Shark vacuum robots have an unpatched flaw that could let attackers access cameras, WiFi passwords, and home maps, researcher claims.
Researcher Tokay0 says SharkNinja failed to fix the issue more than 90 days after private disclosure.
The flaw involves AWS IoT certificates, with 673,000 exposed SharkNinja devices observed in one AWS region.
Don’t buy IOT devices you can’t control. If it’s not usable via valetudo or is offline capable don’t get it. Tell your friends and family the same. Own your technology, limit your attack surfaces.
If you have an old neato bot, there’s work on hacking those too.
A new fear has been unlocked… Shark Ninjas!
Robot shark ninja zombies controlled by pirates.
Not as bad as land sharks.
What? Oh, wait. My doorbell is ringing.
But… Why does a vacuum cleaner need wifi access?
So you can turn it on and access complex settings like map layouts and scheduling from your phone. Not sure how else you would do it. You can implement wifi securely, in this case they didn’t
You can have local control over such things, and IOT devices should be locked down to only ever access via LAN anyways.
That still needs wifi access though. Internet access is a different story, I can’t think of almost anything that needs internet access. Maybe security camera.
Is it easy to isolate a device to LAN only via router? I never figured out how to do it.
It can be “easy” depending on your definition of easy. For the average person, no, not easy. For a tech person, maybe, depending on their interests and proficiencies. Easiest is likely using a firewall on the router blocking all outbound and inbound WAN connections (for the MAC address associated with the device, assuming it doesn’t try to rotate MAC addresses or hop on any open WiFi networks around you). Some devices will straight refuse to work if you do this, however. So you have to do research and be careful about which products you buy.
If you want a vacuum, see the valetudo link I posted in another comment. It has some options for this that you can load local only custom firmware (and integrate it with home assistant).
Maybe security camera.
That’s the one you want to keep off the Internet the MOST!
Is it easy to isolate a device to LAN only via router?
The easiest thing is to have the InternetOfTrash devices with no configured route; just broadcast and that’s it.
I know people who like being able to see their camera remotely. For example ,if someone is trespassing on their farmland, or business. I don’t use this feature personally, but I can see why people might want it
Eufy has offline models like the G, L, and X series which come with a remote that you can do 100% of that from, no wifi needed.
Does it let you paint a square in your map layout to not mop there? Or split an incorrectly merged room into two? Or select specific rooms to do more often? I’m sure the remote is great for basic use though, but there’s a lot you can’t do with it
When you get to that point, you really need to just hire someone and quit fucking around with shitty wifi enabled products.
Edit: Being less obtuse, if you really need such a niche feature, at least block it from having Internet access and restrict it to your LAN as there is sincerely zero reason that cannot be labelled as laziness for needing Internet access on a home appliance.
It’s a lot cheaper, at least where I live. It’s also way more convenient to just put on the robot vacuum mop thing every few weeks. But you do you man
Not shocked. I bought one four years ago, had a ton of issues. After many attempts they send me a new one with the exact same issues. So I have two and neither one works. I’d rather clean the floors myself than fight it.
Their software is garbage, their hardware is garbage.
Anyway based on that experience, I have no doubt their software is full of exploits and issues.
Not to reduce the impact of this article but it does point out:
Attackers need physical device access first, limiting the risk mainly to technically skilled people with a Shark device.
Would this make them useful to side load your own firmware to them? This “exploit” could make these into a hobbyist’s dream
To get to the certificate with which you THEN can attack devices remotely. I.e. the attacker needs one device. And the skill to extract the certificate and the willingness to abuse it.
One of each and then the 613k devices in the tested region are exposed.
Hopefully this means more Valetudo compatible devices 🤘
My vacuum is staring at me.
It must feed



