'Security'...
Sure, sure... All that stuff has good sec...oops...
Sammy Azdoufal used Claude Code to build an app to link his brand-new DJI Romo vacuum to a PS5 controller. Then he noticed something strange. The app wasn’t just controlling his vacuum. It was controlling thousands.
By accident, Azdoufal had taken control of roughly 7,000 DJI robot vacuums around the world, each responding to code he’d intended to use only for his own device. “I found my device was just one in an ocean of devices,” he told The Verge.
He hadn’t hacked DJI’s servers, he said. Instead, he extracted his own Romo’s private token—a key meant to prove you’re allowed to access your own machine—but DJI’s servers returned the data of thousands of other customers as well. “I didn’t infringe any rules. I didn’t bypass, I didn’t crack, brute force, whatever,” he said.
Full article HERE from Inc.com
Once again, we see a manufacturer that ‘thought’ they had things covered...
But they didn’t. Simply put, security is almost always the LAST thing companies think about, other than as a PITA, because it makes the engineers, CSRs, and techs have to work harder to actually DO anything to the particular product.
We’ve seen vehicles hacked to the point that they controlled braking, engines, etc. So called ‘secure’ systems have turned out to not be secure at all, and we all know hackers are out there everyday, including Chinese schools and who knows whom else that are hitting military systems, universities, networks, infrastructure, phones, individual computers, and pretty much anything connected to the web 24/7/365.
And this doesn’t even account for the ‘simple’ phishing attempts that go on daily by the middle easterners, or Nigerian ‘princes’...
Those who’ve fallen for the ‘smart home’ schtick are just begging to get all of their data taken. When everything in your house is connected, everything you do is available/sold to third parties by those manufacturers.
Your fridge reports what you buy/eat/how often you open the door? That’s sold to advertisers. Your fridge door isn’t opened for a day or two? Criminals rob your house. That smart thermostat? Well, you don’t actually control your house temps, the electric company does. Too much draw? They turn the temp up or down as required...
That smart electric meter? Criminals monitor those for usage drops, so they know the homeowners/renters are gone, and they home is ‘available’ for robbery.
And the list goes on and on...
No, I don’t have any ‘smart’ devices in my home, nor any ‘subscriptions’ in my vehicle either. And I don’t plan on ever having any! I’ve done everything I can to sequester my router and limited wireless access to it with the recommendations provided by Borepatch at his blog, HERE.
Yes, I’m old, yes, I’m grumpy... YMMV and all that stuff...


I'm trying to better understand what I can and cannot "secure". If I can't secure the information, I try to obfuscate any pattern I am able to with "chaff". Randomizing actions has a better chance of ensuring I don't get noticed, and if I do get noticed I control what they "see". The more useless information I present, the more they have to sift through, and the higher the likelihood they will move on to an easier target.
My primary domain has been on the internet since the very early 90's (I actually don't recall what year I registered it). So it's ancient.
Because of that we get thousands of hack attempts each day. There have been days where we were getting thousands of attacks per hour.
In the old days I'd call up the college or school, that was trying to hack us, and make legal threats. Or I'd backhack them if they weren't in the US.
But after a while that was just too much work. So we made a bunch of honeypots to mess with people. That was fun, but after a while. Too much work.
Now we have a pretty involved system and a lot of regional domains, countries, and IP blocks that aren't even allowed to connect. I've written scripts that will automagically add ip's and domains to blocking lists if there are too many failures to log in, or if people try to connect to accounts that are normally hacking avenues on most systems.
My server, my domain, has never been hacked. It's been online, almost continually for 30 years. Not that many people can make that claim.
The sad part is, security IS NOT THAT HARD. But too many people are idiots and don't understand it. It's like the whole 'two-factor' crap that's being pushed. The ENTIRE reason for 'Two-Factor' where they use your phone or an email address, is TO MAKE HACKING YOU EASIER.
That's its purpose. It is a security loophole and nightmare that exists solely to allow people to get past a strong password. Passwords (strong ones) ARE NOT HACKABLE! Phones, emails (which are transmitted in the clear) ARE.
Drives me nuts. Along with the people who don't understand how 'Two-Factor' was meant to work and say incredibly stupid things.