> Forums > Drohnen

DJI Go 4 App schockiert Sicherheitsforscher

Erstellt
Jul. '20
letzte Antwort Antwort
1
Aufrufe
13.7T
5
„Gefällt mir“
Abos
Noch keine
Fr., 24. Juli, 2020 um 22:22
#1

Die App sammelt Nutzerdaten und ermöglicht es den Entwicklern, Code auf das Smartphone herunterzuladen und zu installieren.

Sicherheitsforscher haben der Android-App DJI Go 4 ein besonders schlechtes Zeugnis ausgestellt. Sie dient der Steuerung von DJI Drohnen und wurde bereits über eine Million Mal aus dem Google Play Store heruntergeladen.

Die Firmen Synactive und Grimm haben die App nun einem gründlichen Sicherheitstest unterzogen und herausgefunden, dass sie bis vor Kurzem sensible Nutzerdaten an die in China betriebenen Server übermittelte. Die App nutzt dafür ein Entwickler-Kit des chinesischen Anbieters Weibo. Zudem hätten die Entwickler gut versteckte Features nutzen können, um die Nutzer auszuspionieren.

So hätten sie jegliche Programme auf das Nutzer-Smartphone herunterladen, installieren und ausführen können, heißt es in den Berichten. Dieses Vorgehen verstößt gegen die Richtlinien von Google. Zudem wurde kürzlich eine Softwarekomponente entfernt, die auf Telefondaten wie IMEI, IMSI, Mobilfunkanbieter, Seriennummer der SIM, Informationen von der SD-Karte, Sprache und Version des Betriebssystems, Displaygröße und Helligkeit, Name des genutzten WLAN-Zugangs und Bluetooth-Adressen zugreifen konnte.

Wurde die App vom Nutzer geschlossen, startet sie automatisch neu und läuft im Hintergrund weiter, heißt es in den Berichten. Sie stellt dann weiterhin Netzwerkanfragen, ohne dass Nutzer dies mitbekommen. Zudem hat man diese Methoden so verschleiert, dass sie nur durch eine aufwendige Analyse ans Licht kamen. Die Sicherheitsforscher verglichen dieses Verhalten mit jenem von Schadsoftware.

DJI wies die Vorwürfe entschieden zurück. In einem Statement heißt es, die App prüfe regelmäßig, ob sie so modifiziert wurde, dass Flugsicherheitsregeln außer Kraft gesetzt werden.



#######################

Kommentare usw. bitte in der C&M News:
https://ress.at/-news24072020222225.html


#######################


Fr., 24. Juli, 2020 um 22:24
#2

Das Statement von DJI:

Zitat:
DJI Statement On Recent Reports From Security Researchers

DJI takes the security of its apps and the privacy of customer data seriously. While these researchers discovered two hypothetical vulnerabilities in one of our recreational apps, nothing in their work is relevant to, or contradicts, the reports from the U.S. Department of Homeland Security, Booz Allen Hamilton and others that have found no evidence of unexpected data transmission connections from DJI’s apps designed for government and professional customers.

These researchers found typical software concerns, with no evidence they have ever been exploited. The app update function described in these reports serves the very important safety goal of mitigating the use of hacked apps that seek to override our geofencing or altitude limitation features. As the only major drone manufacturer with a Bug Bounty Program, we encourage all researchers to responsibly disclose security concerns about our products at security.dji.com.

We design our systems so DJI customers have full control over how or whether to share their photos, videos and flight logs, and we support the creation of industry standards for drone data security that will provide protection and confidence for all drone users.

We hope these details provide more context to understand these reports:

  • When our systems detect that a DJI app is not the official version – for example, if it has been modified to remove critical flight safety features like geofencing or altitude restrictions – we notify the user and require them to download the most recent official version of the app from our website. In future versions, users will also be able to download the official version from Google Play if it is available in their country. If users do not consent to doing so, their unauthorized (hacked) version of the app will be disabled for safety reasons.

  • Unauthorized modifications to DJI control apps have raised concerns in the past, and this technique is designed to help ensure that our comprehensive airspace safety measures are applied consistently.

  • Because our recreational customers often want to share their photos and videos with friends and family on social media, DJI integrates our consumer apps with the leading social media sites via their native SDKs. We must direct questions about the security of these SDKs to their respective social media services. However, please note that the SDK is only used when our users proactively turn it on.

  • DJI GO 4 is not able to restart itself without input from the user, and we are investigating why these researchers claim it did so. We have not been able to replicate this behavior in our tests so far.

  • The hypothetical vulnerabilities outlined in these reports are best characterized as potential bugs, which we have proactively tried to identify through our Bug Bounty Program, where security researchers responsibly disclose security issues they discover in exchange for payments of up to $30,000. Since all DJI flight control apps are designed to work in any country, we have been able to improve our software thanks to contributions from researchers all over the world, as seen on this list.

  • The MobTech and Bugly components identified in these reports were previously removed from DJI flight control apps after earlier researchers identified potential security flaws in them. Again, there is no evidence they were ever exploited, and they were not used in DJI’s flight control systems for government and professional customers.

  • The DJI GO4 app is primarily used to control our recreational drone products. DJI’s drone products designed for government agencies do not transmit data to DJI and are compatible only with a non-commercially available version of the DJI Pilot app. The software for these drones is only updated via an offline process, meaning this report is irrelevant to drones intended for sensitive government use. A recent security report from Booz Allen Hamilton audited these systems and found no evidence that the data or information collected by these drones is being transmitted to DJI, China, or any other unexpected party.

  • This is only the latest independent validation of the security of DJI products following reviews by the U.S. National Oceanic and Atmospheric Administration, U.S. cybersecurity firm Kivu Consulting, the U.S. Department of Interior and the U.S. Department of Homeland Security.

  • DJI has long called for the creation of industry standards for drone data security, a process which we hope will continue to provide appropriate protections for drone users with security concerns. If this type of feature, intended to assure safety, is a concern, it should be addressed in objective standards that can be specified by customers. DJI is committed to protecting drone user data, which is why we design our systems so drone users have control of whether they share any data with us. We also are committed to safety, trying to contribute technology solutions to keep the airspace safe.


> Forums > Drohnen

Du hast bereits für diesen Post abgestimmt...

;-)



Logo https://t.ress.at/fNFFh/


Ähnliche Themen:











Top