Shark robot vacuum: Cloud vulnerability opens other devices
… Such certificates are normally intended to allow a device to access only its own MQTT topics and its own Device Shadow. However, on the examined device, the assigned AWS IoT policy was too broad. …