• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer
  • DroneRacingLife
  • DroneFlyers
  • Newsletter
DroneLife

DRONELIFE

Stay up to date on all the latest Drone News

  • News
  • Products
  • Industries
    • Agriculture
    • Construction
    • Delivery
    • Dual Use
    • Inspection
    • Public Safety
    • Surveying
  • Enthusiasts
  • Regulations
  • Business
  • Video
  • Podcasts

Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data

April 7, 2021 by staff 13 Comments

drone securityDrones are now more important than ever for enterprise companies – and that means that drone security is more important too.  Here, mobile development expert and author Godfrey Nolan gives 5 points that drone manufacturers, software developers for the drone industry and industry users must consider in the development process.
The following is a guest post by Godfrey Nolan, mobile app development expert and president of RIIS, LLC, a Michigan-based mobile development firm. 

Edmund Burke was the person who first said “Those who don’t know history are doomed to repeat it.”  Everyone in the security world is well aware of that mantra.

In the late 90’s there was a rash of hacked websites because nobody knew how to secure a website. You could put a dot at the end of a Microsoft ASP webpage and it would give you the webpage’s source code sitting on the server.  Microsoft, Sun, Oracle and everyone else gradually closed these holes. And while there are still notable hacks on websites, it’s typically because the sites are not running the latest and greatest software, e.g. the Experian website was using outdated Struts software; or if someone did something silly, like letting the intern create the password.

Over the last decade, the same thing happened on the mobile platform. Hardly a week went by without some earth shattering hack that exposed an app on your phone. Developers were running so fast that they paid little or no attention to their app security: it was much more important to get to market quicker than the competition.  It was irrelevant that your dating preferences, credit card numbers and passwords were exposed.  Bad press shifted the focus, and eventually the basic fundamentals of mobile security became common practice.

Which brings us to drones.  As an industry, just like the mobile guys, we’re all focused on getting to market quicker than the competitors.  Security is DJI’s problem, not ours.

So to help get the conversation going here are 5 security items you should be thinking about as a drone manufacturer or software developer.

1. Don’t store anything on the phone that you can’t afford to lose.

Mobile applications are a huge part of the drone experience.  They are the control center, the gateway to the cloud etc.  Understand that hackers can reverse engineer, decompile or disassemble the code back into something readable.  If you put any decryption or cloud keys in your source code then someone is going to find it. It’s also really tempting to store user’s passwords, tokens or other data on the phone to make things easier for the drone pilot.  Don’t do it. And while Android and iOS have both developed secure storage, we have all heard that one before and eventually someone hacked it and the data was exposed. Read the OWASP mobile top 10 risks to learn more.
2. Frida is your frenemy
Back in the day when everyone was hacking mobile apps, they were mostly doing static analysis to reverse engineer the code or look at any saved data.  However there are lots of new tools, such as Frida, which will do dynamic code injection to rip apart any login or permission restrictions that you think are in place.  Any username and password information stored in memory are also potentially up for grabs. See frida.re for more information.3. “I’ve got an S3 bucket and I’m going to use it.”
A huge part of the explosion in the web was largely due to how easy Amazon made it to create a cloud application.  Drone apps obviously generate tons of video, which seems to be largely stored on Amazon S3 buckets or Azure.  Amazon also has really useful command line tools that automate a lot of the mundane work of uploading, downloading and searching S3 buckets.

Man in the middle tools, such as Burpsuite, are very good at sniffing out the keys. So don’t store your Amazon keys or any other cloud keys in the mobile app or send them in cleartext across the internet, as they can be used together with these tools to download everyone’s videos.  The OWASP cloud top 10 has this and many, many other suggestions on how to secure your cloud.

4. It’s the network, dammit.
Are you using an encrypted signal for your video and telemetry? Great.  But is it the same key for every drone? Can you shell into the drone? But – are you using the same password for every drone? It’s important to secure your network using unique keys and tokens – otherwise you run the risk of someone else gaining access to the drone’s video feed or worse.

5. Mr. Robot’s school of OSINT
Perhaps the least obvious aspect of drone security is OSINT or Open Source Intelligence. Don’t leave any traces of the developer’s names in the mobile app or on the drone. Names can be leveraged for more information about your app on developer sites such as github and stackoverflow.  Developers often love to talk about their cool work and are often easy targets for social engineering.  Also don’t leave any traces of presentations, proposals, contracts etc on your website or on S3 buckets. Google indexes everything and the right google search can be very informative.  To start, try googling filetype:pdf site:yourdomain.com on your own website.  Michael Bazzell’s OSINT Techniques book is also a great resource for the advanced user.

No doubt we’ll have the same issues with whatever technology platform comes next. Pretty sure there have already been some major ML hacks that we haven’t heard about yet.  Here’s hoping to when we can we put the drone security issues in the rear view mirror in the not too distant future.

Godfrey Nolan is the founder and president of RIIS LLC, a mobile development firm in the Detroit Metro area creating amazing apps for the drone industry. A frequent speaker at industry events and writer for a wide variety of industry publications, he is also the author of Agile Swift and Agile Android on setting up Agile testing for both mobile platforms using Continuous Integration (CI).

Filed Under: Drone News Feeds, Featured, News Tagged With: Commercial drone industry, Drone Security, Godfrey Nolan, riis

Reader Interactions

Trackbacks

  1. April 10, 2021 - Air Transat seeking $500 million in government aid - Emond Harnden says:
    February 11, 2022 at 3:13 pm

    […] Drone Security: 5 points manufacturers and users must consider to protect drone data […]

    Reply
  2. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data - Eledonk Electronics says:
    April 10, 2021 at 2:06 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  3. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data - DronesOnline.site says:
    April 10, 2021 at 12:20 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  4. Drone Security: 5 Points for Manufacturers and Developers - Go Drones Blog says:
    April 8, 2021 at 1:09 pm

    […] DRONELIFE EXCLUSIVE: Protect your data. A mobile app development expert discusses potential vulnerabilities to avoid in drone security. Source […]

    Reply
  5. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – Top Drones & reviews says:
    April 7, 2021 at 11:06 pm

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  6. Drone Security: 5 Points for Manufacturers and Developers – Androidlic says:
    April 7, 2021 at 10:34 am

    […] Source link […]

    Reply
  7. Drone Security: 5 Points for Manufacturers and Developers | #microsoft | #microsoftsecurity - National Cyber Security News Today says:
    April 7, 2021 at 9:42 am

    […] Original Source link […]

    Reply
  8. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – DronePilots.News says:
    April 7, 2021 at 8:23 am

    […] Source […]

    Reply
  9. Drone Security: 5 Points for Manufacturers and Developers – Game of Drones says:
    April 7, 2021 at 7:52 am

    […] Godfrey Nolan is the founder and president of RIIS LLC, a mobile development firm in the Detroit Metro area creating amazing apps for the drone industry. A frequent speaker at industry events and writer for a wide variety of industry publications, he is also the author of Agile Swift and Agile Android on setting up Agile testing for both mobile platforms using Continuous Integration (CI). Article Source […]

    Reply
  10. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data | Drone Magazine says:
    April 7, 2021 at 7:33 am

    […] Source […]

    Reply
  11. Drone Security: 5 Points for Manufacturers and Developers – Drone Observer says:
    April 7, 2021 at 6:35 am

    […] Godfrey Nolan is the founder and president of RIIS LLC, a mobile development firm in the Detroit Metro area creating amazing apps for the drone industry. A frequent speaker at industry events and writer for a wide variety of industry publications, he is also the author of Agile Swift and Agile Android on setting up Agile testing for both mobile platforms using Continuous Integration (CI). Source link […]

    Reply
  12. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – DronePilots.News says:
    April 7, 2021 at 6:24 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply
  13. Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data – Best Drones Online says:
    April 7, 2021 at 6:17 am

    […] post Drone Security: 5 Points Manufacturers and Users Must Consider to Protect Drone Data appeared first on […]

    Reply

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

LATEST

Who Builds the Sky? How Regional Partnerships Are Creating the Infrastructure for Advanced Air Mobility

On this episode of the Drone Radio Show, Lavera Alexander of the Monterey Bay Economic Partnership discusses why the future…

Continue Reading Who Builds the Sky? How Regional Partnerships Are Creating the Infrastructure for Advanced Air Mobility

FAA Moves from Planning to Building for Advanced Air Mobility

New research facility signals shift from policy development to operational readiness The Federal Aviation Administration is taking another step toward…

Continue Reading FAA Moves from Planning to Building for Advanced Air Mobility

How Skyways Quietly Built a Global Heavy-Lift Drone Business

Texas-based company expands offshore cargo operations while preparing for the next phase of U.S. BVLOS regulations By DRONELIFE Features Editor…

Continue Reading How Skyways Quietly Built a Global Heavy-Lift Drone Business

National Resilience Strategy Connects the Dots Behind U.S. Drone Policy

New White House strategy frames commercial drones as part of a broader effort to strengthen U.S. manufacturing, infrastructure, and supply…

Continue Reading National Resilience Strategy Connects the Dots Behind U.S. Drone Policy

Beyond the Drone: Percepto’s New Platform Brings AI to Infrastructure Inspections

Percepto launches next-gen inspection software By DRONELIFE Features Editor Jim Magill For energy companies, producing actionable data is almost as…

Continue Reading Beyond the Drone: Percepto’s New Platform Brings AI to Infrastructure Inspections

Danish Investigation Finds No Proof Drones Caused Copenhagen Airport Shutdown

Nine-month investigation underscores the need for better airspace awareness, not just more speculation News and Commentary.  A nine-month investigation into…

Continue Reading Danish Investigation Finds No Proof Drones Caused Copenhagen Airport Shutdown

Flytrex and Wing Report Zero Airspace Conflicts for Multi-Operator Drone Delivery

Flytrex says automated UTM coordination with Wing has deconflicted 100% of operations in Dallas–Fort Worth shared airspace, with zero conflicts.…

Continue Reading Flytrex and Wing Report Zero Airspace Conflicts for Multi-Operator Drone Delivery

BRINC Partnership Gives Public Safety Agencies an “Immediate Upgrade” in Incident Intelligence

BRINC and Nova Partner to Add Advanced Mapping and Thermal Intelligence for Public Safet Public safety drone manufacturer BRINC has…

Continue Reading BRINC Partnership Gives Public Safety Agencies an “Immediate Upgrade” in Incident Intelligence

Prodrone Debuts All-Japanese Industrial Drone

This article published in collaboration with JUIDA, the Japan UAS Industrial Development Association.     Aichi-based Prodrone introduces the PD4B-MS prototype,…

Continue Reading Prodrone Debuts All-Japanese Industrial Drone

Uruguayan Government Announces New Drone Dispatch Program

The Montevideo deployment, run in partnership with Uruguayan technology firm Timerix, ties gunshot-detection alerts to automated drone dispatch and live…

Continue Reading Uruguayan Government Announces New Drone Dispatch Program

Secondary Sidebar

Footer

SPONSORED

Inspired Flight Gremsy IF800 VIO F1 drones geo week

What Will It Take to Strengthen U.S. Drone Manufacturing? A Conversation with Inspired Flight’s CEO

Global Mapper Mobile data collection

Collection Ground Control Points with Global Mapper Mobile

Military Drone Mapping Solutions

How SimActive’s Correlator3Dâ„¢ is Revolutionizing Military Mapping: An Exclusive Interview with CEO Philippe Simard

Photogrammetry Accuracy Standards

SimActive Photogrammetry Software: Enabling Users to Meet Accuracy Standards for Over 20 Years

NACT Engineering Parrot ANAFI tether indoor shot

Smart Tether for Parrot ANAFI USA from NACT Engineering

Blue Marble, features global mapper, features Blue Marble

Check Out These New Features in Global Mapper v25 from Blue Marble

About Us | Contact Us | Advertise With Us | Write for Us | Privacy Policy | Terms of Service

The Trusted Source for the Business of Drones.

This website uses cookies and third party services. By clicking OK, you are agreeing to our privacy policy. ACCEPT

Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT