Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

25 February 2026

The Verge: “The DJI Romo robovac had security so poor, this man remotely accessed thousands of them”

Sammy Azdoufal claims he wasn’t trying to hack every robot vacuum in the world. He just wanted to remote control his brand-new DJI Romo vacuum with a PS5 gamepad, he tells The Verge, because it sounded fun.

But when his homegrown remote control app started talking to DJI’s servers, it wasn’t just one vacuum cleaner that replied. Roughly 7,000 of them, all around the world, began treating Azdoufal like their boss.


On Tuesday, when he showed me his level of access in a live demo, I couldn’t believe my eyes. Ten, hundreds, thousands of robots reporting for duty, each phoning home MQTT data packets every three seconds to say: their serial number, which rooms they’re cleaning, what they’ve seen, how far they’ve traveled, when they’re returning to the charger, and the obstacles they encountered along the way.

I watched each of these robots slowly pop into existence on a map of the world. Nine minutes after we began, Azdoufal’s laptop had already cataloged 6,700 DJI devices across 24 different countries and collected over 100,000 of their messages. If you add the company’s DJI Power portable power stations, which also phone home to these same servers, Azdoufal had access to over 10,000 devices.

Sean Hollister

Speaking of AI coding bots taking down AWS, this story is in several ways the opposite: on one hand evidently human programmers can and have also delivered applications riddled with bugs and security holes — and rather serious ones in this case, as the article later mentions another vulnerability so bad it won’t even detail it until DJI has time to fix it. The other aspect is that here Azdoufal used Claude Code to reverse engineer DJI’s protocols, thus exposing the first issue described in the paragraphs above.

25 July 2025

heise online: “EU launches its own DNS service with practical functions”

The EU now offers its own DNS resolution service (Resolver) and wants to help its citizens to become less dependent on offers from large US companies such as Cloudflare and Google. The service is called DNS4EU and pre-filters internet addresses at the user’s request: In addition to phishing and fraud sites, it blocks websites and advertising that are harmful to minors.

A DNS resolver is one of the almost invisible basic services for stable Internet access: it works in the background, usually at the provider, and ensures that Internet addresses such as www.heise.de are translated into IP addresses such as 2a02:2e0:3fe:1001:7777:772e:2:85. However, in many countries – including Germany –, blocking orders by lobby associations or youth protection authorities are often implemented at DNS level. For this reason and for reasons of speed, users often make do with alternative providers such as Google, which not only uses one of the most beautiful IP addresses with the resolver 8.8.8.8, but also answers over a trillion queries a day. Cloudflare (1.1.1.1) and Quad9 (9.9.9.9) also operate open resolvers. The problem is that many of these servers are located in the USA, which is why the Quad9 consortium has already moved its headquarters to Zurich.

Dr. Christopher Kunz

Good to see the European Union taking – albeit small – steps towards that elusive digital sovereignty and autonomy from US-based companies. While far from the flashy headlines about AI and quantum, DNS over HTTPS improves user privacy and security by preventing eavesdropping and manipulation of DNS data by man-in-the-middle attacks.

05 May 2023

Google Online Security Blog: “So long passwords, thanks for all the phish”

When you add a passkey to your Google Account, we will start asking for it when you sign in or perform sensitive actions on your account. The passkey itself is stored on your local computer or mobile device, which will ask for your screen lock biometrics or PIN to confirm it’s really you. Biometric data is never shared with Google or any other third party – the screen lock only unlocks the passkey locally.

Unlike passwords, passkeys can only exist on your devices. They cannot be written down or accidentally given to a bad actor. When you use a passkey to sign in to your Google Account, it proves to Google that you have access to your device and are able to unlock it. Together, this means that passkeys protect you against phishing and any accidental mishandling that passwords are prone to, such as being reused or exposed in a data breach. This is stronger protection than most 2SV (2FA/MFA) methods offer today, which is why we allow you to skip not only the password but also 2SV when you use a passkey. In fact, passkeys are strong enough that they can stand in for security keys for users enrolled in our Advanced Protection Program.

Arnar Birgisson & Diana K Smetters

I’m no expert in security, but being able to log in seamlessly, without a password, a password manager, or 2FA, sounds like a genuinely useful feature. Microsoft has something similar through the Authenticator app, where you can sign in with only your email address and a confirmation in the app.

27 December 2022

TechCrunch: “LastPass says hackers stole customers’ password vaults”

Password manager giant LastPass has confirmed that cybercriminals stole its customers’ encrypted password vaults, which store its customers’ passwords and other secrets, in a data breach earlier this year.

In an updated blog post on its disclosure, LastPass CEO Karim Toubba said the intruders took a copy of a backup of customer vault data by using cloud storage keys stolen from a LastPass employee. The cache of customer password vaults is stored in a “proprietary binary format” that contains both unencrypted and encrypted vault data, but technical and security details of this proprietary format weren’t specified. The unencrypted data includes vault-stored web addresses. It’s not clear how recent the stolen backups are.

LastPass said customers’ password vaults are encrypted and can only be unlocked with the customers’ master password, which is only known to the customer. But the company warned that the cybercriminals behind the intrusion may attempt to use brute force to guess your master password and decrypt the copies of vault data they took.

Zack Whittaker

I have moved away from LastPass after they restricted free accounts to a single device type, either desktop or mobile. The string of hacks that followed and the company’s bad practices continue to reassure me that I have made the right choice. Nevertheless, I haven’t deleted my account or any of the stored data, so it might have been affected by this breach. I use a fairly strong master password on LastPass, but that’s no guarantee that the encryption won’t be cracked eventually. It might be time to go through all those passwords, update them for critical services, and eventually remove my LastPass account altogether.

02 December 2022

The Washington Post: “Mysterious company with government ties plays key internet role”

Google’s Chrome, Apple’s Safari, nonprofit Firefox and others allow the company, TrustCor Systems, to act as what’s known as a root certificate authority, a powerful spot in the internet’s infrastructure that guarantees websites are not fake, guiding users to them seamlessly.

The company’s Panamanian registration records show that it has the identical slate of officers, agents and partners as a spyware maker identified this year as an affiliate of Arizona-based Packet Forensics, which public contracting records and company documents show has sold communication interception services to U.S. government agencies for more than a decade.

One of those TrustCor partners has the same name as a holding company managed by Raymond Saulino, who was quoted in a 2010 Wired article as a spokesman for Packet Forensics.

Saulino also surfaced in 2021 as a contact for another company, Global Resource Systems, that caused speculation in the tech world when it briefly activated and ran more than 100 million previously dormant IP addresses assigned decades earlier to the Pentagon. The Pentagon reclaimed the digital territory months later, and it remains unclear what the brief transfer was about, but researchers said the activation of those IP addresses could have given the military access to a huge amount of internet traffic without revealing that the government was receiving it.

Joseph Menn

Despite the concerted push a couple of years ago to move the majority of websites to secure connections, online traffic remains vulnerable to surveillance and hacking. After this investigation was published, Firefox and Microsoft Edge said they would stop trusting new certificates from TrustCor Systems, but the underlying issue remains. Organizations with an interest in interception would just create new, more sophisticated and concealed methods to exploit security certificates for their purposes.

12 September 2022

Time: “The Twitter Whistleblower Needs You to Trust Him”

Zatko had come from a long line of jobs where he had free rein to tear up organizational structures and prioritize security above all else. But at Twitter, current and former colleagues say, he found himself in a different environment: navigating tense internal politics at a corporation bent on boosting revenue, without support from his superiors. Some employees caught up in the tumult perceived Zatko to be a figure hired by then CEO Jack Dorsey for publicity reasons, stepping on the toes of qualified colleagues with more institutional knowledge. Technically brilliant and morally rigid, Zatko was an iconoclast stepping into a corporate bureaucracy. It’s like asking a doctor who’s been trained to do brain surgery to suddenly become a podiatrist, says a former Twitter colleague.

The polarized reactions to Zatko’s disclosures illustrate just how atypical a tech whistle-blower he is. Last year, Frances Haugen, a former Facebook product manager, disclosed tens of thousands of pages of internal company documents that revealed a company prioritizing profits over user safety. But readers didn’t have to take Haugen’s word for it; they could read the words of Facebook’s own safety teams. Zatko is different. As a former senior executive, he had a bird’s-eye view into Twitter’s decision-making, ultimately responsible for hundreds of staff in some of Twitter’s most high-priority work streams. But he didn’t release the same breadth of documentation as Haugen; while Zatko supplied some exhibits to support his claims, including internal emails, his partially redacted disclosures rely largely on his own credibility as one of the most celebrated figures in cybersecurity. He is implicitly asking the public to trust that his version of events is the correct one, and that Twitter is lying.

Billy Perrigo, Andrew R. Chow & Vera Bergengruen

That Twitter has major security holes was pretty evident back in 2017 when an employee deactivated Donald Trump’s personal account on their last day of work; and again in 2020 when teenagers temporarily hacked the accounts of Barack Obama, Joe Biden, Elon Musk, and other celebrities. As troubling as it may be to think that these security flaws remain uncorrected, I have a hard time believing Peiter Zatko’s allegations in the absence of hard evidence. Some of them don’t make much sense; others, such as regarding bots and spam, actually support Twitter’s position and reveal Zatko’s superficial understanding of internal processes.

03 May 2022

XDA Developers: “Microsoft Edge is getting a built-in VPN powered by Cloudflare”

Microsoft is testing a VPN-like service for its Edge browser, adding a new layer of security and privacy to the browsing experience. A recently-discovered support page on Microsoft’s website details the “Microsoft Edge Secure Network” feature, which provides data encryption and prevents online tracking, courtesy of Cloudflare.

While it isn’t available yet, even if you have the latest Dev channel build, the Microsoft Edge Secure Network feature appears to be similar in nature to Cloudflare’s 1.1.1.1 service. This is essentially a proxy or VPN service, which encrypts your browsing data so that it’s safe from prying eyes, including your ISP. It also keeps your location private, so you can use it to access geo-restricted websites, or content that’s blocked in your country.

João Carrasqueira

Good to see Microsoft continuing to invest in new features for their browser. The idea of integrating a VPN into the browser is not exactly novel, as Opera and Mozilla offer something similar, but it’s good to expand the reach of secure browsing services to more users. In its current, pre-release state, Microsoft Edge Secure Network looks fairly limited, as you need to sign in with a Microsoft account and the traffic is capped at 1 gigabyte a month. It would be a great idea to turn this on by default in InPrivate mode, as it would offer an extra layer of protection. Perhaps at launch Microsoft will offer a paid tier as well with unlimited traffic for a monthly fee.