Security weakness found in DJI drones, according to the NY Times

This morning, the NY Times featured an article on their home page that is titled, “Popular Chinese-made drone is found to have security weakness. Of course, the article is specifically about DJI drones that are found to have data security issues.

Security weakness found in DJI drones

У "The concerns around DJI drones started in 2017 and over the last three years, these concerns have been expressed by various government departments and lawmakers. DJI has vigorously defended itself against these claims, however, this morning the NY Times reports on a new security weakness specifically related to the use of smartphones that run Google’s Android operating system. The concerns have been reported by two security firms and have been confirmed by the newspaper. Here are some of the highlights of the article.

In two reports, the researchers contended that an app on Google’s Android operating system that powers drones made by -based Da Jiang Innovations, or DJI, collects large amounts of personal information that could be exploited by the Beijing government. Hundreds of thousands of customers across the world use the app to pilot their rotor-powered, camera-mounted aircraft.

“Every Chinese technology company is required by Chinese law to provide information they obtain, or information stored on their networks, to Chinese authorities if requested to do so,” said William R. Evanina, director of the National Counterintelligence and Security Center. “All Americans should be concerned that their images, biometrics, locational and other data stored on Chinese apps must be turned over to China’s state security apparatus.”

The newfound security weakness in DJI drones has been reported by the French company Synacktiv and -based GRIMM.

DJI can also update it without Google reviewing the changes before they are passed on to consumers. That could violate Google’s Android developer terms of service.

“The phone has access to everything the drone is doing, but the information we are talking about is phone information,” said Tiphaine Romand-Latapie, a Synacktiv engineer. “We don’t see why DJI would need that data.”

Synacktiv did not find the same vulnerability in the drone maker’s iPhone application.

Security Weakness Found In Dji Drones, According To The Ny Times 1

According to DJI, it is necessary for the drone maker to be able to update the app to prevent пілоти дронів from ‘hacking’ their DJI drones. Brendan Schulman, DJI’s Vice President of Policy and Affairs said in a statement:

“This safety feature in the Android version of one of our recreational flight control apps blocks anyone from trying to use a hacked version to override our safety features, such as altitude limits and geofencing. If a hacked version is detected, users are prompted to download the official version from our website.”

Schulman added that this feature was not present in the software version that is used by governments and enterprise companies.

… even when the app appears to be closed, it awaits instructions from afar, they [the researchers] found.

For instance, DJI’s direct link to the Android app was most likely designed as a workaround for Chinese policies that block Google in China, forcing companies to send Android app updates themselves.

The security researchers from French Synacktiv, a company that has also worked for DJI’s competitors (?) points out that there’s a worrying pattern to DJI software updates. The company said:

…the pattern of problems in DJI’s code and its quickly implemented fixes, which suggested that the company was already aware of some of the problems but had not fixed them, were also reason for concern.

The research company does not say that DJI is implementing ‘malicious uploads’ but it points out that DJI could be using the app for that purpose.

Security Weakness Found In Dji Drones, According To The Ny Times 2

DroneXL’s take

The security concerns around DJI drones do not seem to go away. You can argue about whether these concerns, including this latest ‘security weakness’, are valid or if they are politically driven. However, but the fact that they keep reappearing in the news, and this time on the front page of a major newspaper is not a good thing for DJI and even the as a whole. Already parts of the , such as the Department of the Interior have stopped using DJI drone altogether. My concern is that a next step might include a complete Federal ban on the use of Chinese-made drones, including DJI drones, and prohibiting the use of Federal funds to purchase Chinese-made drones. This would prevent many from using Federal grant money to purchase DJI drones. All in all a worrying situation, that DJI has not sufficiently addressed in my opinion. A worst-case scenario would be for the Trump administration to issue a flat out ban on Chinese-made drones, including DJI drones. We will watch this space closely.

Let us know what you think about the security concerns, and this security weakness in particular, around DJI drones in the comments below.

 

Банерна реклама Droneu Marketing 1

Залишайтеся на зв'язку!

If you’d like to stay up to date with all the latest drone news, scoops, rumors, and reviews, then follow us on Twitter, Facebook, YouTube, Instagram or…

Підпишіться на нашу щоденну розсилку новин про безпілотники*.


 

Надсилайте поради Якщо у вас є інформація або поради, якими ви хотіли б поділитися з нами, не соромтеся надсилати їх тут.Підтримайте DroneXL.co: Ви можете підтримати DroneXL.co, скориставшись цими посиланнями під час наступної покупки дрона: Adorama, Амазонка, B&H, BestBuy, eBay, DJI, Папугаі Yuneec. Ми беремо невелику комісію, коли ви це робите, без додаткових витрат з вашого боку. Дякуємо, що допомагаєте DroneXL розвиватися! ФТК: DroneXL.co використовує партнерські посилання, які приносять дохід.

* Ми не продаємо, не передаємо, не здаємо в оренду і не розсилаємо спам вашу електронну адресу. Наша електронна пошта відправляється в робочі дні близько 17:30.

Photo: Moment


Дізнайтеся більше від DroneXL.co

Підпишіться, щоб отримувати найсвіжіші записи на вашу електронну пошту.

Хей Кестелоо
Хей Кестелоо

Haye Kesteloo is a leading drone industry expert and Editor in Chief of DroneXL.co і EVXL.co, where he covers drone technology, industry developments, and electric mobility trends. With over nine years of specialized coverage in unmanned aerial systems, his insights have been featured in The New York Times, The Financial Times, and cited by The Brookings Institute, Foreign Policy, Politico and others.

Before founding DroneXL.co, Kesteloo built his expertise at DroneDJ. He currently co-hosts the Виставка дронів PiXL on YouTube and podcast platforms, sharing industry insights with a global audience. His reporting has influenced policy discussions and been referenced in federal documents, establishing him as an authoritative voice in drone technology and regulation. He can be reached at haye @ dronexl.co or @hayekesteloo.

Статті: 4791

Залишити відгук

Цей сайт використовує Akismet для зменшення спаму. Дізнайтеся, як обробляються дані ваших коментарів.

ukUkrainian