Ecovacs says it will fix bugs that can be abused to spy on robot owners

Date:

Share post:


Earlier this month, security researchers warned that a series of security flaws in vacuum and lawn mower robots made by Ecovacs could allow hackers to spy on their owners through the devices’ microphones and cameras. 

At the time, Ecovacs told TechCrunch it concluded that the flaws found by the researchers “are extremely rare in typical user environments and require specialized hacking tools and physical access to the device.”

“Therefore, users can rest assured that they do not need to worry excessively about this,” read the emailed statement, declining to commit to fixing the vulnerabilities. 

Two weeks later, Ecovacs changed its mind, telling the researchers and TechCrunch that, actually, the company will fix the bugs.

“We have conducted an in-depth verification and self-examination. We have identified several areas where there is room for improvement,” Martin Ma, the director of Ecovacs’ security committee, told TechCrunch in an email. “In response, we have initiated targeted improvements and addressing the issues highlighted.”

Contact Us

Do you have more information about flaws in Ecovacs or other internet-connected home robots? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

On August 10, security researchers Dennise Giese and Braylinn gave a talk about their research into Ecovacs home robots at the annual hacking Def Con conference in Las Vegas. The two said they analyzed 11 Ecovacs devices and found several flaws. 

The most impactful vulnerability, they said, allows anyone using a phone to connect to an Ecovacs robot via Bluetooth from as far as 450 feet — around 130 meters — and take control of the devices. That flaw would then let the hackers monitor the robots from anywhere because the robots are connected to the internet via Wi-Fi. 

Other flaws included a bug that would allow someone to access a robot vacuum after selling it and deleting their account, meaning they could then spy on a device’s new owners, according to the researchers.    

In an email to Giese on August 16 and shared with TechCrunch, Ecovacs’ Ma mentioned that the researchers’ talk at Def Con “has captured my attention.” That’s why, the email continued, Ma asked the Ecovacs security team to retrieve the correspondence the company had with the researchers. Ma said that the company “inadvertently overlooked” the researchers’ emails from December 2023. 

“We have carefully reviewed your points raised in the previous emails and the Demos at Def Con 2024, and conducted an in-depth verification and self-examination,” Ma said, adding that the company will fix issues in two Ecovacs models — the Goat G1 and the X1 — and in the Ecovacs app. 

“Your analysis has been greatly valued and appraised by our technical team. Your insights are invaluable in safeguarding the security and integrity of our products, and they contribute significantly to the consumer electronics industry as a whole,” Ma wrote. “Ultimately, it is the general consumers who will benefit most from your dedication.”



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

OpenAI’s GPT-5 reportedly falling short of expectations

OpenAI’s efforts to develop its next major model, GPT-5, are running behind schedule, with results that don’t...

OpenAI announces new o3 model — but you can’t use it yet

Welcome back to Week in Review. This week, we’re looking at OpenAI’s last — and biggest —...

Google pushes back against DOJ’s ‘interventionist’ remedies in antitrust case

Google has offered up its own proposal in a recent antitrust case that saw the US Department...

If climate tech is dead, what comes next?

Humans have an innate desire to name things, but to be honest, we’re not always that good...

Hollywood angels: Here are the celebrities who are also star VCs

Becoming a venture capitalist has become the latest status symbol in Hollywood.  Everyone these days, from Olivia Wilde...

Meet Skyseed, a VC fund and incubator backing the Bluesky and AT Protocol ecosystem

On November 15, Peter Wang posted a message requesting ideas for a new incubator and fund to...

Sam Altman disputes Marc Andreessen’s description of AI meetings with Biden administration

Famed investor Marc Andreessen recently talked about meetings with Biden administration staff who gave him the impression...

EV startup Canoo places remaining employees on a ‘mandatory unpaid break’

Struggling electric van startup Canoo has placed its remaining employees on what it’s calling a “mandatory unpaid...