GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 07:07:02 JST Bernie Bernie

    I have an old #DJI drone from 2020, and noticed that the DJI apps are gone from the Google Play Store.

    I can go to https://dji.com and download a whopping 861MB APK, but my Pixel Phone puts up scary security warnings that I've never seen with other APKs from F-Droid.

    So now I'm not sure whether there's an actual security issue with DJI apps or it's just some US-China trade war bullshit.

    In conversation about 5 months ago from mstdn.io permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: www-cdn.djiits.com
      DJI - 公式ウェブサイト
      最新技術で可能性を秘めた未来へと導くDJI。その公式ウェブサイトで、DJI Mavic 3 Pro、DJI Mini 4 Pro、DJI Air 3、Phantomなど、一般向けドローンに関する情報を確認しましょう。Osmo Action 4やDJI Pocket 2のようなハンドヘルド製品は、滑らかな写真や動画を撮影し、RoninカメラスタビライザーやInspireといったドローンは、プロの撮影ツールとして活躍します。

    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 07:24:16 JST Bernie Bernie
      in reply to

      The absence of official statements from #DJI and Google is suspicious, and news outlets support the trade-war theory:

      barrons.com: "DJI was previously blacklisted by the US Department of the Treasury in 2021 for allegedly supporting the surveillance of the Uyghur minority in China's Xinjiang region."

      wsvn.com: US customs officials have also blocked some DJI shipments over concerns that the products might have been made with forced labor. DJI has called it “a customs-related misunderstanding.”

      In conversation about 5 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: wsvn.com
        Home
        from Shahzaib Mushtaq
    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 07:26:48 JST Bernie Bernie
      in reply to

      But there are also less conspiratory explanations:

      It's in the apple app store. [...] And while the spyware angle is 'fun,' it's a pretty goofy logical jump. The real reason appears to be a compatibility issue, "Google announced a while back that app developers will have to ensure their apps are packaged as bundles (AAB) rather than the standard APK. According to a DroneDJ reader, DJI’s SDK has a bug that prevents it from compiling in this new AAB standard."

      https://www.reddit.com/r/dji/comments/144x6c9/comment/kqj75cb/
      #DJI

      In conversation about 5 months ago permalink

      Attachments


    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 07:34:41 JST Bernie Bernie
      in reply to

      Just a bug then... seems plausible.

      But the #DJI apps have been unavailable from the Play Store since early 2021. Which SDK bug couldn't be fixed in almost 4 years?

      On the other hand, if Google had genuine security concerns with DJI's apps, why would Apple allow them?

      In conversation about 5 months ago permalink
    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 08:38:53 JST Bernie Bernie
      in reply to

      I worked on #AOSP for 3 years. It's enough to know that there are millions of devices in the wild running ancient kernels with unpatched security holes.

      Android system permissions add a second line of defense, but stores also use a combination of security reviews, developer reputation, user reports and static analysis tools to catch malicious apps and actively kick them out.

      In conversation about 5 months ago permalink
    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 09:19:08 JST Bernie Bernie
      in reply to

      Since I can't verify the stories against #DJI, I cautiously decided to keep their apps off my Pixel phone for now.

      Instead, I'll put it on my #LineageOS hacking phone, an old but trusty OnePlus 7T, which shows the same scary message, but this time I take the time to read the small print:

      "This app was built for an older version of Android and doesn't include the latest privacy protections."

      So, was that a simple API level deprecation issue that DJI could have fixed by upgrading the SDK?

      In conversation about 5 months ago permalink

      Attachments


      1. https://media.mstdn.io/mstdn-media/media_attachments/files/113/716/207/737/938/686/original/87b69b41052151b4.jpg
    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 09:29:21 JST Bernie Bernie
      in reply to

      Anyway, the app works and requested access to location and media files, both of which seem plausible for a camera drone.

      A more modern Android SDK would have allowed narrower access to videos, but anyway...

      In conversation about 5 months ago permalink
    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 09:47:22 JST Bernie Bernie
      in reply to

      Upon connecting to my old Mini 2, the app wants to install a 60MB firmware update. Ugh.

      Then comes a "FlySafe Database" update. Hmm, ok.

      After a couple of reboots, we're finally ready to fly. But now it's night, so we'll have to wait until tomorrow 😄

      In conversation about 5 months ago permalink

      Attachments


      1. https://media.mstdn.io/mstdn-media/media_attachments/files/113/716/296/038/924/656/original/b1dee2ff14bc796c.jpg
    • Embed this notice
      Bernie (codewiz@mstdn.io)'s status on Thursday, 26-Dec-2024 14:14:00 JST Bernie Bernie
      in reply to
      • Support GrapheneOS 667

      @SupportGrapheneOS_667 "The analysis of the DJI GO 4 app for Android revealed that the security issues are not there by mistake." 😰

      In conversation about 5 months ago permalink
    • Embed this notice
      Support GrapheneOS 667 (supportgrapheneos_667@social.tchncs.de)'s status on Thursday, 26-Dec-2024 14:14:02 JST Support GrapheneOS 667 Support GrapheneOS 667
      in reply to

      @codewiz

      https://www.bitdefender.com/en-us/blog/hotforsecurity/popular-chinese-drone-android-app-suffers-major-security-issues-investigation-finds

      In conversation about 5 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: blogapp.bitdefender.com
        Popular Chinese Drone Android App Suffers Major Security Issues, Investigation Finds
        from Silviu STAHIE
        The Android application used by the Da Jiang Innovations (DJI) to control their drones has a potential vulnerability that would give the company access to details about the users, security researchers have discovered.
    • Embed this notice
      Support GrapheneOS 667 (supportgrapheneos_667@social.tchncs.de)'s status on Thursday, 26-Dec-2024 14:14:03 JST Support GrapheneOS 667 Support GrapheneOS 667
      in reply to

      @codewiz

      https://drones.stackexchange.com/questions/2209/how-come-the-dji-fly-app-is-not-in-google-play-store

      In conversation about 5 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: cdn.sstatic.net
        How come the DJI Fly App is NOT in Google Play Store?
        Just got a DJI Mini 2, and followed the instructions to get it up and flying, but the required DJI Fly App was not in Google Play Store. I downloaded it, installed it, and successfully flew with it...

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.