Yarbo Promises Security Fixes After Robot Mower Hacking Incident
Robot lawn mower manufacturer Yarbo has issued a detailed response and apology following a security report revealing critical vulnerabilities in its devices. The report, published by security researcher Andreas Makris, demonstrated that thousands of Yarbo robots could be easily hijacked, exposing user data such as GPS coordinates, Wi-Fi passwords, and email addresses. In a direct statement, Yarbo confirmed the findings, acknowledging issues like uniform root passwords across all units. The company has temporarily disabled remote access and pledged to roll out security updates within a week, including implementing unique credentials for each device. However, Yarbo stated it will retain a remote backdoor for diagnostic purposes, albeit with stricter controls requiring user authorization and audit logging. This decision has drawn scrutiny, as previous claims that only authorized employees had access were proven false. Yarbo is establishing a dedicated security response center and engaging directly with Makris to address remediation. While the company attributes some flaws to legacy services, it faces ongoing questions about why the persistent backdoor cannot be removed entirely or made optional for customers concerned about privacy and safety.
Wire timeline
Yarbo Promises Security Fixes After Robot Mower Hacking Incident
Robot lawn mower manufacturer Yarbo has issued a detailed response and apology following a security report revealing critical vulnerabilities in its devices. The report, published by security researcher Andreas Makris, demonstrated that thousands of Yarbo robots could be easily hijacked, exposing user data such as GPS coordinates, Wi-Fi passwords, and email addresses. In a direct statement, Yarbo confirmed the findings, acknowledging issues like uniform root passwords across all units. The company has temporarily disabled remote access and pledged to roll out security updates within a week, including implementing unique credentials for each device. However, Yarbo stated it will retain a remote backdoor for diagnostic purposes, albeit with stricter controls requiring user authorization and audit logging. This decision has drawn scrutiny, as previous claims that only authorized employees had access were proven false. Yarbo is establishing a dedicated security response center and engaging directly with Makris to address remediation. While the company attributes some flaws to legacy services, it faces ongoing questions about why the persistent backdoor cannot be removed entirely or made optional for customers concerned about privacy and safety.
The Verge