• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

DJI Pilot App Security: DJI Says Claims About App Security Misleading

August 6, 2020 by Miriam McNabb 6 Comments

DJI is clearly getting sick of the barrage of recent reports questioning their security; some of which don’t even bother to get the facts right.  The latest report from Synacktiv questions the DJI Pilot App security: but DJI has issued a statement pointing out the problems with a report written by a firm that doesn’t know drones and doesn’t seem to understand how features like geofencing work.

If the response sounds at times frustrated, it’s hard to blame the world’s largest manufacturer.  DJI garners headlines, and any reports about their app security are generally well publicized.  French security firm Synacktiv’s report of the DJI Go App was covered by the New York Times: after which they quickly launched a second analysis of the Pilot App.  Analysis by for-profit firms unfamiliar with drone technology, however, should be like any other headline these days – taken with the proverbial grain of salt.  Removing the perception of security issues can be harder than planting the seeds of doubt: DJI users should examine every point carefully for themselves.

The full text of DJI’s response is below.

DJI Statement On Further Misleading Claims About App Security

Today’s report from the Synacktiv digital security firm about DJI software includes further inaccuracies and misleading statements about how our products work, following similar reports from them last week. We want to make clear that DJI’s products protect user data; that DJI, like most software companies, continually updates products as real and perceived vulnerabilities come to light; and that there is no evidence that any of the hypothetical vulnerabilities reported by Synacktiv have ever been exploited. In this post, we address Synacktiv’s new report.

Synacktiv’s False Claim Concerning Weibo SDK

The DJI Pilot app for Android available from both the DJI website and the Google Play store do not integrate a software development kit (SDK) to connect with Weibo. This claim by Synacktiv is false. In fact, no versions of the DJI Pilot app have any function for users to share data to Weibo.

Synacktiv’s Misleading Claims Concerning DJI Pilot Auto-Updates

The DJI Pilot app for Android that is available on the Google Play store only updates to official versions downloaded from the Google Play store. The user is prompted to update in a pop-up window, and the app will not update unless the user agrees. For customers who operate our products in countries where the Google Play store is not available, the app and app updates are made available on our website. The headline, summary, and first half of Synacktiv’s report are intentionally misleading because they fail to note that this mechanism is limited to the website version of the DJI Pilot app only, and does not affect anyone who obtains the DJI Pilot app from the Google Play store.

Synacktiv’s Incomplete Understanding of DJI’s Geofencing System

The DJI Pilot app includes a feature called Local Data Mode that allows the user to sever the connection to the internet as soon as the setting is turned on in the app. In addition to enhancing data security assurance, this feature blocks the drone’s ability to update flight safety restrictions and blocks the user’s ability to “unlock” some geofenced areas. However, Synacktiv appears to misunderstand the function of DJI’s geofencing safety system and the many other available methods for customers to unlock. For example, government agencies can participate in our Qualified Entities Program which unlocks the entire region they request, with no need to connect to the internet after initial activation. Also, our Government Edition drones have no geofencing at all. DJI users understand these limitations and plan ahead for when and how to unlock geofencing flight restrictions, if needed.

As with automatic updates, these features are implemented for purposes that benefit the public by enhancing airspace safety during the use of our products. The important safety role of geofencing has been recognized by the U.S. Federal Aviation Administration’s (FAA) Drone Advisory Committee; the Airports International Council-North America and Association for Unmanned Vehicle Systems International joint Blue Ribbon Task Force on Airport Mitigation; and the FAA-industry joint Unmanned Aircraft Safety Team. No other company has done as much as DJI to proactively enhance the safety of drone operations. We are dismayed that safety features have again been misunderstood and misconstrued as hypothetical security threats by researchers who are evidently unfamiliar with the operation of drone technology.

DJI Immediately Remediated The Prior Reported Issues

While Synacktiv’s exaggerated and misleading initial report on security was cited in the New York Times, a serious examination of their work shows it falls short. DJI promptly updated the DJI GO 4 Android app July 31 to address the earlier hypothetical concerns Synacktiv noted about the DJI GO 4 app, removing the Weibo SDK and directing automatic safety-related updates to the Google Play store rather than our website.

DJI remains the only drone manufacturer to have its products successfully evaluated in publicly-available reports by multiple independent government and private institutions. DJI also remains the only drone manufacturer to have created a Bug Bounty Program to actively solicit responsible disclosure of security vulnerabilities and pays rewards to the researchers who find them.

For further details on DJI’s robust security protections, please refer to our response to the original allegations at this link: https://www.dji.com/newsroom/news/dji-statement-on-recent-reports-from-security-researchers

Miriam McNabb

Miriam McNabb is the Editor-in-Chief of DRONELIFE and CEO of JobForDrones, a professional drone services marketplace, and a fascinated observer of the emerging drone industry and the regulatory environment for drones. Miriam has penned over 3,000 articles focused on the commercial drone space and is an international speaker and recognized figure in the industry.  Miriam has a degree from the University of Chicago and over 20 years of experience in high tech sales and marketing for new technologies.
For drone industry consulting or writing, Email Miriam.

TWITTER:@spaldingbarker

Subscribe to DroneLife here.

Filed Under: Drone News Feeds, News Tagged With: DJI app security, DJI data security, dji security issues, DJI security response

Reader Interactions

Trackbacks

  1. AirWorks: DJI Launches Inspection Drone Project with Shell Oil | Gadgets says:
    August 26, 2020 at 12:39 pm

    […] a New York Times article covering a French security’s claims that DJI’s Pilot App faced security issues, a company statement swatted […]

    Reply
  2. DJI Pilot App Security: DJI Says Claims About App Security Misleading - Eledonk Electronics says:
    August 6, 2020 at 7:21 pm

    […] post DJI Pilot App Security: DJI Says Claims About App Security Misleading appeared first on […]

    Reply
  3. DJI Pilot App Security: DJI Says Claims About App Security - Go Drones Blog says:
    August 6, 2020 at 7:02 pm

    […] A recent report by data security analysts Synacktiv questioning DJI Pilot App security is misleading, says DJI in a scathing response. Source […]

    Reply
  4. DJI Pilot App Security: DJI Says Claims About App Security Misleading | Drone Films Limited says:
    August 6, 2020 at 3:14 pm

    […] post DJI Pilot App Security: DJI Says Claims About App Security Misleading appeared first on […]

    Reply
  5. DJI Says Claims About App Security Misleading ⋆ says:
    August 6, 2020 at 3:00 pm

    […] The complete article is here […]

    Reply
  6. DJI Pilot App Security: DJI Says Claims About App Security Misleading | Drone Magazine says:
    August 6, 2020 at 2:56 pm

    […] Source […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

Six Takeaways from CIS White Paper on Drone Risks at Public Gatherings

As planning ramps up for the FIFA World Cup 2026, security agencies are preparing for one of the most complex…

Continue Reading Six Takeaways from CIS White Paper on Drone Risks at Public Gatherings

Matternet and SoftBank Robotics America Partner to Scale Drone Delivery Networks

Collaboration targets healthcare and enterprise logistics with focus on real-world deployment Matternet and SoftBank Robotics America have announced a strategic…

Continue Reading Matternet and SoftBank Robotics America Partner to Scale Drone Delivery Networks

FAA Reverses Course on Drone Flight Limits Near Federal Operations

FAA backs down on threat to prosecute drone pilots By DRONELIFE Features Editor Jim Magill The FAA has apparently backed…

Continue Reading FAA Reverses Course on Drone Flight Limits Near Federal Operations

Donecle Raises €10 Million to Expand Drone-Based Aircraft Inspection Platform

Funding will support international growth and further development of AI-driven maintenance solutions Donecle, a France-based company specializing in automated aircraft…

Continue Reading Donecle Raises €10 Million to Expand Drone-Based Aircraft Inspection Platform

Is the U.S. Ready for Drone Threats at World Cup Scale?

U.S. faces multiple challenges in counter-UAS buildup By DRONELIFE Features Editor Jim Magill (Editor’s note: This is part of a…

Continue Reading Is the U.S. Ready for Drone Threats at World Cup Scale?

FAA Moves to Close Drone Enforcement Gap with New DETER Program

As detection outpaces enforcement, the FAA introduces faster penalties for rule-breaking operators Detection Has Outpaced Enforcement Drone detection is no…

Continue Reading FAA Moves to Close Drone Enforcement Gap with New DETER Program

HYFIX Raises $15M to Build U.S.-Made Drone Chip Platform

New system-on-chip aims to replace fragmented electronics with a single secure architecture HYFIX Spatial Intelligence, Inc. has announced a $15…

Continue Reading HYFIX Raises $15M to Build U.S.-Made Drone Chip Platform

FCC Grants Conditional Approval to Sees.ai UAS, Signaling New Path for Foreign Drone Systems

Limited public details raise questions about “v.USA 1.0” and how international companies can meet U.S. security requirements The Federal Communications…

Continue Reading FCC Grants Conditional Approval to Sees.ai UAS, Signaling New Path for Foreign Drone Systems

UK Drone Package for Ukraine Signals Push to Scale Domestic Industry

Largest-ever MOD initiative supports Kyiv while strengthening UK drone manufacturing base As the global race to build sovereign drone capability…

Continue Reading UK Drone Package for Ukraine Signals Push to Scale Domestic Industry

What Are People Really Saying About the Commercial Drone Industry?

Industry survey will shape discussion on real-world challenges and opportunities in commercial drone operations Commercial UAV Expo has announced its…

Continue Reading What Are People Really Saying About the Commercial Drone Industry?

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3D™ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT