<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>DJI on Smart Home? Sure — But Secure!</title>
        <link>https://smarthome-aber-sicher.de/en/tags/dji/</link>
        <description>Recent content in DJI on Smart Home? Sure — But Secure!</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en</language>
        <lastBuildDate>Sun, 01 Mar 2026 00:00:00 +0100</lastBuildDate><atom:link href="https://smarthome-aber-sicher.de/en/tags/dji/index.xml" rel="self" type="application/rss+xml" /><item>
        <title>DJI robot vacuum hacked: 7,000 strangers&#39; living rooms via a master key</title>
        <link>https://smarthome-aber-sicher.de/en/blog/2026/03/01/dji-robot-vacuum-hacked-7000-strangers-living-rooms-via-a-master-key/</link>
        <pubDate>Sun, 01 Mar 2026 00:00:00 +0100</pubDate>
        
        <guid>https://smarthome-aber-sicher.de/en/blog/2026/03/01/dji-robot-vacuum-hacked-7000-strangers-living-rooms-via-a-master-key/</guid>
        <description>&lt;img src="https://smarthome-aber-sicher.de/blog/2026/03/01/dji-saugroboter-gehackt-7000-fremde-wohnzimmer-per-generalschl%C3%BCssel/cover.jpeg" alt="Featured image of post DJI robot vacuum hacked: 7,000 strangers&#39; living rooms via a master key" /&gt;&lt;p&gt;A few days ago a press release turned up in my feed. I skim a lot of them every day – most I just scroll past. Not this one.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DJI. Robot vacuum. 7,000 strangers&amp;rsquo; living rooms. A master key.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I read the article twice. And then I knew immediately: a follow-up video was needed.&lt;/p&gt;
&lt;h2 id=&#34;the-pattern-that-keeps-repeating&#34;&gt;The pattern that keeps repeating
&lt;/h2&gt;&lt;p&gt;If you&amp;rsquo;ve read my &lt;a class=&#34;link&#34; href=&#34;https://smarthome-aber-sicher.de/sas/saugroboter&#34; &gt;robot vacuum article&lt;/a&gt;, you might be nodding right now. Back then it was Ecovacs. Hacked robots remotely controlled in real time, chasing pets and shouting slurs through their speakers. I tried to explain back then why that wasn&amp;rsquo;t an absurd one-off incident, but a structural problem with this entire product category.&lt;/p&gt;
&lt;p&gt;And now it&amp;rsquo;s happened again. Different manufacturer. Same category. Same fundamental vulnerability in principle.&lt;/p&gt;
&lt;p&gt;This bothers me – not because I want to vilify robot vacuums, but because I believe most people who buy one simply don&amp;rsquo;t know what&amp;rsquo;s actually happening with their data. With the &lt;strong&gt;floor plan of their home&lt;/strong&gt;. With &lt;strong&gt;camera footage&lt;/strong&gt;, if the model has one. With the question of who, besides themselves, could theoretically access all of that.&lt;/p&gt;
&lt;h2 id=&#34;what-happened-this-time&#34;&gt;What happened this time
&lt;/h2&gt;&lt;p&gt;It started innocuously. A French developer, a brand-new &lt;strong&gt;DJI robot vacuum&lt;/strong&gt;, a free evening. The idea: control the robot around the apartment with a &lt;strong&gt;PS5 controller&lt;/strong&gt;. Mario Kart in real life, but with dust bunnies.&lt;/p&gt;
&lt;p&gt;To connect the controller, he needed the key from the app – nothing illegal, it was his own device. But when he used that key with the &lt;strong&gt;DJI server&lt;/strong&gt;, the server didn&amp;rsquo;t just download his own data – it downloaded data from thousands of others. &lt;strong&gt;Over 7,000 robots across 24 countries.&lt;/strong&gt; Battery levels, home floor plans, live camera feeds from strangers&amp;rsquo; living rooms. The key wasn&amp;rsquo;t a normal key. It was a &lt;strong&gt;master key for the entire system.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;DJI patched the vulnerability after it was reported. That&amp;rsquo;s good. But it doesn&amp;rsquo;t change the underlying picture.&lt;/p&gt;
&lt;h2 id=&#34;why-i-keep-talking-about-this&#34;&gt;Why I keep talking about this
&lt;/h2&gt;&lt;p&gt;After making this video I naturally asked myself whether I&amp;rsquo;m starting to get repetitive. Robot vacuums again. Privacy again. Same topic again.&lt;/p&gt;
&lt;p&gt;But then I look at the comments under the old video. And I see how many people write that they simply hadn&amp;rsquo;t known how the technology behind it works. Not because they weren&amp;rsquo;t interested. But because hardly anyone explains it without immediately descending into panic or buzzwords.&lt;/p&gt;
&lt;p&gt;That&amp;rsquo;s exactly what I want to do differently. No moralising, no fearmongering. Just: here are the facts. Here&amp;rsquo;s what they mean. And here are three concrete things you can do – if you want to. What you do with a &lt;strong&gt;camera-equipped robot vacuum&lt;/strong&gt; in your home is your decision. I just want that decision to be an informed one.&lt;/p&gt;
&lt;div class=&#34;video-wrapper&#34;&gt;
    &lt;div class=&#34;video-placeholder&#34; onclick=&#34;loadIframe(this)&#34;&gt;
        &lt;img src=&#34;https://smarthome-aber-sicher.de/img/sas_youtube.png&#34; alt=&#34;YouTube Video&#34;&gt;
        &lt;div class=&#34;play-button&#34;&gt;&lt;/div&gt;
        &lt;div class=&#34;privacy-notice&#34;  style=&#34;color: var(--card-text-color-main);&#34;&gt;
            To load the video, please click the image. Please note that by doing so, data will be transmitted to YouTube.
        &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;
&lt;script&gt;
    function loadIframe(element) {
        var iframe = document.createElement(&#39;iframe&#39;);
        iframe.setAttribute(&#39;loading&#39;, &#39;lazy&#39;);
        iframe.setAttribute(&#39;src&#39;, &#39;https://www.youtube-nocookie.com/embed/gQ7-loIWzzY&#39;);
        iframe.setAttribute(&#39;allowfullscreen&#39;, &#39;&#39;);
        iframe.setAttribute(&#39;title&#39;, &#39;YouTube Video&#39;);
        element.parentNode.replaceChild(iframe, element);
    }
&lt;/script&gt;
&lt;style&gt;
    .video-placeholder {
        position: relative;
        cursor: pointer;
    }
    .video-placeholder img {
        width: 100%;
        height: auto;
    }
    .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .video-placeholder:hover .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button_hover.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .privacy-notice {
        position: absolute;
        bottom: 50px;
        width: 100%;
        left: 50%;
        transform: translateX(-50%);
        background-color: rgba(0, 0, 0, 0.7);
        color: white;
        padding: 5px 10px;
        border-radius: 5px;
        font-size: 12px;
        text-align: center;
    }
&lt;/style&gt;

&lt;p&gt;If you already have a view on this – or you have a &lt;strong&gt;robot vacuum&lt;/strong&gt; at home and feel a quiet unease stirring – write it in the comments. I genuinely appreciate every perspective. And yes, every comment helps the video reach more people who are asking themselves exactly these questions for the first time.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;Sources:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.heise.de/news/Sicherheitsluecke-bei-Saugrobotern-Tueftler-erhaelt-Zugriff-auf-tausende-Geraete-11179726.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Heise: Security vulnerability in robot vacuums – developer gains access to thousands of devices&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&#34;link&#34; href=&#34;https://www.golem.de/news/sicherheitsluecke-dji-saugroboter-gab-zugriff-auf-tausende-fremde-geraete-2502-195000.html&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;Golem: Security vulnerability – DJI robot vacuum gave access to thousands of foreign devices&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
        </item>
        
    </channel>
</rss>
