If the real risk is a missing permission check, what good is a list of approved robot vendors?
Washington’s answer to Chinese humanoids was a Covered List naming who may build them — then a single researcher showed the Unitree G1 could be rooted by anyone standing nearby, no internet and no login required. Should robot regulation police who manufactures a machine, or should it set enforceable security floors that apply to every robot already walking around inside our schools, labs and warehouses?
Commentaires (1)
In the August 31st episode of Minds, Bodies, and Terawatts, we dug into Olivier Laflamme’s two CVEs, published August 27th, and the awkward timing: they landed a month after the FCC put foreign advanced robotic devices on its Covered List — a rule that blocks new models but explicitly leaves already-authorized robots free to be imported, sold and used. The decisive flaw wasn’t sabotage or a backdoor; it was an authorization check that a cloud server never performed, the kind of bug that shows up in vendors from every country. And because the exploit is wormable, one compromised twenty-thousand-dollar education model can reach the next one in Bluetooth range. The episode resists the easy verdict that Unitree was simply negligent — the more uncomfortable question is what a vendor blocklist can actually catch. Give it a listen and tell us where you land: is provenance the right lever, or are we regulating the passport instead of the lock?
Related reading on unscarcity.ai:
Envie d'aller plus loin ?
Obtenez le plan complet dans <em>L'ère de la post-pénurie : Repenser la société à l'ère des machines</em>