DJI Pilot app shares same security flaws as DJI Go 4, says Synacktiv

About ten days ago, this story was published in the NY Times highlighting the security flaws found in the for the Android platform by security researchers from the French company Synacktiv. Today, the company releases a new statement claiming that the for commercial and enterprise customers has the same security concerns

DJI Pilot app shares same security flaws as DJI Go 4, according to Synacktiv

Synacktiv, a French security research company that has also worked for DJI’s competitors, released a statement claiming that the DJI Pilot app for commercial and enterprise customers shares many of the same security flaws as the DJI Go 4 app. The issues are related to the apps running on Google’s Android platform, not Apple’s iOS.

Synacktiv’s initial report on the DJI Go 4 app was picked up by the NY Times and July 23, 2020. In a statement, the company says that

“We found similar issues to those listed in our previous blogpost in the application, such as a forced update mechanism.”

The DJI Pilot app is used to control the DJI Matrice, DJI Phantom 4, そして drones.

Dji Pilot App Shares Same Security Flaws As Dji Go 4, Says Synacktiv 1

Synacktiv’s key findings on the DJI Pilot app

Here are the key findings from Synacktiv:

  • The professional DJI Pilot application is protected using the same packer as the consumer-grade DJI Go 4 application
  • The professional DJI Pilot application includes the same forced upgrade mechanism as the one present in its consumer-grade applications
  • The “offline” Local Data Mode requires an Internet connection in order to install unlocking certificates

Synacktiv points out that the forced upgrade mechanism is,

“very similar to command and control servers encountered with malwares. Given the wide permissions required by DJI Pilot (access contacts, microphone, camera, location, storage, change network connectivity, etc.), the DJI servers have almost full control over the user’s phone.”

DJI’s Local Data Mode does allow the drone to be disconnected from the internet while being operated, however, Synactiv points out that in order to unlock flying over certain sensitive areas, the user has to deactivate the Local Date Mode temporarily and thus allowing network communications for a limited time. The research firm also points out that the unlock certificate is linked to a specific aircraft and user account and thus may “allow specific targeting of sensitive users.”

DroneXL’s take

We have reached out to DJI for a response on this latest report from Synacktiv and will let you know once we receive that. Furthermore, we do wonder who is behind this research? Are these research projects done by Synacktiv or does another party pay for Synacktiv to look into these DJI apps? We will ask them.

Droneu Marketing Banner Ad 1

Stay in touch!

If you’d like to stay up to date with all the latest drone news, scoops, rumors, and reviews, then follow us on Twitter, フェイスブック, ユーチューブ, インスタグラム or…

Subscribe to our Daily Drone News email.*


 

Submit tips If you have information or tips that you would like to share with us, feel free to submit them hereSupport DroneXL.co: You can support DroneXL.co by using these links when you make your next drone purchase: Adorama, Amazon, B&H, BestBuy, eBay, DJI, Parrotそして Yuneec. We make a small commission when you do so at no additional expense to you. Thank you for helping DroneXL grow! FTC: DroneXL.co uses affiliate links that generate income.

* We do not sell, share, rent out or spam your email, ever. Our email goes out on weekdays around 5:30 p.m.


DroneXL.coをもっと見る

購読すると最新の投稿がメールで送信されます。

声を届ける

提案されている法案は、楽しみ、仕事、安全のためにドローンを使用するあなたの能力を脅かす。その ドローン擁護同盟 私たちと一緒に、あなたの選挙で選ばれた議員に、空を飛ぶ権利を守るよう訴えましょう。

ドローン擁護同盟
今すぐ行動を起こす
Google Newsでフォローしてください!

パート107証明書の取得

Pass the Part 107 test and take to the skies with the パイロット・インスティテュート.私たちは、何千人もの人々が飛行機や商業ドローンパイロットになるのを助けてきました。私たちのコースは、FAAのテストに合格し、あなたの夢を達成するために、業界の専門家によって設計されています。

パイロット・インスティチュート・ドローネクスル

Copyright © DroneXL.co 2025. All rights reserved. The content, images, and intellectual property on this website are protected by copyright law. Reproduction or distribution of any material without prior written permission from DroneXL.co is strictly prohibited. For permissions and inquiries, please お問い合わせ first. DroneXL.co is a proud partner of the ドローン擁護同盟. Be sure to check out DroneXL's sister site, EVXL.co, for all the latest news on electric vehicles.

FTC:DroneXL.coはAmazonアソシエイトであり、対象となる購入から収入を得ることができるアフィリエイトリンクを使用しています。私たちは、あなたの電子メールを販売、共有、貸し出し、またはスパムはありません。

ヘイ・ケステルー
ヘイ・ケステルー

Haye Kesteloo is a leading drone industry expert and Editor in Chief of DroneXL.co そして EVXL.co, where he covers drone technology, industry developments, and electric mobility trends. With over nine years of specialized coverage in unmanned aerial systems, his insights have been featured in The New York Times, The Financial Times, and cited by The Brookings Institute, Foreign Policy, Politico and others.

Before founding DroneXL.co, Kesteloo built his expertise at DroneDJ. He currently co-hosts the PiXLドローンショー on YouTube and podcast platforms, sharing industry insights with a global audience. His reporting has influenced policy discussions and been referenced in federal documents, establishing him as an authoritative voice in drone technology and regulation. He can be reached at haye @ dronexl.co or hayekesteloo.

記事本文: 4856

コメントを残す

This site uses Akismet to reduce spam. Learn how your comment data is processed.

jaJapanese