• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

DJI Go App Security Problems: DJI Responds to Reports of Potential Flight System Software Vulnerabilities

July 29, 2020 by Miriam McNabb 11 Comments

DJI Go App security problemsAre reports of DJI Go App security problems overblown, or cause for concern?

By DRONELIFE staff writer, Jim Magill

Two related studies, released last week by a pair of cybersecurity companies, claim to reveal potential flaws in a DJI flight operation software system, which researchers say could be exploited “to target specific users with malicious updates or applications that could be used to exploit the user’s phone.”

In its response, DJI said the reports “found typical software concerns, with no evidence they have ever been exploited.” The reports are just the latest example of security issues being raised about the Chinese-based drone manufacturing and software company, which for some time has been under scrutiny by lawmakers and members of the current administration in Washington.

DJI Go App Security Problems

In a blog post Cybersecurity firm GRIMM released it findings on potential privacy concerns of DJI drones within the Android DJI GO 4 application.  Researchers at GRIMM partnered with IT security company Synacktiv, which performed an in-depth dynamic and static analysis of the application.

GRIMM found the DJI GO 4 application “contains a self-update feature that bypasses the Google Play store,” and enables drone users to download and install applications via the Weibo software development kit (SDK). “During this process, the Weibo SDK also collects the user’s private information and transmits it to Weibo,” the report states.

The volume of user data available to DJI and Weibo could leave the drone user vulnerable to hacking by a malicious actor, who “may attempt to compromise DJI’s and Weibo’s servers to exploit this functionality themselves,” the report states.

In addition, the GRIMM report also notes that The DJI GO 4 application restarts itself, after the drone user tries to swipe it closed, allowing it to continue to run in the background even though the the user might believe the app is closed.

“The DJI GO 4 application contains several suspicious features as well as a number of anti-analysis techniques, not found in other applications using the same SDKs,” the report notes.

In its statement DJI said, “The hypothetical vulnerabilities outlined in these reports are best characterized as potential bugs.”

The drone developer said it has safeguards in place to prevent the download of an unofficial, or “hacked,” version of one of its apps. When it detects hacked versions of a DJI app – for example if the app has been modified to remove flight safety features, such as altitude restrictions – the company will notify the user and require the download of the more recent official version of the app from the DJI website.

If the user does not consent, DJI said it would disable the hacked version of the app.

In any case, since the DJI GO4 app is primarily used as the flight operation of its recreational drones, the potential vulnerabilities described in the two reports do not extend to drones used by government agencies, the company said. “DJI’s drone products designed for government agencies do not transmit data to DJI and are compatible only with a non-commercially available version of the DJI Pilot app.”

For its recreational drones that do use the DJI GO4 app, DJI said it integrates its consumer apps with the leading social media sites via those sites’ SDKs. It referred questions about the security of the SDKs to their respective social media services. “However, please note that the SDK is only used when our users proactively turn it on,” DJI said.

The company also disputed the cybersecurity firms’ finding that DJI GO 4 was able to restart itself after being closed by the user. “We are investigating why these researchers claim it did so. We have not been able to replicate this behavior in our tests so far,” DJI said.

“We design our systems so DJI customers have full control over how or whether to share their photos, videos and flight logs, and we support the creation of industry standards for drone data security that will provide protection and confidence for all drone users.”

Over the past several years, DJI and other China-based drone companies have faced numerous questions over the security of the data collected from users. Several bills have been filed in Congress to limit the use by federal agencies of drones manufactured in, or containing components produced in, China. Earlier this year, the U.S. Department of the Interior (DOI) grounded all non-emergency operations for its entire fleet of 800 drones, citing potential security risks.

DJI, whose drones comprised a small portion of the DOI fleet, blasted the move, “which inappropriately treats a technology’s country of origin as a litmus test for its performance, security and reliability.”

In an interview, DJI spokesman Michael Oldenburg said rather than instituting a so-called country-of-origin system of drone regulation, the U.S. should establish a national set of rules regulating the cybersecurity of all unmanned aerial systems. “We’re advocating that in order to make things more secure — and it’s not just for DJI drones, but drones from any manufacturers — there should be clear and transparent guidelines and standards that those manufacturers make sure their products meet,” he said.

Miriam McNabb

Miriam McNabb is the Editor-in-Chief of DRONELIFE and CEO of JobForDrones, a professional drone services marketplace, and a fascinated observer of the emerging drone industry and the regulatory environment for drones. Miriam has penned over 3,000 articles focused on the commercial drone space and is an international speaker and recognized figure in the industry.  Miriam has a degree from the University of Chicago and over 20 years of experience in high tech sales and marketing for new technologies.
For drone industry consulting or writing, Email Miriam.

TWITTER:@spaldingbarker

Subscribe to DroneLife here.

Filed Under: Drone News Feeds, Featured, News Tagged With: chinese drone tech, DJI, DJI GO App, DJI Security

Reader Interactions

Trackbacks

  1. DJI Says Promises About Application Stability Misleading | Cool Gadgets says:
    August 7, 2020 at 5:10 am

    […] protection are normally properly publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: following which they rapidly released a next assessment of the […]

    Reply
  2. DJI Says Claims About App Security Misleading | Aerial Division says:
    August 7, 2020 at 3:13 am

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  3. DJI Says Claims About App Security Misleading – My Blog says:
    August 6, 2020 at 9:49 pm

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  4. DJI Says Claims About App Security Misleading - Lingeriestore says:
    August 6, 2020 at 7:06 pm

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  5. DJI Pilot App Security: DJI Says Claims About App Security Misleading – Drones Crunch says:
    August 6, 2020 at 5:12 pm

    […] app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  6. DJI Says Claims About App Security Misleading | Gadgets says:
    August 6, 2020 at 2:54 pm

    […] their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot […]

    Reply
  7. DJI Responds to Reports of Potential Go App Security Problems - Go Drones Blog says:
    July 30, 2020 at 10:51 pm

    […] Reports of potential DJI Go App security problems identified by research firms are “potential bugs,” says the manufacturer. Source […]

    Reply
  8. DJI Responds to Reports of Potential Go App Security Problems ⋆ says:
    July 30, 2020 at 4:34 am

    […] The complete article is here […]

    Reply
  9. DJI Responds to Reports of Potential Go App Security Problems | Anti Corruption Digest says:
    July 29, 2020 at 8:28 pm

    […] Source: DJI Responds to Reports of Potential Go App Security Problems […]

    Reply
  10. DJI Responds to Reports of Potential Go App Security Problems – DroneLife - On Sale Drones says:
    July 29, 2020 at 5:50 pm

    […] DJI Responds to Reports of Potential Go App Security Problems  DroneLife […]

    Reply
  11. DJI Go App Security Problems: DJI Responds to Reports of Potential Flight System Software Vulnerabilities | Drone Magazine says:
    July 29, 2020 at 1:59 pm

    […] Source […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

FCC Adds More Drone Exemptions to Covered List Ban: Elevon Aerial, Air6 Systems

New FCC notice expands the list of conditionally approved foreign-made drone systems exempted from the agency’s broad Covered List restrictions…

Continue Reading FCC Adds More Drone Exemptions to Covered List Ban: Elevon Aerial, Air6 Systems

Students Compete in XPRIZE Wildfire Finals With AI Drone Firefighting

Silicon Valley students take on pros with wildfire drones. By Dronelife Features Editor Jim Magill

https://dronelife.com/wp-content/uploads/2026/05/Powerus_xFold-DragonH-Fire.mp4
The…

Continue Reading Students Compete in XPRIZE Wildfire Finals With AI Drone Firefighting

Robin Radar Names Homeland Security and Defense Leads for US Expansion

The Hague-based maker of the IRIS drone-detection radar adds senior US sales leadership and larger Virginia headquarters as homeland security…

Continue Reading Robin Radar Names Homeland Security and Defense Leads for US Expansion

Buffalo’s Natrion Rolls Out NDAA-Compliant Drone Battery Cells

The Buffalo-based battery materials company debuts NDAA-compliant pouch cells with up to 80% more energy density than standard Li-ion. Natrion…

Continue Reading Buffalo’s Natrion Rolls Out NDAA-Compliant Drone Battery Cells

ePropelled Launches Integrated Power System for Agricultural Drones

New propulsion platform targets growing precision agriculture UAV market As agricultural drone adoption continues to expand worldwide, ePropelled has introduced…

Continue Reading ePropelled Launches Integrated Power System for Agricultural Drones

FAA and DoD Are Building the Rules for Drones Operating Near Sensitive Airspace

FAA and DoD Explore How Drones, Counter-UAS Systems, and Airports Can Share Airspace XPONENTIAL panel highlights growing cooperation between civil…

Continue Reading FAA and DoD Are Building the Rules for Drones Operating Near Sensitive Airspace

Urban UAV Operations Need More than Drones

Cloud Century has implemented more than 200 drone docks in China, learning what urban drone operations require. In this guest…

Continue Reading Urban UAV Operations Need More than Drones

MatrixSpace Brings Portable Counter-Drone Radar to Lithuanian Exercise

The xTechCounter Strike winner deploys portable AI-powered radar to strengthen low-altitude airspace awareness for M-SHORAD units in Pabradė. MatrixSpace is…

Continue Reading MatrixSpace Brings Portable Counter-Drone Radar to Lithuanian Exercise

Industrial Policy and Wright’s Law: A New Perspective on Building the U.S. Drone Industry

At the AUVSI XPONENTIAL 2026 conference this week, Red Cat Holdings executive Brendan Stewart delivered one of the more historically…

Continue Reading Industrial Policy and Wright’s Law: A New Perspective on Building the U.S. Drone Industry

How DHS Is Helping World Cup Host Cities Get Counter-UAS Ready Before FIFA 2026

DHS lab equips World Cup cities with counter-drone guidance. By DRONELIFE Features Editor Jim Magill (Editor’s note: This is part…

Continue Reading How DHS Is Helping World Cup Host Cities Get Counter-UAS Ready Before FIFA 2026

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3D™ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT