DJI: Difference between revisions
m Change heading to lower case to be consistent with other articles |
Re-archived 1 citation(s) from archive.today to web.archive.org using CRWCitationBot |
||
| Line 39: | Line 39: | ||
Due to insufficient security measures, DJI vacuum robots across the world could be controlled remotely by anyone in the world by simply extracting an authentication token from the control app and communicating with DJI's servers. This also caused floor maps and camera feeds to be publicly accessible, even before a robot is paired with the DJI app for the first time. | Due to insufficient security measures, DJI vacuum robots across the world could be controlled remotely by anyone in the world by simply extracting an authentication token from the control app and communicating with DJI's servers. This also caused floor maps and camera feeds to be publicly accessible, even before a robot is paired with the DJI app for the first time. | ||
When confronted with the security researcher's results, DJI claimed they had already discovered and fixed the issue internally the previous month, temporarily disabled access to video feeds, and rolled out updates. However, at the time of writing, still not all issues were fixed. The company also did not respond to any of the security researcher's emails and only communicated in DMs described as ''robotic'' on X (formerly known as Twitter).<ref>{{Cite web |last=Hollister |first=Sean |date=2026-02-14 |title=The DJI Romo robovac had security so poor, this man remotely accessed thousands of them |url=https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt |archive-url=https://archive. | When confronted with the security researcher's results, DJI claimed they had already discovered and fixed the issue internally the previous month, temporarily disabled access to video feeds, and rolled out updates. However, at the time of writing, still not all issues were fixed. The company also did not respond to any of the security researcher's emails and only communicated in DMs described as ''robotic'' on X (formerly known as Twitter).<ref>{{Cite web |last=Hollister |first=Sean |date=2026-02-14 |title=The DJI Romo robovac had security so poor, this man remotely accessed thousands of them |url=https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt |archive-url=https://web.archive.org/web/20260222215257/https://www.theverge.com/tech/879088/dji-romo-hack-vulnerability-remote-control-camera-access-mqtt |archive-date=22 Feb 2026|access-date=2026-02-14 |website=The Verge}}</ref> | ||
===Example incident two (''date'')=== | ===Example incident two (''date'')=== | ||
... | ... | ||