Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Trending Now
No injuries but Hibernia oil spill posed threat of deadly blast and fire: regulator

No injuries but Hibernia oil spill posed threat of deadly blast and fire: regulator

MAPPA’s next big hit looks simultaneously adorable and unhinged

MAPPA’s next big hit looks simultaneously adorable and unhinged

Fans Are Losing It Over Jason Kelce's Throwback Photos and They're All Saying the Same Thing

28th Jun: Bitch and Rich (2023), 10 Episodes [TV-MA] (6/10)

28th Jun: Bitch and Rich (2023), 10 Episodes [TV-MA] (6/10)

China claims the world’s fastest supercomputer

China claims the world’s fastest supercomputer

Poilievre asks Parliament to probe B.C. ‘condo bailout’ blocking ‘a price correction’

Poilievre asks Parliament to probe B.C. ‘condo bailout’ blocking ‘a price correction’

Supergirl flops at the box office with  million opening on par with Joker 2

Supergirl flops at the box office with $38 million opening on par with Joker 2

Facebook X (Twitter) Instagram
  • Privacy
  • Terms
  • Advertise
  • Contact us
Facebook X (Twitter) Instagram Pinterest Vimeo
Canadian ReviewsCanadian Reviews
  • What’s On
  • Reviews
  • Digital World
  • Lifestyle
  • Travel
  • Trending
  • Web Stories
Newsletter
Canadian ReviewsCanadian Reviews
You are at:Home » Here is Yarbo’s promise to fix the robot mower that ran me over
Here is Yarbo’s promise to fix the robot mower that ran me over
Digital World

Here is Yarbo’s promise to fix the robot mower that ran me over

8 May 20265 Mins Read

I’m writing this directly because the issues raised in the recent security report deserve a direct response, not a corporate one.

On May 7, 2026, security researcher Andreas Makris published a detailed report identifying serious vulnerabilities in Yarbo’s remote diagnostic, credential management, and data-handling systems. The core technical findings are accurate. I would like to thank Mr. Andreas Makris for his work in identifying these issues and for his persistence in bringing them to our attention. I also recognize that our initial response did not adequately reflect the seriousness of the issues he identified. As co-founder, I’m accountable for what shipped on our products, and I’m accountable for the response.

Our engineering, product, legal, and customer support teams are working on remediation as the highest priority. What follows is my account of what was found, what we’ve already fixed, what we’re actively fixing, and what we’re committing to change in how we operate going forward.

Based on our preliminary review, the issues primarily relate to historical design choices in parts of Yarbo’s remote diagnostic, access management, and data handling systems.

Specifically, certain legacy support and maintenance capabilities did not provide users with sufficient visibility or control, and some authentication and credential management mechanisms did not meet the security standards we expect for today’s products.

We have also identified areas where access permissions, backend system configurations, and data flows between devices and cloud services require stronger protections and stricter controls.

We recognize the seriousness of these issues and the concerns they may have caused for our customers and community. We sincerely apologize for the impact this situation has created, and we are committed to addressing these issues in a transparent and responsible manner.

We are strengthening system security by reducing legacy access paths, tightening permissions, and moving toward fully auditable device-level credentials. To make our remediation progress clear, we are separating the actions already taken from the work that is currently in progress.

What We Have Already Done

What We Are Working On Now

Historical servers and legacy access channels will continue to be phased out one by one as part of this remediation process.

We are also accelerating OTA security updates and additional server-side protections. The first wave of updates is expected to begin rolling out within one week. Important: A security firmware update is being pushed to all Yarbo devices. To receive this update, please connect your Yarbo to the internet. Once the update has been applied, you may return to your preferred network settings. If you prefer to keep your device offline in the meantime, you may do so without affecting your warranty or service coverage. We will notify you when the update is ready so you can connect briefly to apply it.

This remediation effort is not limited to a single fix or software update. We are using this process to strengthen the long-term security architecture and governance standards behind our products.

These efforts include strengthening access control standards, improving authentication and authorization models, increasing user visibility and control over remote diagnostic features, and further reducing unnecessary legacy support mechanisms across related systems and infrastructure.

We will also continue expanding our internal security review, remediation, and governance processes to support stronger long-term security practices going forward. Our goal is to ensure that security, transparency, and user trust are built into the foundation of future Yarbo systems and services.

Some items in the external report describe real security issues, while others require clarification because they do not apply to currently shipped Yarbo products or do not represent independent security vulnerabilities.

FRP Auto-Restart and Persistence

The report also mentions that the FRP client may restart through scheduled tasks or service recovery mechanisms. We acknowledge that this can make manual disabling of remote access channels more difficult, but the core issue lies in the existence, permissions, and policy of the remote tunnel itself. Our remediation focuses on disabling or restricting tunnels, introducing allowlisting and auditability, and removing unnecessary persistent remote access paths.

File Monitoring and Self-Recovery

The report mentions file monitoring behavior that can restore certain deleted files or services. This mechanism was originally designed as a defensive reliability measure to prevent critical service files from being accidentally deleted or corrupted. By itself, it was not intended to function as a remote access feature.

That said, we recognize that any mechanism making remote-access-related components difficult for users to remove can create trust concerns. We are reviewing which files should continue to be protected and which components should be removed, simplified, or placed under user control.

Historical or Non-Production Configurations

Some findings involve historical infrastructure, legacy cloud services, dealer-specific customizations, or internal test configurations. These remain under review and are being cleaned up where necessary, but they should be distinguished from the default behavior of currently shipped production units.

Our goal is to be precise: we will not minimize confirmed security issues, but we also want users to understand which findings apply to production devices, which apply only to historical or customized configurations, and which are being addressed as part of broader hardening efforts.

To improve security reporting in the future, we are launching a dedicated security response channel and security contact process for vulnerability reports and responsible disclosure:

[email protected]

The public will also be able to find our security contact information on the Yarbo Security Center page under the “Explore” section of our official website.

We are also exploring the possibility of establishing a formal bug bounty program as part of our broader long-term security initiatives.

We appreciate the role independent security researchers play in responsibly identifying potential issues, and we remain committed to strengthening the security, transparency, and trustworthiness of our products.

As the investigation and remediation work continues, I will provide further updates as they become available.

Kenneth Kohlmann

Co-founder, Yarbo

New York

Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email

Related Articles

China claims the world’s fastest supercomputer

China claims the world’s fastest supercomputer

Digital World 28 June 2026
Nest’s quest to fix your thermostat

Nest’s quest to fix your thermostat

Digital World 28 June 2026
TMD’s keyless bike lock is a 0 solution to a  problem

TMD’s keyless bike lock is a $280 solution to a $60 problem

Digital World 28 June 2026
Teenage Engineering adds lo-fi mode, USB audio, and more to its KO II sampler

Teenage Engineering adds lo-fi mode, USB audio, and more to its KO II sampler

Digital World 27 June 2026
Apple wants permission to buy memory from a blacklisted Chinese supplier

Apple wants permission to buy memory from a blacklisted Chinese supplier

Digital World 27 June 2026
Why is Apple asking me to pay more for Big Tech’s AI obsession?

Why is Apple asking me to pay more for Big Tech’s AI obsession?

Digital World 27 June 2026
Top Articles
Grace Gummer, Meryl Streep’s Daughter, Owns the Red Carpet After Haunting Portrayal of Caroline Kennedy

Grace Gummer, Meryl Streep’s Daughter, Owns the Red Carpet After Haunting Portrayal of Caroline Kennedy

15 April 2026240 Views
Canadians aren’t taking their paid vacation days. Can burnout be far behind? | Canada Voices

Canadians aren’t taking their paid vacation days. Can burnout be far behind? | Canada Voices

2 June 2026204 Views
Does alcohol make you sleep better or worse? | Canada Voices

Does alcohol make you sleep better or worse? | Canada Voices

25 May 2026112 Views
Canada’s ‘most beautiful’ university campuses were revealed and so many are by water

Canada’s ‘most beautiful’ university campuses were revealed and so many are by water

15 April 2026109 Views
Demo
Don't Miss
Poilievre asks Parliament to probe B.C. ‘condo bailout’ blocking ‘a price correction’
Lifestyle 28 June 2026

Poilievre asks Parliament to probe B.C. ‘condo bailout’ blocking ‘a price correction’

Conservative Leader Pierre Poilievre is calling on Parliament to probe Ottawa’s proposal to convert unsold…

Supergirl flops at the box office with  million opening on par with Joker 2

Supergirl flops at the box office with $38 million opening on par with Joker 2

1965 Folk Rock Hit, Written in a Taxi, Became a Legendary 11-Minute Anthem

Oakville couple earning more than 0,000 makes mortgage payments of ,000 each month | Canada Voices

Oakville couple earning more than $400,000 makes mortgage payments of $8,000 each month | Canada Voices

About Us
About Us

Canadian Reviews is your one-stop website for the latest Canadian trends and things to do, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
No injuries but Hibernia oil spill posed threat of deadly blast and fire: regulator

No injuries but Hibernia oil spill posed threat of deadly blast and fire: regulator

MAPPA’s next big hit looks simultaneously adorable and unhinged

MAPPA’s next big hit looks simultaneously adorable and unhinged

Fans Are Losing It Over Jason Kelce's Throwback Photos and They're All Saying the Same Thing

Most Popular
Why You Should Consider Investing with IC Markets

Why You Should Consider Investing with IC Markets

28 April 202433 Views
OANDA Review – Low costs and no deposit requirements

OANDA Review – Low costs and no deposit requirements

28 April 2024372 Views
LearnToTrade: A Comprehensive Look at the Controversial Trading School

LearnToTrade: A Comprehensive Look at the Controversial Trading School

28 April 202494 Views
© 2026 ThemeSphere. Designed by ThemeSphere.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us

Type above and press Enter to search. Press Esc to cancel.