• 87Six@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 months ago

    Since I dont see it mentioned, the company is

    iLife

    iLife makes vacuums that map your house and can be remote controlled

    Just so we are clear. You should all up your name and shame game.

  • Regna@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 months ago

    At first I thought ”Well, duh!”, but the manufacturer having a remote kill switch when he network blocked his vacuum from sharing his home map data with them, as well as unprotected root access when connecting to the vacuum… urgh.

    The engineer says he stopped the device from broadcasting data, though kept the other network traffic — like firmware updates — running like usual. The vacuum kept cleaning for a few days after, until early one morning when it refused to boot up.

    After reverse engineering the vacuum, a painstaking process which included reprinting the devices’ circuit boards and testing its sensors, he found something horrifying: Android Debug Bridge, a program for installing and debugging apps on devices, was “wide open” to the world. “In seconds, I had full root access. No hacks, no exploits. Just plug and play,” Narayanan said.

  • imetators@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 months ago

    Am I too dumb to understand why sending cartographer data is wrong?

    His model is iLife A11 that has Lidar. He probably has an app that is used to control robot and shows cleaning progression. Vac 100% Lidar’d his entire home and sent data to create map in the app.

    How in the fuck he thinks it is getting that map? If his ass so smart to find a killswitch and reverse it, how come he doesn’t grasp that map data is sent to a server though which he ca use vac app? Like in what world is it not obvious?

    Not even gonna discuss about TOS he signed, or that it is general cheap brand cheap but super smart model for it’s price.

    Unless some FOSS firmware and software is installed, that thing most certainly will ping back home every chance it gets.

    Sidenote: My TV now is offline cause when it kept calling home (ove 60% of my pi-holes querries of all time was TV), it would freeze due to pi-hole block. Once set offline - issue is gone. I also know my robo vac is pinging, but at the same time if I block it, I’ll lose app controls which I wont do. Sadly, my vac doesn’t support Valetudo.

    • Reginald_T_Biter@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 months ago

      I think yes, to your first question. Couldn’t it just crunch the lidardata locally to feed into cartographer, I don’t understand why you don’t understand that this is the issue.

      • Wispy2891@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        10 months ago

        afaik the lidar data is crunched locally, then sent to the remote server for easy consumption

        when those vacuums are flashed with valetudo, they can still make the map with lidar without internet connection

        • Reginald_T_Biter@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          arrow-down
          1
          ·
          10 months ago

          Exactly. So it’s pure surreptitious data exfiltration. They only reason they send the data back is because they can, and there is value for them.

  • ByteOnBikes@discuss.online
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 months ago

    In addition, Narayanan says he uncovered a suspicious line of code broadcasted from the company to the vacuum, timestamped to the exact moment it stopped working. “Someone — or something — had remotely issued a kill command,” he wrote.

    “I reversed the script change and rebooted the device,” he wrote. “It came back to life instantly. They hadn’t merely incorporated a remote control feature. They had used it to permanently disable my device.”

    In short, he said, the company that made the device had “the power to remotely disable devices, and used it against me for blocking their data collection… Whether it was intentional punishment or automated enforcement of ‘compliance,’ the result was the same: a consumer device had turned on its owner.”

    They kill switched it remotely. Yikes.

    • Evotech@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 months ago

      More likely it killed itself after not being in contact with home base. Since it worked fine elsewhere

  • 1985MustangCobra@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    10 months ago

    or…just buy a vacuum cleaner and vacuum your house? you don’t need smart devices for everything.