DJI Pilot app shares same security flaws as DJI Go 4, says Synacktiv

About ten days ago, this story was published in the NY Times highlighting the security flaws found in the for the Android platform by security researchers from the French company Synacktiv. Today, the company releases a new statement claiming that the for commercial and enterprise customers has the same security concerns

DJI Pilot app shares same security flaws as DJI Go 4, according to Synacktiv

Synacktiv, a French security research company that has also worked for DJI’s competitors, released a statement claiming that the DJI Pilot app for commercial and enterprise customers shares many of the same security flaws as the DJI Go 4 app. The issues are related to the apps running on Google’s Android platform, not Apple’s iOS.

Synacktiv’s initial report on the DJI Go 4 app was picked up by the NY Times and July 23, 2020. In a statement, the company says that

“We found similar issues to those listed in our previous blogpost in the application, such as a forced update mechanism.”

The DJI Pilot app is used to control the DJI Matrice, DJI Phantom 4, drones.

Dji Pilot App Shares Same Security Flaws As Dji Go 4, Says Synacktiv 1

Synacktiv’s key findings on the DJI Pilot app

Here are the key findings from Synacktiv:

  • The professional DJI Pilot application is protected using the same packer as the consumer-grade DJI Go 4 application
  • The professional DJI Pilot application includes the same forced upgrade mechanism as the one present in its consumer-grade applications
  • The “offline” Local Data Mode requires an Internet connection in order to install unlocking certificates

Synacktiv points out that the forced upgrade mechanism is,

“very similar to command and control servers encountered with malwares. Given the wide permissions required by DJI Pilot (access contacts, microphone, camera, location, storage, change network connectivity, etc.), the DJI servers have almost full control over the user’s phone.”

DJI’s Local Data Mode does allow the drone to be disconnected from the internet while being operated, however, Synactiv points out that in order to unlock flying over certain sensitive areas, the user has to deactivate the Local Date Mode temporarily and thus allowing network communications for a limited time. The research firm also points out that the unlock certificate is linked to a specific aircraft and user account and thus may “allow specific targeting of sensitive users.”

DroneXL’s take

We have reached out to 大疆创新 for a response on this latest report from Synacktiv and will let you know once we receive that. Furthermore, we do wonder who is behind this research? Are these research projects done by Synacktiv or does another party pay for Synacktiv to look into these DJI apps? We will ask them.

Droneu 营销横幅广告 1

保持联系!

If you’d like to stay up to date with all the latest drone news, scoops, rumors, and reviews, then follow us on 推特, 在 Facebook 上, YouTube, Instagram 或者

订阅我们的每日无人机新闻电子邮件*。


 

提交提示 如果您想与我们分享信息或技巧,请随时提交 这里支持 DroneXL.co: 您可以在下次购买无人机时使用这些链接来支持 DroneXL.co: Adorama, 亚马逊, B&H, 百思买, 易趣网, 大疆创新, 鹦鹉Yuneec.我们会在您不支付额外费用的情况下收取少量佣金。感谢您帮助 DroneXL 发展! 联邦贸易委员会: DroneXL.co 使用可产生收入的联盟链接。

* 我们绝不出售、共享、出租或发送垃圾邮件。我们的电子邮件在工作日下午 5:30 左右发出。


了解 DroneXL.co 的更多信息

订阅后即可通过电子邮件收到最新文章。

发出你的声音

拟议的立法威胁到您使用无人机娱乐、工作和安全的能力。无人机 无人机宣传联盟 加入我们,告诉您的民选官员保护您的飞行权利。

无人机宣传联盟
立即行动
在谷歌新闻上关注我们!

获取第 107 部分证书

Pass the Part 107 test and take to the skies with the 试点研究所.我们已帮助数千人成为飞机和商用无人机飞行员。我们的课程由行业专家设计,帮助您通过 FAA 考试,实现梦想。

试验研究所

Copyright © DroneXL.co 2025. All rights reserved. The content, images, and intellectual property on this website are protected by copyright law. Reproduction or distribution of any material without prior written permission from DroneXL.co is strictly prohibited. For permissions and inquiries, please 联系我们 first. DroneXL.co is a proud partner of the 无人机宣传联盟. Be sure to check out DroneXL's sister site, EVXL.co, for all the latest news on electric vehicles.

美国联邦贸易委员会:DroneXL.co 是亚马逊联营公司,使用联营链接可从符合条件的购买中获得收入。我们不会出售、分享、出租或向您发送垃圾邮件。

Haye Kesteloo
Haye Kesteloo

Haye Kesteloo is a leading drone industry expert and Editor in Chief of DroneXL.coEVXL.co, where he covers drone technology, industry developments, and electric mobility trends. With over nine years of specialized coverage in unmanned aerial systems, his insights have been featured in The New York Times, The Financial Times, and cited by The Brookings Institute, Foreign Policy, Politico and others.

Before founding DroneXL.co, Kesteloo built his expertise at DroneDJ. He currently co-hosts the PiXL 无人机表演 on YouTube and podcast platforms, sharing industry insights with a global audience. His reporting has influenced policy discussions and been referenced in federal documents, establishing him as an authoritative voice in drone technology and regulation. He can be reached at haye @ dronexl.co or @hayekesteloo.

文章: 4803

发表评论

这个站点使用 Akismet 来减少垃圾评论。了解你的评论数据如何被处理

zh_CNChinese