Security flaws discovered at world’s largest drone maker DJI
Personal data at risk of being accessed by intruders, warn cyber experts
Cyber security experts found security flaws in the software of DJI, the world’s largest commercial drone maker, which put data collected by drones and usage patterns of individual drones at risk of being accessed by intruders.
Check Point, the California-based security company, and DJI said the bug had been fixed, but the announcement may re-ignite discussions in the US over potential risks of using drones from the China-based manufacturer.
In a pattern similar to the US government’s warnings about Chinese telecoms gear makers Huawei and ZTE, the US Army in August last year ordered an immediate end to using any DJI drones, citing classified internal research on technology threats and user vulnerabilities of DJI products.
DJI, headquartered in Shenzhen, is best known for photography and video drones used by professionals and consumers, but has also started branching out into corporate solutions.
Check Point said a probe of DJI’s infrastructure found this year that the drone maker’s user authentication systems allowed potential attackers to pose as a user and look at and steal users’ personal information, photos and video taken by their drones and information such as flight paths and GPS data.
According to the analysts, potential intruders would have been able to gain the tokens that allow users to access different applications on one platform — a software feature that has proven a security risk with other companies too.
“We are seeing over the past two years that malicious actors are exploiting tokens, for example in a Facebook incident last month involving the theft of tokens,” said Oded Vanunu, head of products vulnerability research at Check Point.
Mr Vanunu said the analysts had undertaken their investigation on their own initiative following last year’s statement from the US Army citing vulnerabilities in DJI systems.
Late last year, DJI initiated a bug bounty programme, an incentive some technology companies use to encourage benevolent hackers to help them find security loopholes.
Check Point said it had informed DJI of the problem in late March, but not taken any reward or signed any non-disclosure agreement with the Chinese company.
According to the two companies, DJI had fixed the bug by late September, six months after being notified — a period Mr Vanunu said was double the time companies needed on average to patch such problems.
In February, Denver-based security firm Kivu Consulting, hired by the Chinese drone maker, gave DJI a clean bill of health with regard to the question whether its systems might extract user data and transfer them elsewhere without authorisation.
But Kivu also mentioned at the time that it had identified certain vulnerabilities in one DJI application and on one of its outsourced servers, and notified the company.
In a joint statement with Check Point, DJI applauded the cyber security firm for demonstrating the weakness. “All technology companies understand that bolstering cyber security is a continual process that never ends. Protecting the integrity of our users’ information is a top priority for DJI,” it quoted Mario Rebello, vice-president and country manager, North America, at DJI, as saying.
DJI did not respond to a request for additional comment.