• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

DJI Security Issues: Booz Allen Performs Exhaustive Audit

June 9, 2020 by Miriam McNabb 10 Comments

DJI security issues

Rumors of DJI security issues have dogged the company – and their many users – since the beginning of the U.S. government’s trade arguments with China, and Chinese communications company Huwei.  Now, a new report from consulting giant Booz Allen Hamilton finds that DJI systems do not send data to DJI, China, or any other “unexpected” third party.

DJI has had to address security fears repeatedly, and with discussions over the U.S.  Drone Origin Security Enhancement Act leading to the Department of the Interior downing its fleet of nearly 800 DJI drones.  At the heart of fears over Chinese drones is the issue of data gathered by the drones being passed to the Chinese government or other third party.

The fears about DJI security issues have had a negative effect on many DJI clients and partners, who are caught between the need to reassure industrial clients and hardware requirements: DJI’s affordable and advanced hardware solutions have few competitors in the same price range not manufactured in “listed countries” including China.  One client, legendary drone company PrecisionHawk, worked with Booz Allen to develop a framework for testing the security of drone technology.  Their initial tests were performed on DJI drones – and the report is the result of that testing.

Threat Vectors and Vulnerabilities: DJI Drones or Drones in General?

The report states clearly that they found no evidence of data transmission to DJI or China, which backs up DJI’s assertion that users have complete control over their own data.  However, the report does identify technical vulnerabilities, such as when using the Map Services App – which does ping addresses like Google and AWS (Amazon’s cloud services.)  Customers looking for an absolutely secure platform will have to use the mitigations suggested – just turning off the “Allow Map Services” function.  But vulnerabilities like these need to be put into context.  These are the risks associated with any system, the report points out:  “Any drone that provides the feature of externally-sourced map services would be expected to make such connections and to present similar vulnerabilities.”

DJI has responded to the report saying that they appreciate the further evidence that their systems allow users total control over the data – and that they will make use of the detailed list of potential vulnerabilites and threat vectors.

“We take these findings extremely seriously and are already implementing concrete steps to address many of the threat vectors identified in the report,” says a DJI blog post. “Some have already been remediated, and we are actively working on several others, for our current products and longer-term approaches to security. All but two of these threat vectors relate to physical proximity or access to the drone itself.”

 

Miriam McNabb

Miriam McNabb is the Editor-in-Chief of DRONELIFE and CEO of JobForDrones, a professional drone services marketplace, and a fascinated observer of the emerging drone industry and the regulatory environment for drones. Miriam has penned over 3,000 articles focused on the commercial drone space and is an international speaker and recognized figure in the industry.  Miriam has a degree from the University of Chicago and over 20 years of experience in high tech sales and marketing for new technologies.
For drone industry consulting or writing, Email Miriam.

TWITTER:@spaldingbarker

Subscribe to DroneLife here.

Filed Under: DJI, Drone News Feeds, Featured, News Tagged With: Booz Allen, DJI, DJI Security, drone data security, Drone Security, drone security act

Reader Interactions

Trackbacks

  1. Public Safety Drone Survey Addresses COVID, Data Security | Gadgets says:
    July 14, 2020 at 2:59 am

    […] security have been up in the air for the past several months, with Chinese manufacturer DJI facing federal scrutiny amid recent discussions over the U.S. Drone Origin Security Enhancement […]

    Reply
  2. ANAFI USA Targets DJI: the Newest Parrot Drone for Law Enforcement and Enterprise | Gadgets says:
    July 1, 2020 at 11:51 am

    […] newest drone targets DJI directly on their most vulnerable point: data security rumors that just can’t be quelled. The ANAFI USA offers a compelling alternative: a U.S.-manufactured, […]

    Reply
  3. ANAFI USA Targets DJI: the Newest Parrot Drone for Law Enforcement and Enterprise - NEWS DIGITAL TECH says:
    July 1, 2020 at 10:17 am

    […] newest drone targets DJI directly on their most vulnerable point: data security rumors that just can’t be quelled. The ANAFI USA presents a compelling different: a U.S.-manufactured, […]

    Reply
  4. DJI Safety Points: Booz Allen Performs Exhaustive Audit - Drone Stuff Pro says:
    June 9, 2020 at 2:40 pm

    […] score : Supply Hyperlink Supply […]

    Reply
  5. DJI Security Issues: Booz Allen Performs Exhaustive Audit - Eledonk Electronics says:
    June 9, 2020 at 1:49 pm

    […] post DJI Security Issues: Booz Allen Performs Exhaustive Audit appeared first on […]

    Reply
  6. DJI Security Issues: Booz Allen Performs Exhaustive Audit - Drone Shop says:
    June 9, 2020 at 1:45 pm

    […] Source link […]

    Reply
  7. DJI Security Issues: Booz Allen Performs Exhaustive Audit | Drone Magazine says:
    June 9, 2020 at 12:31 pm

    […] Source […]

    Reply
  8. DJI Security Issues: Booz Allen Performs Exhaustive Audit ⋆ says:
    June 9, 2020 at 12:29 pm

    […] The complete article is here […]

    Reply
  9. DJI Security Issues: Booz Allen Performs Exhaustive Audit | Gadgets says:
    June 9, 2020 at 12:28 pm

    […] Source link […]

    Reply
  10. DJI Security Issues: Booz Allen Performs Exhaustive Audit - Baseball says:
    June 9, 2020 at 12:25 pm

    […] Source link […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

NASA Working Group Targets Autonomous Multi-Aircraft UAS Operations

A NASA-sponsored working group is pushing forward efforts to make autonomous, multi-drone fleet operations a routine part of the national…

Continue Reading NASA Working Group Targets Autonomous Multi-Aircraft UAS Operations

DHS Offers Counter-UAV Siting Advice For World Cup Communities

By Dronelife Features Editor Jim Magill (Editor’s note: This following story is part of an ongoing series of stories on…

Continue Reading DHS Offers Counter-UAV Siting Advice For World Cup Communities

Rapid Mapping for a 24/7 Defense Environment: SimActive on Speed, Security, and Scalable Intelligence

As defense budgets rise and geopolitical tensions reshape operational priorities, militaries are investing heavily in technologies that can turn raw…

Continue Reading Rapid Mapping for a 24/7 Defense Environment: SimActive on Speed, Security, and Scalable Intelligence

SkySafe on the Drone Radio Show! Drone Detection and Airspace Intelligence

Melissa Swisher is Chief Revenue Officer at SkySafe, a company delivering the intelligence organizations need to detect, analyze, and act…

Continue Reading SkySafe on the Drone Radio Show! Drone Detection and Airspace Intelligence

SimActive Integrates Phase One iXM-FS130 for High-Resolution Aerial Mapping

Correlator3D enables sub-centimeter processing for fixed-wing survey missions SimActive has announced full support for the Phase One iXM-FS130 sensor in…

Continue Reading SimActive Integrates Phase One iXM-FS130 for High-Resolution Aerial Mapping

WISPR Systems’ SkyScout 2+ Achieves Green UAS Certification

WISPR Systems announced that its SkyScout 2+ has earned Green UAS Certification from the Association for Uncrewed Vehicle Systems International (AUVSI). The designation confirms…

Continue Reading WISPR Systems’ SkyScout 2+ Achieves Green UAS Certification

EagleNXT Expands in Europe as Defense Drone Market Demand Grows

European Market for Defense Drones, Counter-UAS Grows By Dronelife Features Editor Jim Magill As western European nations contend with the…

Continue Reading EagleNXT Expands in Europe as Defense Drone Market Demand Grows

AeroDefense Launches No-Cost Drone Detection Access Program for Law Enforcement

AirWarden Essentials customers can now share drone detection data with SLTT, DHS, and FBI partners at no added cost AeroDefense…

Continue Reading AeroDefense Launches No-Cost Drone Detection Access Program for Law Enforcement

Versaterm Acquires Aloft to Expand Drone Capabilities for Public Safety

Deal adds FAA-approved airspace intelligence to DroneSense platform Versaterm has announced the acquisition of Aloft, an FAA-approved provider of airspace…

Continue Reading Versaterm Acquires Aloft to Expand Drone Capabilities for Public Safety

Trojan Horse or Trade Dispute? Texas Attorney General Targets Anzu in High-Stakes Drone Lawsuit

Texas AG sues Anzu, claims company sells DJI clones By DRONELIFE Features Editor Jim Magill Claiming that the company is…

Continue Reading Trojan Horse or Trade Dispute? Texas Attorney General Targets Anzu in High-Stakes Drone Lawsuit

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3D™ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT