Robots in homes, offices can be hacked: Study

Robots in homes, offices can be hacked: Study

Cybersecurity experts said the robot vulnerabilities were alarming

Story highlights

"Our research shows proof that even non-military robots could be weaponized to cause harm," Lucas Apa said in an interview

Researchers who warned half a dozenrobotmanufacturers in January about nearly 50 vulnerabilities in their home, business and industrialrobots, say only a few of the problems have been addressed.

The researchers, Cesar Cerrudo and Lucas Apa of cybersecurity firm IOActive, said the vulnerabilities would allow hackers to spy on users, disable safety features and makerobots lurch and move violently, putting users and bystanders in danger.

While they say there are no signs that hackers have exploited the vulnerabilities, they say the fact that therobots were hacked so easily and the manufacturers' lack of response raise questions about allowingrobots in homes, offices and factories.

Add WION as a Preferred Source

"Our research shows proof that even non-militaryrobots could be weaponized to cause harm," Apa said in an interview.

"Theserobots don't use bullets or explosives, but microphones, cameras, arms and legs. The difference is that they will be soon around us and we need to secure them now before it's too late."

Some of therobotmanufacturers defended themselves, saying they had fixed some or all of the issues raised.

Apa's comments come in the wake of a letter signed by more than 100 leadingrobotic experts urging the United Nations to ban the development of killer militaryrobots, or autonomous weapons.

Apa, a senior security consultant, said that of the six manufacturers contacted, only one, RethinkRobotics, said some of the problems had been fixed. He said he had not been able to confirm that as his team does not have access to that particularrobot.

A spokesman for RethinkRobotics, which makes the Baxter and Sawyer assembly-linerobots, said all but two issues - in the education and research versions of itsrobots - had been fixed.

Apa said a review of updates from the other five manufacturers - UniversalRobots of Denmark, SoftBankRobotics and Asratec Corp of Japan, Ubtech of China, andRobotis Inc of South Korea - led him to believe none of the issues he had raised had been fixed.

Asratec said that software released for itsrobots so far was limited to "hobby use sample programs", and it believed IOActive was pointing to security vulnerabilities in those. Software it planned to release for commercial use would be different, it said.

SoftBankRobotics said it had already identified the vulnerabilities and fixed them. Ubtech said it had "fully addressed any concerns raised by IoActive that do not limit our developers from programming" theirrobots.

UniversalRobots did not respond to emailed requests for comment.Robotis Inc declined to comment.

The slow reaction by therobotindustry was not surprising, said Joshua Ziering, founder of Kittyhawk.io, a commercial drone software company. "A new technology bursts on to the market and people fail to secure it," he said.

Cybersecurity experts said therobotvulnerabilities were alarming, and cyber criminals could use them to disrupt factories by ransomware attacks, or withrobots slowed down or forced to embed flaws in the products they are programmed to build.

"The potential impact to companies, and even countries, could be massive," said Nathan Wenzler, chief security strategist at AsTech, a San Francisco-based security consulting company, "should an attacker exploit the vulnerability within the applications that control theserobots."

Even in the home, danger lurks, said Apa, demonstrating how a 17-inch (43.18 cm) tall Alpha 2robotfrom Ubtech could be programmed to violently jab a screwdriver.

"Maybe it's small and it's not really going to hurt right now, but the trend is that therobots are going to be more powerful," he said. "We tested industrial ones which are really heavy and powerful, and some of the attacks work with them."

Apa and Cerrudo released their initial findings in January.

This week, they released details about the specific vulnerabilities they found, including one case where they mix several of those vulnerabilities together to hijack a UniversalRobotfactoryrobot, making it lurch about and be a potential threat.