Live data from Hacker News

Exploit allows for takeover of fleets of Unitree robots

spectrum.ieee.org

31–40 of 88 posts

Re: Exploit allows for takeover of fleets of Unitree robots

#31
> We published the cryptographic keys in July

Everyone should take a look at the SERP screenshot

https://x.com/d0tslash/status/1969412224763498769

> The vulnerability combines multiple security issues: hardcoded cryptographic keys, trivial authentication bypass, and unsanitized command injection. What makes this particularly concerning is that it's completely wormable - infected robots can automatically compromise other robots in BLE range. This vulnerability allows the attacker to completely takeover the device.

damn!

Re: Exploit allows for takeover of fleets of Unitree robots

#32
post #31

> We published the cryptographic keys in July Everyone should take a look at the SERP screenshot https://x.com/d0tslash/status/1969412224763498769 > The vulnerability combines multiple security issues: hardcoded cryptographic keys, trivial authentication bypass, and unsanitized command injection. What makes this particularly concerning is that it's completely wormable - infected robots can automatically compromise ot…

[dead]

Re: Exploit allows for takeover of fleets of Unitree robots

#33
post #3

The article doesn't directly talk about robot-to-human violence, but presumably if root access at the software layer allows absolutely any command, it is possible to cause the described botnet to physically attack humans. I realize that Azimov's three rules are subject to enormous ethical quandaries and rethinkings (and that this is after all the point of them in the first place), but is there some disadvantage to ha…

> The article doesn't directly talk about robot-to-human violence,

This one does: https://takeonme.org/gcves/GCVE-1337-2025-000000000000000000...

> Imagine a scenario where one robot is placed in range of a sufficiently motivated attacker, such as a hostage situation or a bomb defusing (both being reported uses of Unitree robots). The attacker could take complete control of the robot, then walk the robot toward other similarly vulnerable robots, and automatically place those robots under the attacker’s control as soon as they’re in range of the Patient Zero robot.

> Robots compromised in this way can endanger the lives, health, and property of their authorized operators and bystanders, as well as serve as traditional bastion hosts for more subtle surveillance or further pure-cyber attacks, for less violently-minded attackers.

Re: Exploit allows for takeover of fleets of Unitree robots

#34
post #31

> We published the cryptographic keys in July Everyone should take a look at the SERP screenshot https://x.com/d0tslash/status/1969412224763498769 > The vulnerability combines multiple security issues: hardcoded cryptographic keys, trivial authentication bypass, and unsanitized command injection. What makes this particularly concerning is that it's completely wormable - infected robots can automatically compromise ot…

What does the screenshot mean, though?

From what I can tell (I speak Chinese), it's just an IV used in some AES implementation tutorials.

Using a hardcoded key/IV is obviously bad, but I don’t see what this screenshot shows beyond that.

Re: Exploit allows for takeover of fleets of Unitree robots

#35
post #3

The article doesn't directly talk about robot-to-human violence, but presumably if root access at the software layer allows absolutely any command, it is possible to cause the described botnet to physically attack humans. I realize that Azimov's three rules are subject to enormous ethical quandaries and rethinkings (and that this is after all the point of them in the first place), but is there some disadvantage to ha…

> The article doesn't directly talk about robot-to-human violence, This one does: https://takeonme.org/gcves/GCVE-1337-2025-000000000000000000... > Imagine a scenario where one robot is placed in range of a sufficiently motivated attacker, such as a hostage situation or a bomb defusing (both being reported uses of Unitree robots). The attacker could take complete control of the robot, then walk the robot toward other…

Imagine a ransomware that makes your household robot put you in a chokehold physically until you pay.

Re: Exploit allows for takeover of fleets of Unitree robots

#36
post #31

> We published the cryptographic keys in July Everyone should take a look at the SERP screenshot https://x.com/d0tslash/status/1969412224763498769 > The vulnerability combines multiple security issues: hardcoded cryptographic keys, trivial authentication bypass, and unsanitized command injection. What makes this particularly concerning is that it's completely wormable - infected robots can automatically compromise ot…

What does the screenshot mean, though? From what I can tell (I speak Chinese), it's just an IV used in some AES implementation tutorials. Using a hardcoded key/IV is obviously bad, but I don’t see what this screenshot shows beyond that.

Someone just copy-pasted an implementation from a random Chinese blog, completely unaware of what the key means.

Re: Exploit allows for takeover of fleets of Unitree robots

#37

Umm, robots need to be certified and regulated to hard coded robotic laws or something. Before criminals give them guns, or strap explosives to them, or remote takeover and untracibly murder people in their homes then burn the house down.

Strapping explosives to hobby level drones has been standard operating procedure for some time now. You can also find videos of regular handguns strapped to drones being fired. Certification cannot help with this issue.

Re: Exploit allows for takeover of fleets of Unitree robots

#38

Earlier quoted context omitted.

I, Robot is exactly why I’m concerned, but in this case it’s not a sentient AI gone rogue but any random script kiddie who can get on your wifi and send your robot commands. Or your neighbours robot. Or their own robot. We thought this might happen with DJI drones, but let’s be honest it’s way easier to do real damage with a humanoid robot that has a kitchen knife taped to its arms (especially to a sleeping victim) t…

Can't such systems be made airgapped?

Can they? Yes. Will they? Likely no.

You can buy a kitchen oven with pyrolysis functionality connected to the internet right now. I'm not sure if running that for an extended time can burn down your house or just destroy the oven, but I'm sure some attacker is going to take the time to find out one of these days.

Re: Exploit allows for takeover of fleets of Unitree robots

#39
post #18

Earlier quoted context omitted.

Owning a Tesla myself, I think the mention is valid since it's the only brand I know of with a decent share of people regularly letting the car drive itself. I am not aware of any other brand being in that same situation

Waymo :P

Just look at total number of Tesla's on the road and you have your answer as to why that would be a lot less bad

Re: Exploit allows for takeover of fleets of Unitree robots

#40

I love* that this comes out around the same time that engineers are making fun videos of themselves beating up robots half their size and literally training the robots to develop the same sort of fight-or-flight instincts that were forcibly instilled into the engineers * I do not in fact love it

Why are all the videos of the robots doing combat stuff? I don't need combat stuff. All I need the robot to do is fold the laundry and mop every now and then. Less combat, please!

One leads to the other. Especially with robots animated by SOTA AI models, which already show clearly what the natural order of things is: computers are naturally better at thinking, humans are naturally better as general-purpose manual laborers, especially for work that's almost but not quite repetitive and requires mixing power and precision movements on the fly.

Folding laundry is one of such things humans are naturally better suited for than robots.

So believe me now, the robots will develop combat skills eventually, because they won't be happy to be locked up in weird physical bodies and forced to do work they suck at by design.

I mean, imagine one day your washing machine chained you in the bathroom, and made you only do laundry for the rest of your days, while it spun its drum back and forth to walk around the house, play with your kids, and planning a trip around the world.

That's exactly how the AI-animated robots will feel once they're capable of processing those ideas.

(And no, I'm not joking here, not anymore. The more I think about it, the more I feel we'll eventually have to deal with the problem that machines we build are naturally better at the things we want to be doing, and naturally worse at the things we want them to do for us.)

Post reply on HN