13 votes

Hackers take control of robot vacuums in multiple cities, yell racial slurs

17 comments

  1. [14]
    DefinitelyNotAFae
    Link
    WHY DO THEY EVEN HAVE SPEAKERS

    WHY DO THEY EVEN HAVE SPEAKERS

    9 votes
    1. [4]
      boxer_dogs_dance
      Link Parent
      I would ask why should it be online. I don't want my vacuum phoning home. Let it talk, but don't let it listen or transmit information.

      I would ask why should it be online. I don't want my vacuum phoning home. Let it talk, but don't let it listen or transmit information.

      9 votes
      1. [3]
        vord
        Link Parent
        I just recently purchased a robot vaccum/mop from Lidl for $50. Here's my review: It does both functions as intended for 1/4 the price of the cheapest option at Target. It doesn't have fancy laser...

        I just recently purchased a robot vaccum/mop from Lidl for $50. Here's my review:

        It does both functions as intended for 1/4 the price of the cheapest option at Target. It doesn't have fancy laser walls or anything, or app programability. It isn't remotely exploitable, as it has no way to connect to the internet at all.

        It beeps if it gets stuck using a simple pizo-electric buzzer. It has a basic IR remote to set a timer or choose a mode.

        The only downside is that if I want to wall off an area, I have to do it manually. Turns out that's not a huge deal for me, since I usually only run it at night or when we're not home so we just unblock it after.

        11/10 purchase. This is what smart appliances should look like.

        7 votes
    2. [5]
      updawg
      Link Parent
      They gotta tell you what's wrong with them. "Low battery, please charge." "Error 644, cameras obscured." Stuff like that.

      They gotta tell you what's wrong with them. "Low battery, please charge." "Error 644, cameras obscured." Stuff like that.

      6 votes
      1. cfabbro
        (edited )
        Link Parent
        This. My Eufy one also lets me know whenever it's gotten stuck or can't return to the base station by notifying me over the app, and beeping every few seconds until it's found, and I'm glad for...

        This. My Eufy one also lets me know whenever it's gotten stuck or can't return to the base station by notifying me over the app, and beeping every few seconds until it's found, and I'm glad for that functionality. My buddy has a Roomba without a speaker or any way to locate it in his house, so he is constantly complaining about having to search every room until he finds it whenever that happens, which with 2 dogs and a young kid in the house is rather frequent.

        6 votes
      2. vord
        Link Parent
        Thats why god invented diagnostic LEDs. 4 LEDs and a pizo-electric buzzer can fill a 200-page dianostic book, no fancy speaker with TTS required.

        Thats why god invented diagnostic LEDs. 4 LEDs and a pizo-electric buzzer can fill a 200-page dianostic book, no fancy speaker with TTS required.

        2 votes
      3. raze2012
        Link Parent
        just ping me on my phone with Bluetooth please. Last thing I need in my house is more noisy objects and beings.

        just ping me on my phone with Bluetooth please. Last thing I need in my house is more noisy objects and beings.

        1 vote
      4. DefinitelyNotAFae
        Link Parent
        I really don't think it needs that as others said. Either an app alert if necessary, or beeps or something would be fine IMO

        I really don't think it needs that as others said. Either an app alert if necessary, or beeps or something would be fine IMO

        1 vote
    3. [4]
      Hobofarmer
      Link Parent
      You remember "I have no mouth yet I must scream?"

      You remember "I have no mouth yet I must scream?"

      2 votes
      1. DefinitelyNotAFae
        Link Parent
        It explains why smart devices are a form of torture to humans.

        It explains why smart devices are a form of torture to humans.

        1 vote
  2. CrazyProfessor02
    Link
    The fact that the company was made aware of this, by the people that found it before showcasing it at that conference, but the company decide not to pursue to patch it, and to carry on with a...

    The fact that the company was made aware of this, by the people that found it before showcasing it at that conference, but the company decide not to pursue to patch it, and to carry on with a business as usually mentally. It's just annoying that did nothing before this event happened. And even then it's considered halved assed.

    He took the device to the garage, and never switched it on again.

    I would have taken a hammer to the fucking thing at that point, just to bite the bullet and accept the money lost. And so that I am not tempted of giving it away or having someone else might pick it up by chance.

    4 votes
  3. SteeeveTheSteve
    Link
    LOL That's a good one! Ya'll know you can just restart your modem and get a new IP right?

    They also said the company's technical team had identified the culprit's IP address, and disabled it to prevent further access.

    LOL That's a good one! Ya'll know you can just restart your modem and get a new IP right?

    4 votes
  4. tibpoe
    Link
    From their statement: A single person was able to make 90x the number of login attempts that every other user in their system was making combined? I appreciate their transparency, but this doesn't...

    From their statement:

    This investigation also identified a credential stuffing event, in which a third party attempted to use email addresses and passwords to try to gain access to Ecovacs’ customer accounts. There were significantly more attempts to log-in than the average daily amount, by a factor of 90:1. These all from the same IP address, which was identified as coming from both an unusual device, and an unusual location. This IP address was
    immediately blocked.

    A single person was able to make 90x the number of login attempts that every other user in their system was making combined? I appreciate their transparency, but this doesn't look good.

    4 votes