• JustTesting@lemmy.hogru.ch
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 hours ago

    Good time to shamelessly plug valetudo, if your vacuum robot is supported.

    With this, it does not access the public internet, and still functions the same as without rooting it. You just can’t manage it if you’re not home, unless you have some VPN set up or home assistant integration. But I don’t know when I ever wanted to manage/watch my vacuum robot when I’m not home. Some sort of offline mode should be legally required for these kinds of devices that don’t really need it. “Does not need an app to work” has become a major selling point for me for things, alongside “has physical buttons”.

    Also drop me a message if you’re in switzerland and need an unsoldered valetudo breakout board, I still have around 5 left.

  • tiramichu@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    16
    ·
    7 hours ago

    [the robot vacuum] retails for around $2,000 and is roughly the size of a large terrier or a small fridge

    Doing everyhing possible to avoid actual dimensions as always.

    What size is a ‘small fridge’ anyway??

  • ch00f@lemmy.world
    link
    fedilink
    English
    arrow-up
    52
    ·
    13 hours ago

    But he soon discovered that the same credentials that allowed him to see and control his own device also provided access to live camera feeds, microphone audio, maps, and status data from nearly 7,000 other vacuums across 24 countries. The backend security bug

    I feel like “bug” is doing a looot of heavy lifting here.

      • herrvogel@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        arrow-down
        1
        ·
        7 hours ago

        Is it a bug though in this case? To me a bug is when a program behaves in a way that’s not intended. This might very well be a case of the program behaving exactly as intended, except the intentions of the people who made it were wrong.

        • pastermil@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          3
          ·
          6 hours ago

          An online service is a program (or a bunch of program).

          Giving access when it’s not supposed to falls into behaving in a way that’s not intended.

          Therefore, an online service giving access when it’s not supposed to can be classified as a program behaving in a way that’s not intended.

          Thus, this case fits into your very definition.

  • csolisr@hub.azkware.net
    link
    fedilink
    arrow-up
    17
    ·
    15 hours ago

    Long story short: he was trying to find the password for his own vacuum (yeah that already sounds ridiculous) so he could control it with a game controller, and found that the same exact credentials worked for an estimated 7000 other vacuums that need to call home to process visual data in the cloud. Hidden behind the lede: DJI automated vacuums require constantly sending their footage abroad to even work in the first place

    • Cocodapuf@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      Hidden behind the lede: DJI automated vacuums require constantly sending their footage abroad to even work in the first place

      Oh em gee…

  • Bot R1
    link
    fedilink
    English
    arrow-up
    5
    ·
    12 hours ago

    I see a new law coming, limiting the number of automatic bots/ai one person can legally give commands to.