Yarbo Pledges to Remove Intentional Backdoor from Robot Lawn Mowers
Yarbo, the manufacturer of robot lawn mowers, has announced a significant policy reversal regarding security vulnerabilities in its devices. Following reports that a security researcher could remotely hijack the robots and access user data, the company initially promised to patch security holes but intended to keep a remote backdoor for internal troubleshooting. However, after further scrutiny and public pressure, Yarbo co-founder Kenneth Kohlmann confirmed that the company will completely remove this intentional backdoor by default. Instead, remote access will become an optional, opt-in feature that users must explicitly enable if they require remote technical support. This decision aims to prevent bad actors from reprogramming the robots over the internet. While firmware updates with unique root passwords are already being rolled out, the full removal of the remote access tunnel will take time. The company is now collaborating with the security researcher who exposed the flaws to validate these changes, marking a shift towards greater user control and enhanced cybersecurity for consumer robotics.
Wire timeline
Yarbo Pledges to Remove Intentional Backdoor from Robot Lawn Mowers
Yarbo, the manufacturer of robot lawn mowers, has announced a significant policy reversal regarding security vulnerabilities in its devices. Following reports that a security researcher could remotely hijack the robots and access user data, the company initially promised to patch security holes but intended to keep a remote backdoor for internal troubleshooting. However, after further scrutiny and public pressure, Yarbo co-founder Kenneth Kohlmann confirmed that the company will completely remove this intentional backdoor by default. Instead, remote access will become an optional, opt-in feature that users must explicitly enable if they require remote technical support. This decision aims to prevent bad actors from reprogramming the robots over the internet. While firmware updates with unique root passwords are already being rolled out, the full removal of the remote access tunnel will take time. The company is now collaborating with the security researcher who exposed the flaws to validate these changes, marking a shift towards greater user control and enhanced cybersecurity for consumer robotics.
The Verge