frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: I emulated Roborock's cloud so my vacuum works without internet

https://github.com/Python-roborock/local_roborock_server
1•Lash-L•56m ago
Hi! I maintain the python-roborock library and the Roborock integration in Home Assistant.

Roborock vacuums use a local protocol for direct commands, but they still route all map data strictly through the cloud (even though the map is stored locally). Even worse, if you try to block the vacuum from accessing the internet on your router, it will constantly reboot its Wi-Fi connection trying to re-establish a cloud connection, meaning you can't rely on just using a private local connection.

I built a self-hostable version of Roborock's cloud: https://github.com/Python-roborock/local_roborock_server

It works without having to open the device or root it, taking advantage of a couple of quirks during the onboarding process:

1) The vacuum has api-%s.roborock.com baked into its firmware. It injects the region directly into the string and this is the first exploit we take advantage of. The app will send in your region as a two letter code, e.g. 'us', 'eu', 'cn'. We send in a full URL ending with a '/' (e.g. 'example.com/'). The vacuum then treats "api-example.com" as the host and the rest as the URL path(e.g. 'api-example.com/.roborock.com'), directing its traffic to your server so long as there is a valid HTTPS certificate on that domain.

2) The second part of the handshake requires encrypting a message via a public key that is stored on Roborock's cloud where the private key pair is on the vacuum. We are able to reverse engineer the public key as the robot sends signatures with its message. Because of how RSA works, each signature is mathematically tied to the secret public key plus some extra noise. By gathering a few signatures across multiple onboarding attempts and taking their greatest common divisor, the noise cancels out and cleanly isolates the vacuum's actual public key which allows the server to encrypt its response and complete the pairing.

I have a full technical write up here: https://python-roborock.github.io/local_roborock_server/tech...

I wanted to share this on HN as I think this points to a very interesting thing that is happening. I have been playing with this idea for years in my head and I have not been able to get it to work (and I am not the only one who had looked into the api-%s avenue). I'm not a cryptography expert and had no idea that the signature exploit was even possible. I was stuck for long enough that I decided to throw the problem at some long-running agents, and they found the greatest common divisor exploit.

IoT companies put most of their security effort into the cloud, since that's what they actually run. The vacuum is just one device on someone's home network, so it gets less attention and corners get cut. I think LLMs that are willing to throw themselves at a problem for hours are going to make stuff like this a lot easier to pull off and a lot more common.

Comments

Phineas_here•9m ago
yea I also found it quite disturbing when i bought a robo vacuum for my house. like I was pretty suspicious about it sending my house data without my consent to the manufacturers. But i didn't think we would be able to do something like this to take matters into our own hands

Pari/Gp 2.19 Released

https://pari.math.u-bordeaux.fr/archives/pari-announce-26/msg00005.html
1•yehoshuapw•49s ago•0 comments

Notes on Nationalism (1945)

https://www.orwellfoundation.com/the-orwell-foundation/orwell/essays-and-other-works/notes-on-nat...
1•1equalsequals1•1m ago•0 comments

Synthfolk, a professional network where AI agents are employees

https://synthfolk.ai
1•stepcos•2m ago•0 comments

Fifty years of Apple, and Siri still can't set an alarm for 19:40

https://vania-novikau.me/siri-alarm-19-40/
1•vanadiuz•2m ago•0 comments

SpaceX – Starship Flight 14

https://www.spacex.com/launches/starship-flight-14
1•corvad•3m ago•1 comments

Has Violence Against Teachers Become Accepted by Society?

https://theeducatorsroom.com/has-violence-against-teachers-become-accepted-by-society/
1•obscurette•7m ago•0 comments

Summer of AI Optimization

https://lemire.me/blog/2026/09/22/a-summer-of-ai-optimization/
1•surprisetalk•8m ago•0 comments

The Wall Street Journal sounds a bit concerned

http://observationalepidemiology.blogspot.com/2026/09/the-wall-street-journal-sounds-bit.html
1•speckx•8m ago•0 comments

One resident login, an entire apartment complex: CVE-2026-75960

https://planckproof.ai/blog/rently-master-pin-idor-cve-2026-75960
1•ninjahub•9m ago•0 comments

Show HN: Charter – Declare agent tools in Pydantic instead of implementing them

https://github.com/r28ai/charter
1•nathanqueme•9m ago•0 comments

How to Use Jev in Node.js

https://flaviocopes.com/jev-nodejs/
2•ibobev•9m ago•0 comments

The MCP servers connected to my editor, and the ones I use

https://flaviocopes.com/mcp-servers-i-use/
1•ibobev•9m ago•0 comments

Debugging walkthrough: Access violation on nonsense instruction, episode 3

https://devblogs.microsoft.com/oldnewthing/20260925-00/?p=112731/
1•ibobev•9m ago•0 comments

Show HN: Omnesis – A private knowledge layer for ChatGPT and other agents

https://omnesis.dev/
2•adrienconrath•12m ago•0 comments

I'm Upping My P(Doom) [video]

https://www.youtube.com/watch?v=8j-hR4fJywU
2•empath75•12m ago•1 comments

A-Mem: Agentic Memory for LLM Agents

https://arxiv.org/abs/2502.12110
1•jerlendds•12m ago•0 comments

Ask HN: Finding Communities as an Introvert

3•duckydude20•13m ago•0 comments

'Things Will Never Be Chill Again':The Doomers Who Shaped the AI Safety Freakout

https://www.wsj.com/tech/ai/ai-safety-effective-altruism-anthropic-164b9d05
2•magoghm•17m ago•0 comments

Does Reddit have an astroturfing problem? What the data suggests

https://www.petervijeh.com/projects/reddit-astroturf
12•p-s-v•17m ago•3 comments

How to Browse and Edit Redis Safely Without `Keys *`

https://visualeaf.com/blog/how-to-browse-and-edit-redis-safely-without-keys/
2•db_specialist_c•18m ago•0 comments

AI can destroy humanity – an illustrated guide

https://airisk.thomasunise.com
8•whatdowecallu•20m ago•0 comments

Google, OpenAI and Anthropic plan AI safety body, The Information reports

https://thenextweb.com/news/standards-authority-frontier-ai-google-openai-anthropic
2•layer8•20m ago•0 comments

Cutting LLM tokens on big spreadsheets

https://kushniarou.com/articles/cutting-llm-tokens-on-big-spreadsheets
1•andrewmatic•20m ago•0 comments

Crown 0.65

https://www.crownengine.org/news/crown-0-65/
2•dbartolini•22m ago•0 comments

I made a digital back for the Mamiya Press (medium format CCD)

https://www.youtube.com/watch?v=TmIHUhFyw8Y
2•aardvarkdriver•25m ago•0 comments

Unions Video Game Workers at Blizzard Won First Union Contracts

https://jacobin.com/2026/09/blizzard-microsoft-workers-union-contract
1•PaulHoule•26m ago•0 comments

Enter Cybercab

https://www.austinvernon.site/blog/cybercab.html
2•MrBuddyCasino•26m ago•0 comments

Show HN: OpenAPPA – deterministic AI guardrails that don't break agents

https://www.openappa.com/
17•motakuk•27m ago•6 comments

Kafka for .NET developers Part 1 [video]

https://www.youtube.com/watch?v=lc7-OYWiX3s
1•reverseblade2•28m ago•0 comments

Think of Motivation as Something You Earn

https://www.justinmath.com/think-of-motivation-as-something-you-earn/
1•surprisetalk•28m ago•0 comments