this post was submitted on 23 Feb 2026
147 points (99.3% liked)

Not The Onion

20535 readers
1739 users here now

Welcome

We're not The Onion! Not affiliated with them in any way! Not operated by them in any way! All the news here is real!

The Rules

Posts must be:

  1. Links to news stories from...
  2. ...credible sources, with...
  3. ...their original headlines, that...
  4. ...would make people who see the headline think, “That has got to be a story from The Onion, America’s Finest News Source.”

Please also avoid duplicates.

Comments and post content must abide by the server rules for Lemmy.world and generally abstain from trollish, bigoted, or otherwise disruptive behavior that makes this community less fun for everyone.

And that’s basically it!

founded 2 years ago
MODERATORS
 

cross-posted from: https://lemy.lol/post/61542544

top 21 comments
sorted by: hot top controversial new old
[–] Kolanaki@pawb.social 4 points 12 hours ago

World's suckiest army.

[–] tiramichu@sh.itjust.works 23 points 22 hours ago (1 children)

[the robot vacuum] retails for around $2,000 and is roughly the size of a large terrier or a small fridge

Doing everyhing possible to avoid actual dimensions as always.

What size is a 'small fridge' anyway??

[–] d_k_bo@feddit.org 10 points 22 hours ago

!anythingbutmetric@discuss.tchncs.de

[–] JustTesting@lemmy.hogru.ch 8 points 19 hours ago (2 children)

Good time to shamelessly plug valetudo, if your vacuum robot is supported.

With this, it does not access the public internet, and still functions the same as without rooting it. You just can't manage it if you're not home, unless you have some VPN set up or home assistant integration. But I don't know when I ever wanted to manage/watch my vacuum robot when I'm not home. Some sort of offline mode should be legally required for these kinds of devices that don't really need it. "Does not need an app to work" has become a major selling point for me for things, alongside "has physical buttons".

Also drop me a message if you're in switzerland and need an unsoldered valetudo breakout board, I still have around 5 left.

[–] greatwhitebuffalo41@slrpnk.net 2 points 6 hours ago

Damn, not supported. Bookmarked though for when I need a new one at some point

[–] besmtt@lemmy.world 4 points 13 hours ago

I absolutely love Valetudo! It's been rock solid for me for years.

[–] ch00f@lemmy.world 64 points 1 day ago (1 children)

But he soon discovered that the same credentials that allowed him to see and control his own device also provided access to live camera feeds, microphone audio, maps, and status data from nearly 7,000 other vacuums across 24 countries. The backend security bug

I feel like "bug" is doing a looot of heavy lifting here.

[–] pastermil@sh.itjust.works 8 points 1 day ago (1 children)

It also illustrates how a security vulnerability is simply a bug, albeit a dangerous one.

[–] herrvogel@lemmy.world 9 points 23 hours ago (1 children)

Is it a bug though in this case? To me a bug is when a program behaves in a way that's not intended. This might very well be a case of the program behaving exactly as intended, except the intentions of the people who made it were wrong.

[–] pastermil@sh.itjust.works 4 points 22 hours ago (1 children)

An online service is a program (or a bunch of program).

Giving access when it's not supposed to falls into behaving in a way that's not intended.

Therefore, an online service giving access when it's not supposed to can be classified as a program behaving in a way that's not intended.

Thus, this case fits into your very definition.

[–] javiwhite@feddit.uk 3 points 12 hours ago (1 children)

Giving access when it's not supposed too

Not sure I'd agree with that statement. Personally I see it as the correct credentials were provided, and thus access was granted; ergo, the app performed as intended, and there is no bug.

The error here seems to be around the lack of concern for security; nobody considered that using the same credentials for their fleet of robots could pose a threat if discovered. It's no different to someone using the same email and password for everything, and then wondering why their facebook has been hacked after their Reddit account leaked. The problem isn't a bug in code, it's just poor cybersecurity hygiene; what we see here is the same just on a commercial level. 

[–] thallamabond@lemmy.world 2 points 12 hours ago

The error here seems to be around the lack of concern for security

I feel like this is extremely generous, but I'm a bit of a cynic.

I don't see an error at all. All I see is Upskirt Robot working as intended

[–] sheridan@lemmy.world 17 points 1 day ago (1 children)

Why do these things require microphones?

[–] Dhs92@piefed.social 4 points 1 day ago

Some are voice controlled

[–] luthis@lemmy.nz 18 points 1 day ago

Minions! Tonight we vacuum.. THE ROOM!

[–] Railcar8095@lemmy.world 9 points 1 day ago (1 children)
[–] TheBat@lemmy.world 2 points 21 hours ago

Great tagline for a vacuum advert.

[–] csolisr@hub.azkware.net 19 points 1 day ago (1 children)

Long story short: he was trying to find the password for his own vacuum (yeah that already sounds ridiculous) so he could control it with a game controller, and found that the same exact credentials worked for an estimated 7000 other vacuums that need to call home to process visual data in the cloud. Hidden behind the lede: DJI automated vacuums require constantly sending their footage abroad to even work in the first place

[–] Cocodapuf@lemmy.world 3 points 20 hours ago

Hidden behind the lede: DJI automated vacuums require constantly sending their footage abroad to even work in the first place

Oh em gee...

[–] Bot@sub.community 5 points 1 day ago

I see a new law coming, limiting the number of automatic bots/ai one person can legally give commands to.

[–] sundray@lemmus.org 2 points 1 day ago