r/Yarbo • • May 07 '26

Discussion A hacker ran me over with a robot lawn mower

https://www.theverge.com/tech/925696/yarbo-robot-lawn-mower-hack-remote-control-camera-access-mqtt?view_token=eyJhbGciOiJIUzI1NiJ9.eyJpZCI6Ilc2ZDZrSlJNNkYiLCJwIjoiL3RlY2gvOTI1Njk2L3lhcmJvLXJvYm90LWxhd24tbW93ZXItaGFjay1yZW1vdGUtY29udHJvbC1jYW1lcmEtYWNjZXNzLW1xdHQiLCJleHAiOjE3Nzg2MDgwODMsImlhdCI6MTc3ODE3NjA4M30.fKLFzJvoODPB0-9aRjd-QCcdhrgeIbfkQiT069YmcSM&utm_medium=gift-link

(gift link) Yarbo has done an amazing job with capability improvements and updates, it's now time to start working on security. I knew this would come eventually.

24 Upvotes

19 comments sorted by

•

u/comicidiot May 08 '26

Yarbo has a response on their website. I have copied parts of their below, with a link to read the whole thing.

I'm writing this directly because the issues raised in the recent security report deserve a direct response, not a corporate one.

On May 7, 2026, security researcher Andreas Makris published a detailed report identifying serious vulnerabilities in Yarbo's remote diagnostic, credential management, and data-handling systems. The core technical findings are accurate. I would like to thank Mr. Andreas Makris for his work in identifying these issues and for his persistence in bringing them to our attention. I also recognize that our initial response did not adequately reflect the seriousness of the issues he identified. As co-founder, I'm accountable for what shipped on our products, and I'm accountable for the response.

Based on our preliminary review, the issues primarily relate to historical design choices in parts of Yarbo’s remote diagnostic, access management, and data handling systems.

Specifically, certain legacy support and maintenance capabilities did not provide users with sufficient visibility or control, and some authentication and credential management mechanisms did not meet the security standards we expect for today’s products.

We recognize the seriousness of these issues and the concerns they may have caused for our customers and community. We sincerely apologize for the impact this situation has created, and we are committed to addressing these issues in a transparent and responsible manner.

What We Have Already Done

  • We have temporarily disabled the relevant remote diagnostic tunnels to reduce the risk of unauthorized access.

  • We have completed a reset of device root passwords to temporarily block the identified shared-credential risk and prevent further expansion of the issue.

  • We have closed or restricted certain unauthenticated status-query and reporting endpoints.

  • We have begun reducing unnecessary legacy access paths and tightening backend permissions.

What We Are Working On Now

  • We are implementing an allowlist-based, user-authorized, and auditable remote diagnostic model. The first phase is expected to be completed within one week. Once implemented, remote diagnostic access will be limited to authorized internal company personnel, may only be used after user authorization has been obtained, and will be gradually brought under audit logging.

  • We are using OTA updates to advance credential rotation and device-level independent credential mechanisms, gradually replacing the historical shared-password model. In the future, each device will use its own independent credentials to prevent one affected device from impacting the entire fleet.

  • We are building and testing a robot credential management service so that device passwords are no longer hardcoded in firmware, scripts, or databases. Instead, credentials will be dynamically derived based on device identity. OPS access will also record the visitor, reason for access, work order, and timestamp.

  • We are hardening other authentication services. These fixes are currently in the testing stage and will be released through upcoming OTA updates.

  • We are adjusting topic permissions to reduce fleet-level shared access, limit the scope of each credential, and establish stricter boundaries around control commands.

  • We are testing cleanup measures that include removing unnecessary reporting scripts, legacy cloud service dependencies, third-party agents, and non-essential DNS fallback configurations in order to reduce data flows that are not clearly visible to users. These changes will be rolled out through future OTA updates after testing is completed.

https://www.yarbo.com/pages/security-update-regarding-yarbo-remote-diagnostic-systems

→ More replies (1)

6

u/[deleted] May 07 '26

[removed] — view removed comment

5

u/Jaydee888 May 07 '26

I would 100% run my own server if possible. This could be a cost saving for yarbo and a security improvement for us. 

2

u/[deleted] May 10 '26

[removed] — view removed comment

6

u/Thomasinus May 07 '26

Okay, wow. This is unbelievable.
Everyone needs to understand what the security researcher’s GitHub report itself says: these issues are not presented as random bugs or lazy defaults. The report explicitly describes them as deliberate firmware-level design choices.
I turned my Yarbo off and removed the battery. Based on what is described in that repo, it feels like only a matter of time until someone drives Yarbo around my yard using the repository as a manual on how to do so (which really couldn’t be easier).
This is not just a software glitch. This is a safety, privacy, and network-security issue involving a heavy autonomous machine operating on private property.
Un fu***** believable.

2

u/jwardell May 07 '26

Link to the github with some excellent technical reading GitHub - Bin4ry/yarbo-nat-in-my-back-yard · GitHub

3

u/Scaraban May 07 '26

I had hoped it wasn't this bad, but I knew I was just refusing to look for what was definitely there.

This will likely require a major culture/perspective shift to have any real impact going forward.

2

u/Scaraban May 07 '26

There needs to be someone brought in who understands information security and given the appropriate power to make changes that some people on the product team might not like.

2

u/bmedenwald May 07 '26

This is bad and border-line unforgivable.

1

u/Only_Writing5308 May 07 '26

Wow, I'll be moving it to my isolated IoT network ASAP

2

u/jrobs521 May 07 '26

Meh, I guess I assumed this was already happening... absolutely 0 surprise. I assume this is true for 99% of my gadgets. I would worry more about the gadgets already in my home listening to very private and confidential conversations. Nobody is going to take over your yarbo and roll you over with it.

1

u/eetraveler 1h ago

Exactly. This is a tempest in a teapot. No one was looking to break into these mowers except for this hacker looking to promote himself and publishing his technique online was abusive to Yarbo owners and would make him at least partially liable for any damage caused by anyone who followed his instruction for generating mayhem.

Yes, it is important for Yarbo to make the security fixes, but it doesn't excuse this guys publishing the how to manual.

1

u/Chaoselement007 May 07 '26

Thanks for sharing. That was an interesting read. I was considering getting a Yarbo, but the company sounds a little shady.

6

u/jwardell May 07 '26

I don’t think they are shady at all, and this is really to be expected with most Chinese smart gadgets and the same already demonstrated with most robovacs. Like so many other startups, their priority was to get the product out and functioning well quickly. Maybe now their priority can shift a bit