r/righttorepair • u/Turbulent-Equal4056 • 14h ago
DJI holds your flight telemetry hostage, passes decryption keys to 3rd-party paywalls, and forces uncertified drivers. Here is what I found.
I bought a $400 DJI drone for a tech startup project expecting basic access to flight telemetry. Instead, I discovered that DJI aggressively encrypts local logs, transmits full telemetry to their servers, passes decryption keys to third-party subscription services, and forces uncertified drivers on desktop/mobile.
The Background
As a startup engineer, I recently bought a $400 DJI drone. My objective was straightforward: extract raw spatial/geolocation data from flight logs and video for 3D reconstruction—a basic feature you can do on almost any smartphone or open-source device.
Instead of an open tool, I encountered a walled garden built on anti-consumer practices and severe data lock-in.
- Total Telemetry Gathering vs. Local Encryption
During each flight, the drone collects an immense array of sensitive spatial and environmental telemetry: exact GPS coordinates, atmospheric pressure, signal metrics, altitude, and proximity to critical infrastructure.
While DJI's cloud servers receive all of this data seamlessly, DJI encrypts the raw log files on your own local device. You own the hardware, you paid for the drone, yet you are denied direct access to your raw flight data.
- Creating the Problem, Selling the Solution (The Key Leak)
In newer firmware versions, accessing your own detailed logs locally has become practically impossible without decryption.
Here is the kicker: third-party commercial log-viewing websites somehow possess official DJI decryption keys.
To view detailed analytics of your own flights:
You must upload your files to a third-party site.
They offer a short trial before placing access to your data behind a monthly paywall/subscription.
When I confronted DJI support on how a third-party commercial platform obtained official decryption keys to unlock user data while the actual owner is locked out, their response was a generic "we don't know" before escalating and closing the chat.
- Uncertified Drivers & Software Lock-in
Attempting to connect and interface hardware (like controllers) with PCs or Android devices reveals further red flags:
Key drivers and software utilities lack proper digital security signatures/certifications for Windows and Android.
Bypassing operating system safety warnings is often required to run their software, creating software vulnerabilities and systemic security risks.
Why This Matters
Right to Repair & Data Ownership: Paying hundreds of dollars for hardware should not turn users into unpaid data miners for a corporation. Denying users access to their own data violates basic digital rights (and potentially personal data regulations like PIPEDA or GDPR).
Cybersecurity Concerns: Distributing uncertified software and keeping master encryption keys within a closed loop of "select partners" raises serious security flags.
Has anyone else in the community managed to extract raw unencrypted telemetry directly on-device without relying on paywalled third-party services? How are you handling data privacy with DJI hardware in your projects?



