DJI admits that AeroScope drone tracking signals aren't encrypted, after claiming otherwise for almost a month, letting anyone track its drones and their pilots
Sean Hollister / The Verge : Tweets: @d0tslash , @chr1sa , and @starfire2258 Tweets: @d0tslash : @TC_Johnson Long story short it means that @adamlisberg needs to provide an updated comment to @StarFire2258 stating that his engineering staff misspoke & that @DJIFlySafe @DJIEnterprise @djiglobal @djisupport #AeroScope #DroneID #RemoteID packets are NOT *encrypted*. https://www.theverge.com/... https://twitter.com/... Chris Anderson / @chr1sa : This sounds shady, but reality may be less conspiratorial. It's common for Chinese engineers to be vague about how their code works, either because they copied it from elsewhere & don't want to admit that or because they don't think others will understand https://www.theverge.com/... Sean Hollister / @starfire2258 : not sure about just anyone, you'd need gear and chops to do it meaningfully, but yes: https://twitter.com/...
Context & Ripple Effects
AeroScope is DJI's receiver system for identifying nearby drones and their pilots — the product it sells to police and security teams as a way to see who is flying overhead. For nearly a month DJI maintained that those transmissions were encrypted, until researchers including @StarFire2258 pressed the company into admitting its engineering staff misspoke and the packets are readable by anyone.
The admission lands on a company whose security posture has been questioned for years: firmware patches against hackers circumventing flight restrictions back in 2017, an offline-flight mode explored after the US Army dropped DJI over cyber vulnerabilities, and a Check Point finding that its own apps exposed owner accounts and live video. With roughly three-quarters of the US consumer market per Bloomberg's profile of DJI's precarious position, a claim about its tracking signal being wrong is not a footnote.
First-order effects
- Any operator flying a DJI drone near an AeroScope-equipped site — or anyone with the right receiver — can now identify and follow specific aircraft and their pilots, turning a tool marketed for security into a stalking and targeting risk for commercial and recreational flyers.
- DJI must walk back its public encryption claim to government and enterprise customers who bought AeroScope precisely because they trusted the signal was restricted, forcing an awkward correction from the same company that told them otherwise.
Second-order effects
- Rivals selling drone-detection and Remote ID gear gain a ready-made contrast point — encrypted or independently verifiable identification becomes a sales pitch against DJI's ecosystem.
- The finding hands ammunition to US lawmakers already scrutinizing China-made drones, compounding concerns like the reported hundreds of DJI flights violating restricted Washington, DC airspace that drew senatorial attention later in 2022.
Third-order effects
- If vendor-asserted security claims keep failing public testing, drone identification standards will drift toward open protocols and third-party verification rather than trusting the dominant manufacturer's word — a structural problem for any single-vendor tracking layer.
- For DJI specifically, each verified security lapse narrows the trust margin its US business depends on, making regulatory exclusion easier to justify regardless of intent.
The trend: Drone identification and tracking is becoming a contested trust layer, where the dominant vendor's security claims are independently tested and geopolitically weaponized rather than taken on faith.