• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data

April 7, 2021 by staff 13 Comments

drone securityDrones are now more important than ever for enterprise companies – and that means that drone security is more important too.  Here, mobile development expert and author Godfrey Nolan gives 5 points that drone manufacturers, software developers for the drone industry and industry users must consider in the development process.
The following is a guest post by Godfrey Nolan, mobile app development expert and president of RIIS, LLC, a Michigan-based mobile development firm. 

Edmund Burke was the person who first said “Those who don’t know history are doomed to repeat it.”  Everyone in the security world is well aware of that mantra.

In the late 90’s there was a rash of hacked websites because nobody knew how to secure a website. You could put a dot at the end of a Microsoft ASP webpage and it would give you the webpage’s source code sitting on the server.  Microsoft, Sun, Oracle and everyone else gradually closed these holes. And while there are still notable hacks on websites, it’s typically because the sites are not running the latest and greatest software, e.g. the Experian website was using outdated Struts software; or if someone did something silly, like letting the intern create the password.

Over the last decade, the same thing happened on the mobile platform. Hardly a week went by without some earth shattering hack that exposed an app on your phone. Developers were running so fast that they paid little or no attention to their app security: it was much more important to get to market quicker than the competition.  It was irrelevant that your dating preferences, credit card numbers and passwords were exposed.  Bad press shifted the focus, and eventually the basic fundamentals of mobile security became common practice.

Which brings us to drones.  As an industry, just like the mobile guys, we’re all focused on getting to market quicker than the competitors.  Security is DJI’s problem, not ours.

So to help get the conversation going here are 5 security items you should be thinking about as a drone manufacturer or software developer.

1. Don’t store anything on the phone that you can’t afford to lose.

Mobile applications are a huge part of the drone experience.  They are the control center, the gateway to the cloud etc.  Understand that hackers can reverse engineer, decompile or disassemble the code back into something readable.  If you put any decryption or cloud keys in your source code then someone is going to find it. It’s also really tempting to store user’s passwords, tokens or other data on the phone to make things easier for the drone pilot.  Don’t do it. And while Android and iOS have both developed secure storage, we have all heard that one before and eventually someone hacked it and the data was exposed. Read the OWASP mobile top 10 risks to learn more.
2. Frida is your frenemy
Back in the day when everyone was hacking mobile apps, they were mostly doing static analysis to reverse engineer the code or look at any saved data.  However there are lots of new tools, such as Frida, which will do dynamic code injection to rip apart any login or permission restrictions that you think are in place.  Any username and password information stored in memory are also potentially up for grabs. See frida.re for more information.3. “I’ve got an S3 bucket and I’m going to use it.”
A huge part of the explosion in the web was largely due to how easy Amazon made it to create a cloud application.  Drone apps obviously generate tons of video, which seems to be largely stored on Amazon S3 buckets or Azure.  Amazon also has really useful command line tools that automate a lot of the mundane work of uploading, downloading and searching S3 buckets.

Man in the middle tools, such as Burpsuite, are very good at sniffing out the keys. So don’t store your Amazon keys or any other cloud keys in the mobile app or send them in cleartext across the internet, as they can be used together with these tools to download everyone’s videos.  The OWASP cloud top 10 has this and many, many other suggestions on how to secure your cloud.

4. It’s the network, dammit.
Are you using an encrypted signal for your video and telemetry? Great.  But is it the same key for every drone? Can you shell into the drone? But – are you using the same password for every drone? It’s important to secure your network using unique keys and tokens – otherwise you run the risk of someone else gaining access to the drone’s video feed or worse.

5. Mr. Robot’s school of OSINT
Perhaps the least obvious aspect of drone security is OSINT or Open Source Intelligence. Don’t leave any traces of the developer’s names in the mobile app or on the drone. Names can be leveraged for more information about your app on developer sites such as github and stackoverflow.  Developers often love to talk about their cool work and are often easy targets for social engineering.  Also don’t leave any traces of presentations, proposals, contracts etc on your website or on S3 buckets. Google indexes everything and the right google search can be very informative.  To start, try googling filetype:pdf site:yourdomain.com on your own website.  Michael Bazzell’s OSINT Techniques book is also a great resource for the advanced user.

No doubt we’ll have the same issues with whatever technology platform comes next. Pretty sure there have already been some major ML hacks that we haven’t heard about yet.  Here’s hoping to when we can we put the drone security issues in the rear view mirror in the not too distant future.

Godfrey Nolan is the founder and president of RIIS LLC, a mobile development firm in the Detroit Metro area creating amazing apps for the drone industry. A frequent speaker at industry events and writer for a wide variety of industry publications, he is also the author of Agile Swift and Agile Android on setting up Agile testing for both mobile platforms using Continuous Integration (CI).

Filed Under: Drone News Feeds, Featured, News Tagged With: Commercial drone industry, Drone Security, Godfrey Nolan, riis

Reader Interactions

Trackbacks

  1. April 10, 2021 - Air Transat seeking $500 million in government aid - Emond Harnden says:
    February 11, 2022 at 3:13 pm

    […] Drone Security: 5 points manufacturers and users must consider to protect drone data […]

    Reply
  2. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data - Eledonk Electronics says:
    April 10, 2021 at 2:06 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  3. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data - DronesOnline.site says:
    April 10, 2021 at 12:20 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  4. Drone Security: 5 Points for Manufacturers and Developers - Go Drones Blog says:
    April 8, 2021 at 1:09 pm

    […] DRONELIFE EXCLUSIVE: Protect your data. A mobile app development expert discusses potential vulnerabilities to avoid in drone security. Source […]

    Reply
  5. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – Top Drones & reviews says:
    April 7, 2021 at 11:06 pm

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  6. Drone Security: 5 Points for Manufacturers and Developers – Androidlic says:
    April 7, 2021 at 10:34 am

    […] Source link […]

    Reply
  7. Drone Security: 5 Points for Manufacturers and Developers | #microsoft | #microsoftsecurity - National Cyber Security News Today says:
    April 7, 2021 at 9:42 am

    […] Original Source link […]

    Reply
  8. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – DronePilots.News says:
    April 7, 2021 at 8:23 am

    […] Source […]

    Reply
  9. Drone Security: 5 Points for Manufacturers and Developers – Game of Drones says:
    April 7, 2021 at 7:52 am

    […] Godfrey Nolan is the founder and president of RIIS LLC, a mobile development firm in the Detroit Metro area creating amazing apps for the drone industry. A frequent speaker at industry events and writer for a wide variety of industry publications, he is also the author of Agile Swift and Agile Android on setting up Agile testing for both mobile platforms using Continuous Integration (CI). Article Source […]

    Reply
  10. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data | Drone Magazine says:
    April 7, 2021 at 7:33 am

    […] Source […]

    Reply
  11. Drone Security: 5 Points for Manufacturers and Developers – Drone Observer says:
    April 7, 2021 at 6:35 am

    […] Godfrey Nolan is the founder and president of RIIS LLC, a mobile development firm in the Detroit Metro area creating amazing apps for the drone industry. A frequent speaker at industry events and writer for a wide variety of industry publications, he is also the author of Agile Swift and Agile Android on setting up Agile testing for both mobile platforms using Continuous Integration (CI). Source link […]

    Reply
  12. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – DronePilots.News says:
    April 7, 2021 at 6:24 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  13. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – Best Drones Online says:
    April 7, 2021 at 6:17 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

Gaussian Splatting Meets Photogrammetry: SimActive Integrates New Capability in Correlator3D

From Industry Buzz to Practical Workflow Gaussian splatting has quickly become one of the most talked-about developments in 3D reconstruction.…

Continue Reading Gaussian Splatting Meets Photogrammetry: SimActive Integrates New Capability in Correlator3D

Saildrone Deploys 16 Voyager USVs for Coast Guard Great Lakes Mission

The Bay Area autonomous maritime company brings persistent surveillance to the Great Lakes and Northeast under a $15.5 million Coast…

Continue Reading Saildrone Deploys 16 Voyager USVs for Coast Guard Great Lakes Mission

Indiana Scores First Drone Deer Hunting Conviction in Landmark UAV Poaching Case

Indiana’s first drone deer hunting conviction sets legal precedent By DRONELIFE Features Editor Jim Magill As hunters find new ways…

Continue Reading Indiana Scores First Drone Deer Hunting Conviction in Landmark UAV Poaching Case

Beyond Pizza Delivery: How AI Agents and Drones Are Building the Next Commerce Infrastructure

Papa Johns, Wing, and Google Cloud offer a glimpse of a future where AI systems, autonomous logistics, and drone delivery…

Continue Reading Beyond Pizza Delivery: How AI Agents and Drones Are Building the Next Commerce Infrastructure

SkyDrive, Osaka Metro Launch Japan’s First eVTOL Vertiport Consortium

The Toyota-based eVTOL maker joins Osaka Metro, Marubeni, Soracle, and local governments to commercialize the Osakako Vertiport on Osaka Bay.…

Continue Reading SkyDrive, Osaka Metro Launch Japan’s First eVTOL Vertiport Consortium

RPX Technologies Lands Embir-3 Thermal Camera on Blue UAS Framework

The Stillwater, Oklahoma firm secures NDAA compliance and DIU listing for its compact thermal imaging payload aimed at unmanned aircraft…

Continue Reading RPX Technologies Lands Embir-3 Thermal Camera on Blue UAS Framework

Amprius Taps Intralink for South Korea Drone Battery Push

The Silicon Valley battery maker brings on a Seoul-based business development team to chase OEM and pack-maker deals across Korea’s…

Continue Reading Amprius Taps Intralink for South Korea Drone Battery Push

The Challenge of Drone Pizza Delivery: Flytrex Finally Solved It

Flytrex, Little Caesars join in first-of-kind pizza delivery By DRONELIFE Features Editor Jim Magill Over the past several years, residents…

Continue Reading The Challenge of Drone Pizza Delivery: Flytrex Finally Solved It

Headed to XPONENTIAL 2026? Don’t Miss These Partners, Panels, and Dual-Use Innovations in Detroit

From May 11-14, the annual AUVSI Xponential conference will bring the global autonomous systems industry to Detroit. This year’s conference…

Continue Reading Headed to XPONENTIAL 2026? Don’t Miss These Partners, Panels, and Dual-Use Innovations in Detroit

Rogue Cortex and UAS Nexus Launch Modular FPV Drone Developer Kit

Salt Lake City partnership pairs UAS Nexus’ Platform One airframe with Rogue Cortex’s SDK to give engineers a production-grade FPV…

Continue Reading Rogue Cortex and UAS Nexus Launch Modular FPV Drone Developer Kit

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3Dâ„¢ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT