  3. Teenage hackers yelling slurs and terrorizing pets enabled by security vulnerabilities in robot vacuums.:please_no: :facepalm:

    The Verge opines:

    “Issues like these can feel inevitable when so many smart home devices require a persistent internet connection to function, especially for those companies that don’t offer easy ways to report security vulnerabilities.”

    theverge.com/2024/10/12/242685

    #Robovacs

  4. Teenage hackers yelling slurs and terrorizing pets enabled by security vulnerabilities in robot vacuums.:please_no: :facepalm:

    The Verge opines:

    “Issues like these can feel inevitable when so many smart home devices require a persistent internet connection to function, especially for those companies that don’t offer easy ways to report security vulnerabilities.”

    theverge.com/2024/10/12/242685

    #Robovacs

  5. #CyberSecurity #Privacy #RobotVaccums #RoboVacs #IoT #SmartHome: "The problem is that most of these smart home companies are selling consumer hardware and don’t want or care to invest much in security — it’s an afterthought for a home appliance. You can buy one of dozens of robovacs on Amazon; most people just want the cheapest one. So this is what we get, a company that doesn’t put basic security measures in place.

    And ‘basic’ seems to be fair here. ABC found that although Ecovacs accounts are password-protected, and a further four-digit PIN code is required to access the video feed, that PIN code is not validated server-side—meaning anyone with the basic know-how of a tool like Chrome web inspector could bypass it. It’s likely that Swenson was reusing credentials from other services, but the code should have been an extra factor that prevented access anyway. At a bare minimum all Ecovacs really needs to do is some basic “if-true” validation on its servers before opening the video feed.

    Ecovacs reportedly was informed about the vulnerability back in 2023 by researchers and didn’t take action until recently. It says a more substantial security update will be released in November.

    It sounds crazy when we’re talking about a vacuum of all things, but if you’re going to buy a robot vacuum, be sure to research the product’s security measures."

    gizmodo.com/hacked-robot-vacuu

  6. #CyberSecurity #Privacy #RobotVaccums #RoboVacs #IoT #SmartHome: "The problem is that most of these smart home companies are selling consumer hardware and don’t want or care to invest much in security — it’s an afterthought for a home appliance. You can buy one of dozens of robovacs on Amazon; most people just want the cheapest one. So this is what we get, a company that doesn’t put basic security measures in place.

    And ‘basic’ seems to be fair here. ABC found that although Ecovacs accounts are password-protected, and a further four-digit PIN code is required to access the video feed, that PIN code is not validated server-side—meaning anyone with the basic know-how of a tool like Chrome web inspector could bypass it. It’s likely that Swenson was reusing credentials from other services, but the code should have been an extra factor that prevented access anyway. At a bare minimum all Ecovacs really needs to do is some basic “if-true” validation on its servers before opening the video feed.

    Ecovacs reportedly was informed about the vulnerability back in 2023 by researchers and didn’t take action until recently. It says a more substantial security update will be released in November.

    It sounds crazy when we’re talking about a vacuum of all things, but if you’re going to buy a robot vacuum, be sure to research the product’s security measures."

    gizmodo.com/hacked-robot-vacuu