+| | [Reverse engineering and hacking Ecovacs robots](https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.html) ([slides]([url](https://dontvacuum.me/talks/HITCON2024/HITCON-CMT-2024_Ecovacs.pdf)), [video]([url](https://www.youtube.com/playlist?list=PL9PoaNtZCJRYiwGlHVpGZdVqPKQ2mo57k)), [news article]([url](https://www.abc.net.au/news/2024-10-04/robot-vacuum-hacked-photos-camera-audio/104414020))) | Dennis Giese, Braelynn | Vulnerabilities and security risks of Ecovacs smart home robots, highlighting serious flaws such as broken encryption, missing certificate verification, inadequate access control, and unauthorized live camera access. Building on years of experience hacking devices from brands like Roborock and Xiaomi, the presenters dive into the alarming security issues within Ecovacs robots, the market leader in home robotics. The talk covers the difficulties of reporting bugs to the company and warns against relying on third-party certifications. It emphasizes the importance of being cautious with device choices and even personal relationships, due to the potential privacy risks involved. | 24-08-2024 |
0 commit comments