📱

Get Our Mobile App

Take your business learning on the go!

Download on the App StoreGet it on Google Play

This isn't the future I want

ThePrimeTime11:11

Transcription

There's something about robots that just currently make me feel uncomfortable. Okay, the clankers, I just don't like the experience of it, cuz I just always feel like something's going to go wrong.

Right. Because you would assume, right, you would assume that the people making the robots have taken the highest precautions in ensuring that these robots can't be hacked. But it turns out, no, that's actually not the case. It's just massive incompetency, and it's going to end with us all being destroyed by robots. Skynet is real, and it comes in the form of a Bluetooth exploit. I cannot believe this.

This is the Unitree robot. You can purchase one of these for the low price of $67,900, in which this robot can be easily exploited. So, let's take a look at the exploitation, and then furthermore, let's take a little bit of a look at how the company's responding to this, because the response is so absurd that it's difficult to tell the difference between ignorance and malice in this case. Okay, it's actually, it's that ridiculous. Okay. All right.

So, first off, the exploit. A critical vulnerability in the Bluetooth Low Energy BLE Wi-Fi configuration interface used by several different Unitree robots can result in root-level takeover by an attacker. That's right. Bluetooth. Now, you're going to, you're going to get root-level access through Bluetooth. This just feels so bad. And it's just crazy that just misconfiguring it. It's not even really misconfiguring, honestly. This, this is actually underelling what is going on here. But the fact that Bluetooth alone can make it so that you can just completely destroy a robot is wild. But that's, that's like the smallest part of the, "Oh my gosh, that can't be real" cake that we are on right now. Okay, that's just layer one. We've got like two to three more layers to go.

Because the vulnerability is wireless, and the resulting access to the affected platform is complete, the vulnerability becomes wormable, say researchers. Meaning an infected robot can simply scan for other Unitree robots in BLE range and automatically compromise them, creating a robot botnet that spreads without user intervention. We, like, they've literally invented robot co. You actually have to socially distance your robots in the future. That's what's going to end up happening. It's just like, "Dude, you got to stay out. Hey, stay out of BLE range. Okay, I see that other robot. I don't know if you, I don't know if you got that computer virus." It's literally, it's like an actual virus for computers, this this wormable thing that's in physical range. It's the first physical range wormable virus. Oh my gosh, this is so, it just doesn't even feel real. But again, that's just layer two of this ridiculous cake. Okay, we have, we, we're not even to the midpoint yet.

Now, you're probably thinking that the exploit itself is a very complicated or sophisticated attack using some like, really advanced methodology. Well, you would be 100% wrong, because here we go. Get ready for the mid-layer. All right. The BLE packets that the robots accept are encrypted, but those encryption keys are hard-coded and were published on X by Macris in July. Okay, so first off, the fact that you have hard-coded keys that are just one for each robot. I get that that could happen, but it's the same key for every robot. That means, like, think about this for a second. That means if you figure out this magical key, which by the way, is literally published on Twitter, that means you can just, any robot, you can just simply break into. If you are a robot next to it, you already know the passkey. You already know how to make encryptable packets. And that also means you can replay any packet easily. You can just one robot, and you just can get all, you can just literally get them all.

Although the robot does validate the contents of the BLE packets to make sure that the user is authenticated, the researchers say that all it takes to become an authenticated user is to encrypt the string "unit" with the hard-coded keys, and the robot will let somebody in. That's right. It is $19.99, and your WordPress app is calling because "admin admin," we are so back. All right. Can you believe that the actual password is just "Unitree" encoded with the encryption keys that are public on Twitter, and it's the same for every single robot? It's the master password. This is almost as bad as that time that PayPal almost lost their codebase, and the only thing that saved them was someone made their password "ass." It's like, it's that, it's just that ridiculous. Like, how did this ever go out? How did anybody say, "Hey, you know what? Yeah, this is okay. You can have that. You know what? Super passcode. It's 'Unitree.' No one's ever going to be able to hack our hashes." The level of incompetency, it just, it, how does it reach this level? How are you able to produce a robot, which I would argue is an exceptionally hard task, that has to involve many smart people to make a machine walk upright, and yet, you pretty much just "admin." Okay, what is this? "Hunter 2" is your password. "Hunter 2." If you just, it just automatically shows up with asterisks. If you just actually leak it out, like, this is so bad.

I bet some of you right now are probably a little peeved, okay? Feeling a little hot, a little, you know, just, just pretty upset that somebody would actually tweet the private keys just right out on Twitter, like, or sorry, X, formerly known as Twitter, formerly known as Twitter, the Everything Application. Yes, I'm sure some of you are pretty upset about that. I hear you. But you may not know this. The people who figured that out, they first attempted to do responsible disclosure, and Unitree just stopped talking to them. Just wouldn't talk to them at all. Just said, "Hey, I don't want to, well, you know, we're not, we're not speaking about this any further." And so, of course, at that point, they just let it all fly in the public, including the keys, and been like, "Hey, guess what, everybody? Hey, that's your problem now, not our problem."

And the person that tweeted the keys says this statement. I think it's just so amazing, the statement, which goes like this: "So, we need to ask ourselves, are they introducing vulnerabilities like this on purpose, or is it sloppy development? Both answers are equally bad." It really is. Like, can somebody be that bad at development while also being able to make a robot, arguably exceptionally difficult? Or are they just intentionally just having backdoors that can be played into at any point? I actually don't even know.

And the reason why this feels fairly malicious is this part right here: that the Unitree robots include undisclosed streaming of telemetry data to servers in China, which could potentially include audio, video, and spatial data. Like, just data is going to China. There's no explanation. Just some hard-coded IPs being like, "Hey, these are going to be sent off." And, uh, that's just how it's going to be. That's my data now.

All right. So, let's, let's get to the, like, the final layer of this experience, because honestly, at this point, like, there's half of me that's dying and half of me that's having the best time of my lifetime, cuz this is so funny. But this is also just like, "Dude, I don't want robots to be real." Like, I know what goes on behind closed doors when it comes to development, and let's just face it, it's not good. Pressures from work to get things out. It is awful all the time. I mean, look at Apple CarPlay Ultra. It was one of the biggest disasters in the universe, and this is apparently from the greatest company to design user interfaces ever, and they could not execute. You just don't, like, think about how bad it's going to be.

But now, the final portion of this whole like saga comes down to how they responded. First off, Unitree posted a statement on LinkedIn addressing the security concerns. "We have become aware that some users have discovered security vulnerabilities and network-related issues while using our robots." Oh, okay. So it's just like some network-related issues, like, okay, so it's not like something terrible, such as root-level access with absolutely no effort, right? It's not, it's not like spreadable, it's not like, like a human virus that's contagious, right? Nothing that bad. It's not like they could gain access to the robot and then, as part of the boot sequence, not allow updates to come in and permanently disable your robot, right? Like, that's not like a part of this, correct? Oh, no. Oh, it is.

"We immediately began addressing these concerns and have now completed the majority of the fixes. These updates will be rolled out to you in the near future." The majority of fixes. The majority? That means 51%? Does that mean 55%? Does that mean 75%? Like, I don't want a majority fix. I hate to break it to you, but fixing most of it doesn't count. You, you have to fix all of it. Every last little bit of it, because fixing most of it, that's a zero. That's 0%. It's either fixed or it's not. It's not halfway fixed. That is such a crazy statement to make, especially after in July. Remember, this statement was released on September 29th on LinkedIn, and they were informed of this with good disclosure in early July, and potentially earlier than that. And they were unable to even get to this point of "mostly fixed." And it will be out at some point in the future. It's not even, it's going out now. It's, "Hey, it will be going out some other time later, and it'll be mostly fixed." Hey, we got your back. We're a good company. Okay, so just buy our robots. Put our robots in your house next to your children. You should do that. Oh, you know, it's not like they're going to be mistakes. It's not like it's going to accidentally confuse, you know, anything and accidentally step on a squishy human. Just like, "Dude, robots."

I, I get the thing, though. Like, I, I get it. Like, I want a robot that folds my laundry. I think most people do. I don't want to do laundry. Okay, I don't. But there's just no universe that exists that version, like, one through 20, I want in my house. In fact, I'm not even convinced in my lifetime it's going to be that secure. It's like, do you really want something that can be controlled even near you that's like mobile and can punch you? Like, no. No, I don't want this.

Anyways, there's actually a ton more that's inside this article. It is just, I don't even want to go over it all. It's just disheartening. Also, if you haven't seen, we did a stand-up episode with Casey Miratori, TrashDev, and TJ talking about this. This is just so funny to me. I, I just love this. So, hey, check that out.

Also, press like, man. Just do it. I don't know why. Why do I have to tell you to press like? Why do I get like 10 times a like when I tell you to do that? It's crazy. Also, subscribe. We are almost to a million. When I get a million, that means I'm programming React live on stream. Okay, you got me. I'm going to become a soy dev. I'm going to get on Vercel. I'm going to drink my soy latte. I'll be programming in TypeScript. Maybe I'll wear a button-up. We're going to do it, okay? We're going to fully commit to it. But you got to get me there before the end of this year. The name is The Primogen.