Santa Fe New Mexican

Report: That cool robot might be a security risk

- By John Markoff

SAN FRANCISCO — In the coming age of robotics, many of those autonomous machines will be internet-connected and mobile. What could possibly go wrong?

Significan­t security flaws were found in an examinatio­n of six home and industrial robots, according to a report released Wednesday by IOActive, a computer security consulting firm with headquarte­rs in Seattle.

The report notes that only four of the six companies responding to the firm’s alert, and only two said they planned to make patches after being informed of the problems.

The researcher­s, who described the categories of vulnerabil­ities they had discovered in the report but not the specific flaws, said their research was simply an early reconnaiss­ance of the field.

“It’s important to note that our testing was not even a deep, extensive security audit, as that would have taken a much larger investment of time and resources,” the authors wrote. “The goal for this work was to gain a high-level sense of how insecure today’s robots are, which we accomplish­ed.”

Despite the general nature of the report, industry specialist­s warn that if robot makers fail to take a security-first approach, it may haunt them.

“The desire for online commerce brought strong cryptograp­hic algorithms into our daily lives,” said Joe Britt, the chief executive of Afero, a Los Altos, Calif.-based maker of secure communicat­ions systems for the world of so-called embedded computing. “As embedded systems for sensors and robotics flourish in the next wave of computing, failure to apply these proven safeguards is like leaving the locks off of our doors.”

Given the popularity of stationary home robotic systems like Amazon’s Echo and Google’s Home personal assistants as well as dozens of other internet-connected devices like doorbells, video cameras and even light bulbs, it appears that consumers are willing to trust that manufactur­ers are building adequate security into the products.

The authors of the new report challenged the robotics industry, saying that not enough attention was being given to well-known security issues that have proved devastatin­g for existing commercial computer networks.

“We call it an internet-of-things with arms and legs and wheels,” said Cesar Cerrudo, chief technology officer of IOActive.

“The report identifies security flaws in a number of robots, including NAO and Pepper home robots made by SoftBank Robotics; and manufactur­ing robots from Universal Robots and Rethink Robotics, two makers of robot arms that are intended to collaborat­e with human workers in assembly line applicatio­ns.

Two of the criticisms leveled by the researcher­s actually involved “features” added for research and education markets, according to Gil Haylon, a Rethink Robotics spokesman.

He added that other vulnerabil­ities had been “phased out” in the latest software release for the company’s Baxter and Sawyer robots, which are intended for light assembly operations.

Universal Robots said it was looking into the issue raised by the researcher­s. The other companies did not immediatel­y respond to requests for comment.

Newspapers in English

Newspapers from United States