Share.

    5 Kommentare

    1. > What makes this different from a conventional security discovery is how it happened. Azdoufal used Claude Code to decompile DJI’s mobile app, understand its protocol, extract his own authentication token, and build a custom client.

      > The technical failure was almost comically basic. DJI’s MQTT message broker had no topic-level access controls. Once you authenticated with a single device token, you could see traffic from others device in plaintext.

      Disappointed, but unsurprised, that this is literally all it took.

      As if I needed another reason to avoid DJI products.

    2. Jmc_da_boss on

      > Claude code found an unauthed mqtt topic

      Yawn, is this what we are reporting on these days lmao

    3. Sounds like something Michael Reeves would do. But likely on purpose strictly for the absolute chaos.

    4. rollerfedora on

      This title blows. Where’s my coded robot vacuum army to clean up this dusty town?

    Leave A Reply