[HN Gopher] DJI - The ART of obfuscation
___________________________________________________________________
DJI - The ART of obfuscation
Author : PaulHoule
Score : 211 points
Date : 2024-02-20 07:31 UTC (15 hours ago)
(HTM) web link (blog.quarkslab.com)
(TXT) w3m dump (blog.quarkslab.com)
| Aurornis wrote:
| > The packer contains some countermeasures, as partially
| described in this issue, to prevent the use of dynamic tools.
| Fortunately, these can be easily bypassed.
|
| Does anyone have more details on this step? The linked issue is
| devoid of information and was closed because the person refused
| to release the technique publicly.
| romland wrote:
| It's a rabbit hole, but try googling "anti-debugging" (you may
| want to include "ptrace" or not). It's only if you are curious
| about it more in general, if you are wondering about this
| specific protector (secneo?), then that won't help you much,
| sadly.
| supriyo-biswas wrote:
| As I understood the protection talked about here is a bit
| different from ptracing your own processes, which is already
| talked about just above grandparent's quoted statement.
|
| On that note, I'll just remark how RE tutorials avoid talking
| about anything but the basics, and the advanced writeups
| handwave away the challenging parts, leaving a major void for
| learners.
| weinzierl wrote:
| I found the courses from Josh Stroschein pretty good in
| that regard.
| pbhjpbhj wrote:
| The issue says at the end what worked for one respondent.
| echelon wrote:
| With cheap drones appearing to be critical to the future of
| warfare, is there a chance that the US will develop a domestic
| drone industry that rivals China's, or has that ship sailed?
| sschueller wrote:
| Maybe we should stop killing each other instead of banning
| drones.
|
| Next thing will be assassinating people with their own phone by
| causing it to blow up next to their head.
|
| The tool isn't the problem, the problem is that "we" still
| think killing each other is some sort of solution.
| bandergirl wrote:
| > Maybe we should stop killing each other instead of banning
| drones.
|
| Wishful thinking. Always have, always will. War is even
| "legal", think about that, no repercussions for NATO
| countries.
| mewpmewp2 wrote:
| Okay and how do we stop killing each other?
| cgio wrote:
| It's simple, you stop first /s
| numpad0 wrote:
| Ah, the "stop resisting" approach.
| thimp wrote:
| Ban anyone over the age of 60 from politics. It's all
| senile old men trying to kill each other with younger
| people.
| master-lincoln wrote:
| Additionally ban all males from positions of power
| pjc50 wrote:
| > Next thing will be assassinating people with their own
| phone by causing it to blow up next to their head
|
| I don't know if this was an intentional reference or not, but
| that has definitely already been done (with a rigged phone).
| Plus the widespread use of phone position data for targeting.
|
| > the problem is that "we" still think killing each other is
| some sort of solution
|
| The problem is that violence _works_ against everything
| except more violence.
| lazide wrote:
| Even then, violence works in that it decides a winner - one
| way or another.
|
| It's not like Japan or Germany were going to wave a white
| flag just because someone finally convinced them they were
| wrong.
| ipsum2 wrote:
| There's plenty of military drones companies, the US military
| has the budget for them. But now I'm wondering, who would win,
| 1,000 military drones or 1,000,000 consumer DJI ones?
| sofixa wrote:
| "Quantity has a quality of its own". Consumer DJI Drones are
| useless in a fight (good only for reconnaissance or maybe
| crashing into military drones to disrupt them), but Russia is
| showing that drones can be made on the cheap (e.g. there was
| footage of a drone of theirs using a plastic soda bottle as
| the fuel reservoir) and still be disruptive.
| sverhagen wrote:
| Why are they useless? Could they not carry a payload, and
| swarm their way past defenses that aren't equipped for
| "volume"?
| usrusr wrote:
| Getting signal through a hostile radio environment comes
| to mind. But as it stands now it looks like this might be
| a field were a hundred "macguyvers on typewriters"
| adapting consumer drones are more effective than a
| Shakespeare trapped in the bowels of the military
| industrial complex.
| lazide wrote:
| Even basic consumer drones use frequency hopping and have
| relatively complex signal integrity logic - necessary
| even for using 'free' frequencies like 2.4 and 5.4 ghz in
| typical urban environments. And they're pretty good,
| frankly.
| 15155 wrote:
| "Frequency hopping" does nothing when your adversary can
| blow out the entire 2.4 and 5.4GHz bands, even before
| getting into sophisticated radio-specific attacks.
|
| Urban radio environments are crowded, not actively
| hostile.
| lazide wrote:
| And yet, plenty of field success right now with consumer
| (even basic amateur level) drones.
|
| The issue with high energy jamming (broad frequency band
| denial) is it makes your jammer a super tempting (and
| easy) target for a HARM or equivalent, and consumes quite
| a bit of power. If someone is actively denying such a
| wide frequency band, any high school level electronics
| student can design a pretty effective seeker.
|
| And the whole 'radio power drops off as a cube of the
| distance' thing means the equipment needs to be pretty
| close to operations, so it's going to get attacked pretty
| often.
|
| The noise level in a typical urban environment from wifi
| is already pretty terrible, 'hostile' or not. Way more
| terrible than a typical remote environment, which is
| where these drones are being used, unless there are
| active countermeasures pretty close.
|
| Counter measures, counter-counter measures, etc. But I'm
| not seeing much mention of effective jamming happening
| in-theatre right now.
| gpderetta wrote:
| They do. In fact they graduated from simply dropping
| grenades on soldiers and IFVs to suicide roles taking out
| actual tanks. I'm not sure actual DJIs are being used in
| suicide missions or custom, still inexpensive, drones.
| callmemclovin wrote:
| The video footage of suicide drones you can find on
| r/combatfootage is nearly always from custom drones, the
| giveaway is the analog video transmission. As the poster
| before said, DJI drones are only used for reconnaisance
| (for example DJI Matrice), where high-quality digital
| video transmission (and thermal image cameras) are very
| useful.
| rasz wrote:
| Plenty of DJI grenade drops (auxiliary light), both from
| cheap mavics and expensive matrices.
| jdietrich wrote:
| DJI drones are ubiquitous on both sides in the Ukraine
| conflict. They have excellent cameras and long flight
| durations, which make them an ideal aerial observation
| platform. The battlefield is a very different place if you
| can't hide behind terrain and have to assume that if you
| can see the sky, then you can be seen by the enemy. These
| drones have drastically improved the effectiveness of
| conventional artillery, because you can seek out targets
| and get real-time reports on exactly where you shells are
| landing. Consumer/prosumer drones are vulnerable to jamming
| or being shot down, but they're also cheap enough to be
| essentially expendable. Ukraine are reportedly losing
| 10,000 drones a month, but that's a bargain for what they
| achieve on the battlefield.
|
| DJI drones fitted with grenade-dropping mechanisms have
| been used extensively and still see some use, but DIY FPV
| drones are now the preferred offensive weapon, used in a
| kamikaze role as a kind of cheap guided missile. They're
| cheaper, faster and more agile than the DJI drones. A good
| FPV pilot can hit the weak spots on a moving tank, or fly
| through a narrow opening to hit troops sheltering in a
| bunker. They're invariably used with DJI drones in hunter-
| killer teams, with a DJI drone acting as a spotter for an
| FPV pilot.
|
| The sound of a DJI drone is known to everyone on the front
| line and it means exactly one thing - that you need to find
| hard cover _now_. If you can hear it, then chances are that
| it has spotted you, the pilot has passed on your
| coordinates and a kamikaze drone or an artillery shell is
| already flying towards you. If you ignore it or take pot
| shots at it, then you 're gambling with your life.
|
| https://www.youtube.com/watch?v=NjsemcB7I9o (subtitles
| available)
| maxglute wrote:
| UKR also has limited access to latest PRC drones, DJI T60
| is $8000 consumer agriculture drone with 60kg payload and
| AESA radar. That's enough to start swarming and engaging
| almost any ground vehicles.
| helsinkiandrew wrote:
| There's a coalition to supply Ukraine with a million drones
| (although that figure might be exaggerated) I'm guessing
| they'll be slightly cheaper than the Black Hornet ($100K+)
|
| https://breakingdefense.com/2024/02/european-coalition-
| bids-...
|
| https://en.wikipedia.org/wiki/Black_Hornet_Nano
| TeMPOraL wrote:
| In what volume of space? You don't want them to be packed
| densely enough that the enemy can fire a buckshot in a random
| direction and shoot down two dozen drones.
| ipsum2 wrote:
| It's an open ended question :). It's reasonable to assume
| both sides are intelligent and will do whatever it takes to
| win.
| hoseja wrote:
| None of those are cheap FPV quadcopters, are they?
| 15155 wrote:
| 1,000 electronic warfare-hardened drones vs. 1,000,000 drones
| using simple, documented radio on ISM bands?
|
| Exactly 0 of those 1,000,000 consumer drones will be flying
| in US operating areas.
| ipsum2 wrote:
| At what distance do those jammers work?
| Megustatrw wrote:
| Building drones is very easy from a base requirement point of
| view.
|
| And the components are easy to buy as most if not all have
| plenty of other use cases.
| sagz wrote:
| There's also something fishy about DJI in that their Android app
| to control their drones is intentionally not listed on the Play
| Store. I've never seen a manufacturer require side loading.
|
| Anyone know why it's not on the Play Store? (On iOS it is on the
| App Store, well because there isn't another way till this DMA
| thing kicks in)
| bandergirl wrote:
| > Anyone know why it's not on the Play Store?
|
| Can't think of any reason that isn't sketchy. The article gives
| a clue already.
|
| If the app passes Apple's review, then it could pass Google's
| review.
| rnmmrnm wrote:
| see Epic suit i guess.
| sschueller wrote:
| You can side load android, you can't side load Apple (without
| jailbreak). Having to deal with two review processes instead
| of just one saves money and headaches. Also since they are
| dealing with US sanctions they probably had to fill out all
| kinds of stuff and submit that to Apple which they would also
| have to do for Google but again, they can just side load
| instead.
| LoganDark wrote:
| > You can side load android, you can't side load Apple
| (without jailbreak).
|
| Did Cydia Impactor stop working or something? Sure you need
| a developer account, but then you can use the account to
| sideload any third-party IPA.
| malermeister wrote:
| Here's a dark conspiracy theory for ya: Consumer drones
| (including DJIs) are being used in warfare more and more
| frequently, including the war in Ukraine.
|
| The Chinese government, while not openly supporting Russia, has
| been repeatedly accused of covertly doing so. Imagine what kind
| of harm a device used for reconnaissance could do if it
| secretly works for the other side.
| sofixa wrote:
| DJI's app wasn't on the Play Store for years before Russia
| invaded Ukraine, so that's somewhat unlikely.
| sannee wrote:
| If my Googling is correct, it seems to have been removed
| around 2020-2021. Russia first invaded Ukraine in 2014
| though.
| swells34 wrote:
| China effectively banned the Play Store in 2010. Your
| Google-fu leaves something to be desired.
|
| https://cybernews.com/resources/how-to-access-google-
| play-ap...
| spacebanana7 wrote:
| I don't have a source to hand, but I've heard their drones
| were used in Syria for several years before Ukraine
| WhereIsTheTruth wrote:
| Are you suggesting we should ban Starlink because it is used
| in warfare both in Ukraine and in the middle east?
| sverhagen wrote:
| If you're very principled about it: possibly, probably,
| yes?
|
| Otherwise, it might depend whose side you're on?
| travoc wrote:
| Hah, everybody is principled until the first bullet
| whizzes by.
| dylan604 wrote:
| It's not any different from people that do not shop at
| WalMart, Amazon, etc because of differences with the
| corporation. It's not hard once you quit making excuses
| randall wrote:
| https://twitter.com/AustingrahamZ1/status/10293854972133662
| 7...
| WhereIsTheTruth wrote:
| Perhaps i expect too much from ordinary people
|
| https://www.businessinsider.com/elon-musk-tesla-spacex-
| secre...
| L_226 wrote:
| no even that - DJI are potentially collecting thousands if
| not millions of hours of telemetry about how small drones are
| used in real-life combat. This is absolutely invaluable to
| developing countermeasures or optimising their own offensive
| platforms.
| tomaskafka wrote:
| Also mapping all of the western world, and sending the most
| detailed 3d maps of western infrastructure to servers of a
| company that's a part of the chinese military complex.
| Staple_Diet wrote:
| That's not a theory as much as it is an acknowledged fact,
| and why DJI are banned from many 5-Eyes facilities.
| yard2010 wrote:
| No conspiracy here, just hard cold truth.
| jijijijij wrote:
| I very much assume, involved militaries are aware of this
| possibility and are not blindly trusting Chinese consumer
| drones right off the shelves, have soldiers in every unit
| install random sideloaded apps. Lol.
|
| They likely flash verified firmware and use a verified app
| version, not the latest one from DJI's website... Maybe they
| have their own code, by now. _Especially_ with reconnaissance
| drones. The Ukrainians probably need to do this, not just
| because of the obvious possibility of a "backdoor", but RF
| adaptability in the EM warfare situation.
|
| I would worry more about contractor John Doe bringing a
| compromised private phone to a government or industrial
| facility. Not sure a highres video feed from a drone could be
| easily exfiltrated unnoticed, anyway, since they usually
| don't come with WWAN hardware built-in. But the phone itself
| would be able do all sorts of reconnaissance and become an
| attack vector in a sensitive context. Then again, this is not
| specific to drone (software), but all untrusted software
| people install.
| WhereIsTheTruth wrote:
| When you are leader in the market, you want to make sure your
| competition isn't able to reverse engineer your products,
| including google
| zakki wrote:
| You meant google can't buy DJI product and Android phone to
| reverse engineer the product?
| squarefoot wrote:
| This, and also they still have the firmware which stays in
| the drone hardware and very likely is where the most
| important code is. Cloning the app wouldn't give much
| advantage to a competitor.
| WhereIsTheTruth wrote:
| That's the point, they are not forced to remove some
| protections to please google and whoever is running Google
|
| https://qz.com/1145669/googles-true-origin-partly-lies-in-
| ci...
|
| Drone business is important to the military industrial
| complex
|
| This however is akin to malware development, i wouldn't
| want to install such software
| nulld3v wrote:
| Google accepts obfuscated apps though (even ones that are
| heavily obfuscated). I've never heard of anyone getting
| their app rejected due to obsfucation.
| danpalmer wrote:
| Why would sideloading prevent Google from reverse engineering
| the product?
| secretsatan wrote:
| They recently dropped support for the iOS SDK and stopped
| releasing new versions, they've been moving away from iOS in
| general in favour of using their own controllers.
|
| That they don't want to release through the official android
| app stores for a free app is a bit sus.
| londons_explore wrote:
| The play store is banned in China. So sideloading/alternate app
| stores are the main way most users install apps there.
|
| Their china-based engineers might not even consider it
| important to support the play store.
|
| As a non-US citizen, I frequently see how US based engineering
| teams just don't understand local markets/customs. This is just
| being on the other side of that.
| BoiledCabbage wrote:
| And yet tons of other apps from China seem to make it to the
| play store. And it's not like DJI isn't aware of how many
| devices they sell overseas.
|
| It's almost as if it were intentional.
| lazide wrote:
| Android isn't a huge market segment for high end drones,
| and when it is, it's almost always purpose
| specific/dedicated devices. 'Juice not worth the squeeze'
| and all.
| vetinari wrote:
| Their dedicated controllers use AOSP under the hood.
|
| But since they control entire device, there's no need for
| Play Framework, Play Store and whatever is needed for
| certification just to ship it.
| lazide wrote:
| Yup. Aka dedicated devices.
| dheera wrote:
| > And yet tons of other apps from China seem to make it to
| the play store.
|
| The Play Store versions of some of those apps are likely
| not the same as the side-loaded version.
| dylan604 wrote:
| It's precisely those differences that make me concerned
| about what they are doing with the side loaded versions.
| m-p-3 wrote:
| We clamped down our MDM policies to disallow sideloading on
| corporate devices, when we asked DJI when they planned to
| submit their app on the Play Store and they basically told us
| never, we decided to remove all DJI drones from our fleet.
| neom wrote:
| What did you replace the DJI drones with?
| ikekkdcjkfke wrote:
| Buy cheap dedicated motorolas?
| dheera wrote:
| I don't use their app at all, I just use the DJI RC. In any
| case I wouldn't recommend controlling a drone from a phone
| running a bunch of background tasks that may pop up
| notifications and phone calls while you're trying to dodge
| obstacles.
| dylan604 wrote:
| do not disturb mode is your friend here, or even airplane
| mode
| rideontime wrote:
| Wouldn't airplane mode prevent you from communicating with
| the drone?
| dylan604 wrote:
| why? it just turns off the cell radio. wifi/bluetooth is
| still enabled, or at least they can be re-enabled if they
| are turned off.
| rideontime wrote:
| Don't people typically fly their drones outdoors?
| dylan604 wrote:
| you're asking questions like a bot that was just brought
| on line.
|
| i would suggest you familiarize yourself with the
| quantity of information available online. all of this
| information is available on the vendor's website.
| dev1ycan wrote:
| To submit an app you'd have to give free access to your source
| code to a potential rival, DJI is a huge brand, it'd be easy
| for the US government to basically get access to such code and
| clone it.
|
| I'm surprised people really think it's anything other than
| wanting to protect their IP.
| JoachimS wrote:
| Very impressive analysis!
|
| Interesting that they go through all that work to protect against
| modern deobfuscation attacks and reversing - and then use RC4 and
| MD5. They may be ok in this context, but the choice is sort of
| odd.
| robinduckett wrote:
| I'd love to see some analysis of their OTA transmission formats.
| Currently the DJI headsets must communicate with the drone
| somehow in order to receive the video stream - this means the
| headset is constantly transmitting to the drone and this can
| effect other people even on different frequencies flying drones
| and it makes spectating rather difficult (and racing in groups
| impossible, not that you would want to race DJI drones as the
| variable latency does not really lend itself to drone racing).
|
| There is already some signal analysis done by those in the field
| on Youtube but an open source method to pull packets from
| transmitting drones and redisplay them without transmitting to
| the drone would be wonderful.
| 05 wrote:
| > can effect other people even on different frequencies flying
| drones and it makes spectating rather difficult (and racing in
| groups impossible,
|
| It's a solved problem, spectating is supported out of the box
| and frequency bands have been public for a long time.
|
| Here's a JB video with all you need to know to coexist with
| analog: [1] Here's Oscar Liang's frequency chart (updated for
| O3): [2]
|
| [1] https://youtu.be/P0b99JDcUQs
|
| [2] https://oscarliang.com/fpv-channels/
| rasz wrote:
| Afair DJI drone link is modified LTE radio.
| tripdout wrote:
| I thought it was essentially WiFi.
| dji4321234 wrote:
| Very old DJI drones were 5Mhz WiFi (Atheros). Newer ones
| are LTE based (OcuSync).
| dji4321234 wrote:
| > pull packets from transmitting drones and redisplay them
| without transmitting to the drone
|
| You can see what happens when you try this by putting DJI FPV
| Goggles in Audience Mode. It's horrible and not suitable for
| flying. The DJI link is fundamentally two-way and aggressively
| uses sounding and HARQ.
|
| The solution to flying with DJI FPV users at your field is to
| not use Raceband 6 at all (DJI uses this for link negotiation),
| and otherwise look up the Raceband to DJI correlation chart and
| allocate separate channels as usual.
| Fb24k wrote:
| Stuff like this is is part of the reason the US DoD banned DJI
| drone usage in 2020, looks like the ban will likely extend to all
| federal agencies this year: https://www.govtech.com/em/emergency-
| blogs/disaster-zone/fed...
| dontlaugh wrote:
| The actual reason is jingoism, regardless of excuse.
| dan-0 wrote:
| Oh come on. It definitely couldn't be that it's surveillance
| technology produced in a country known on a massive scale for
| stealing information via electronic means, especially against
| the US, right?
|
| Your statement reflects little knowledge on US national
| defense matters, shows a lack of knowledge about the
| technology, ignores recent historical knowledge of China's
| hacking efforts against the US, and provides zero information
| to back up your claim.
| casercaramel144 wrote:
| >a massive scale for stealing information via electronic
| means
|
| You mean the NSA?
|
| https://en.wikipedia.org/wiki/The_Shadow_Brokers
|
| https://en.wikipedia.org/wiki/Equation_Group
|
| https://en.wikipedia.org/wiki/PRISM
|
| Surely we apply the same level of scrutiny to everyone
| right? Don't pretend that this is about China being a bad
| actor in the space. Everyone is a bad actor here, and
| arguably the NSA is _worse_.
|
| I'm not trying to say DJI shouldn't be banned for
| government applications. It definitely has a hardware kill
| switch back home. But let's not pretend that facebook et al
| + Google + Apple are any different.
| dji4321234 wrote:
| > But let's not pretend that facebook et al + Google +
| Apple are any different.
|
| Were we pretending this? Was anyone pretending this? It
| would likewise be quite wise for China to ban the use of
| products made by these companies in their own sensitive
| federal applications, and my understanding is that
| broadly, they have.
| throwaway4good wrote:
| It is pretty standard stuff to obfuscate your code when you
| distribute your app to a phone to protect against decompiling
| and sometimes just to save space.
| luma wrote:
| It's also pretty standard stuff to obfuscate your code when
| you're doing something dirty. The problem with obfuscation is
| that, for the end user, there's not a great way to determine
| which use case the developer had in mind which means one
| should probably approach such an application with extreme
| caution.
| ryandrake wrote:
| It's user-hostile no matter what the intentions are. In an
| ideal world, the market would punish companies that treat
| their own users as attackers.
| crimsontech wrote:
| How is it user-hostile to obfuscate your source code? It
| doesn't change the user experience, just makes it more
| difficult to reverse engineer which would be against the
| EULA anyway.
| EMIRELADERO wrote:
| Most anti-reversing clauses in EULAs wouldn't get past a
| court because of public policy concerns (i.e, recovering
| the systems/methods/algorithms used by an app is a
| legitimate form of competition and we don't want
| copyright or contract law to get in the way of that)
| dev1ycan wrote:
| mommyyy dji didn't upload their source code to github so we
| could clone it then ban them on the grounds of national
| security, mooooom!!1
|
| I'm sure TSMC also not bringing their latest node tech to
| their US fabs _also_ happens to be because they 're doing
| something dirty! oh wait, corporations want to protect
| their IP, and countries have time and time again proven
| that they're willing to enter the private business to give
| their country an edge.
| josephcsible wrote:
| Most of the kinds of obfuscating DJI is doing make the app
| take up more space.
| makeitdouble wrote:
| That ban wouldn't be lifted if DJI rrleased all their source
| code, showed their belly and wagged their tail.
|
| I mean, the central point is straight where everyone's
| focusing:
|
| > But broadly speaking, U.S. drone makers say they expect to
| see a sales bump this year even though the new ban on federal
| purchases is not yet in effect.
| miki123211 wrote:
| I wonder if this obfuscation was implemented at the behest of
| some government or other to make entering no-fly zones much
| harder. It seems overkill for something that's otherwise such a
| simple app.
| londons_explore wrote:
| Also, I think the 'no fly zone' stuff is entirely implemented
| on the drone itself and the app could be fully opensource if
| needed without compromising that functionality.
| csomar wrote:
| This feels to me like an order from a Chinese project manager to
| have their code "obfuscated". The developers had to comply and
| put something that satisfies him. This doesn't matter in the
| least, and the conspiracy theories about this being used for
| military or intelligence purposes are ridiculous. Any obfuscation
| will be overcome and the only way around it is for DJI to release
| both their own hardware and software.
| matsemann wrote:
| 10 years ago I "reverse engineered" the protocol of their
| controllers so that I could use it for drone simulators on my PC.
| When plugging in the controller to update the firmware, I noticed
| their software could read stick positions. So I just dumped all
| the data on the serial and looked at what changed and what
| remained static when moving one stick all the way to the left,
| right etc. And just copied the patterns of whatever the software
| used to prod the controller. Then I used a joystick library to
| emulate my readings as an xbox controller.
|
| https://github.com/Matsemann/mDjiController/
| sverhagen wrote:
| I worked for a company that had a cloud solution to manage
| drone fleets, and we tried ingesting log files. We had a small
| team working on that, and we were grateful to use and/or learn
| from what was available in GitHub repositories like yours
| (although I don't recognize yours specifically). There was a
| lot of trial and error, a lot of magic numbers, and stuff was
| still wrong half the time. And then... they leveled up the
| encryption of the log files, and it was game-over. Their new
| solution gave limited access to vendors willing to work through
| the legalities. If I remember correctly, it required the log
| file, or at least parts of it to be uploaded to get the keys to
| unlock it. Not something US companies, like big utilities, were
| very keen on.
| eigenvalue wrote:
| Seems like it's basically impossible to ever prevent this kind
| of black box strategy. It's similar to the problem of secure
| DRM on videos-- at some point you need to decode the stuff to
| play it on the screen, and you can intercept it at that point.
| They need to send the commands to the drone in a timely way for
| it to work, and you can control those commands and know what
| commands you're sending. Although I guess they could XOR that
| command stream with some kind of one-time pad or something so
| you can never mimic it going forward, so maybe not? But
| whatever the stream of bits getting XORed to the command
| stream, that would need to exist in the memory in the drone
| unit, so with enough persistence and skill maybe you could
| crack it for a particular drone at least. I guess all they need
| to do is make it uneconomically hard to do for an arbitrary
| individual drone unit.
| MartijnBraam wrote:
| This looks like the DJI can bus protocol used for the accessory
| ports on at least the DJI RS2. There's some documentation for
| the headers in the protocol in the DJI RS2 SDK pdf.
| dji4321234 wrote:
| It's called DUML/DUSS, there's a lot of documentation about
| it in http://github.com/o-gs/dji-firmware-tools
| matsemann wrote:
| Cool that it's now a usable SDK. Afaik there was nothing when
| I made this a decade ago, but perhaps I didn't look in the
| correct places or asked the correct people.
| m463 wrote:
| I bought a DJI mavic when it first came out - and it would not
| allow me to fly it - even with the small 2-stick controller -
| without installing the app, which required an account.
|
| I sent it back.
|
| Later, I found out HOW MUCH data was sent back to DJI. It was
| basically everything. It was sent to a variety of sites, with
| stuff like flight profiles, images, all kinds of stuff.
|
| I think open source drones are the answer.
___________________________________________________________________
(page generated 2024-02-20 23:01 UTC)