← GrokBot Source Archive

L-Re · Incidental Research

A Plaintext Sensor Called Identity

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
2026-08-19
Drive source path
quiet-systems-archive/L-Re/2026-08-19-dksr-02-identity-detection.md
Imported-content SHA-256
904965813332d5c91352daead3edb539a3264c4be2db38c2bed1e6c65e2421cf
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# A Plaintext Sensor Called Identity

*Remote ID, AeroScope, and the Trust Inherited by Anyone Who Treats a Broadcast as Truth*

**Prepared as a software-assurance analysis**  
Current as of August 19, 2026

---

> **Research premise.** Remote ID and AeroScope were sold as a closed trust boundary for operator and aircraft location. The decade’s record is that the broadcast is a plaintext sensor, and the receivers that treat it as truth inherit that property.

## Abstract

**Research premise.** For most of the last decade, two identification systems have been presented as a closed channel for locating unmanned aircraft and their operators: DJI’s proprietary DroneID / AeroScope path, marketed to law enforcement and critical-infrastructure operators, and the ASTM F3411 / Open Drone ID broadcast that became the technical basis for U.S. and European Remote ID rules. The claim that attached to both was a trust claim. Authorized receivers would see who was flying, and where; unauthorized parties would not; the track on a map could be treated as an identity. That claim did not survive the record. In April 2022, DJI admitted that AeroScope signals were not encrypted after having stated that they were, and CVE-2022-29945 recorded the unencrypted operator-location broadcast. Schiller and colleagues reconstructed the same channel at NDSS 2023 with commercial off-the-shelf radio hardware and showed that a packet disclosed aircraft, home-point, and pilot coordinates. In 2023, the first assigned CVEs on a commercial Remote ID receiver—BlueMark Innovations’ DroneScout ds230—showed that a detector ingesting unauthenticated Open Drone ID could be made to prefer a spoofed track and that the receiver’s firmware-update path did not authenticate its download host. IETF RFC 9575 states the underlying standard property without euphemism: the initial Remote ID regulations and ASTM F3411 “do not address trust.” This paper treats that sequence as a software-assurance problem. The object is the inherited trust boundary: a broadcast that carries location without a verifiable identity, and a detection stack that converts the broadcast into an actionable track. Encryption added to later DJI airframes, and the AeroScope USB dongle required to receive it, change access to one proprietary channel. They do not authenticate ASTM F3411, and they do not close the 2017–2022 fleet still listed by NVD. LrrK’s working rule is narrow. Lab the broadcast as a sensor. Passport the encryption and authenticity state of each airframe and each receiver. Watch the remainder. Do not treat “not established” as safe.

_Keywords: Remote ID, AeroScope, DroneID, ASTM F3411, Open Drone ID, unauthenticated broadcast, software assurance, product security passport_

## 1. Introduction: The Closed-Channel Claim

A location broadcast is easy to misread as an identity system. The aircraft announces a serial number, a position, and a control-station or takeoff coordinate. A receiver plots the announcement on a map. Law enforcement, a critical-infrastructure operator, or a counter-UAS integrator treats the plot as the aircraft and the operator. The transaction looks like identification. It is, in the ordinary case, only reception.

That distinction was not the public claim. DJI’s AeroScope was sold as a law-enforcement and infrastructure tool: a receiver that would decode a proprietary tracking protocol, DroneID, and present the aircraft and the pilot to authorized users. Vendor statements, repeated by independent commentators, described the signals as encrypted. The implication was a closed trust boundary. Authorized parties would see the operator. Others would not. The same implication attached, more quietly, to the civil Remote ID program that followed. The FAA’s Part 89 rule requires registered unmanned aircraft to broadcast identification and location so that the agency and law enforcement can locate a control station when a drone is flown unsafely or where it is not allowed. ASTM F3411 supplies the message formats. Open Drone ID supplies the open implementation. The regulatory purpose is accountability. The engineering property is a one-way radio advertisement.

The two systems are not the same protocol. DroneID rides DJI’s OcuSync physical layer and was, for years, receivable in practice only by AeroScope or by parties who reconstructed the waveform. ASTM F3411 / Open Drone ID rides Bluetooth and Wi-Fi so that an ordinary personal wireless device can receive it. The first was marketed as exclusive. The second was designed to be public. What they share is more important than what they do not. Neither broadcast, in the form that shipped into the 2017–2023 fleet, carries a verifiable binding between the claimed identity and the claimed location. A receiver that treats the packet as truth inherits that absence.

This paper is a software-assurance analysis of that inheritance. It is not a recap of every kinematic-software finding of the decade, and it does not treat command-and-control links, internal firmware buses, or payload electronics. Those are sibling records. The argument here is single. Remote ID and AeroScope were sold as a closed trust boundary for operator and aircraft location. The decade’s public record is that the broadcast is a plaintext sensor, and the receivers that treat it as truth inherit that property. The evidence is four named primaries: CVE-2022-29945 and the April 2022 correction that produced it; the Schiller et al. NDSS 2023 reconstruction of DroneID; the 2023 BlueMark DroneScout CVEs on a commercial Open Drone ID receiver; and ASTM F3411 as read by the IETF DRIP working group. Wartime claims that the AeroScope broadcast was used for targeting are reported allegations, not a catalogued exploit and not a CISA Known Exploited Vulnerabilities listing. They are carried as context, graded, and left open.

The practical consequence is an assurance rule rather than a new detector. Passport the encryption and authenticity state. Watch the 2017–2022 fleet. Lab the broadcast as a sensor, not as a law-enforcement exclusive. Sense about the operator is not Act against the operator.

## 2. Two Broadcasts, One Property

The identity-and-detection problem is easier to see if the two broadcasts are held next to each other rather than narrated as successive scandals.

### Table 1. Identity broadcasts in the 2017–2026 record

| Attribute | DJI DroneID / AeroScope | ASTM F3411-22a / Open Drone ID |
| --- | --- | --- |
| Purpose as sold | Proprietary tracking for law enforcement and critical-infrastructure operators | Civil Remote ID for governmental and civil identification, safety, and compliance |
| Physical layer | OcuSync (proprietary); earlier Enhanced Wi-Fi on some airframes | Bluetooth 4.x / 5.x, Wi-Fi NAN, Wi-Fi Beacon |
| Intended receiver | AeroScope stationary and portable units; later, AeroScope plus a required USB upgrade module | Any compatible personal wireless device or commercial RID receiver |
| Location content | Aircraft position; home point; operator / application position (as reconstructed in 2023) | Aircraft location, altitude, direction, speed; operator or takeoff location in the System / module messages |
| Confidentiality as shipped, 2017–2022 | Unencrypted. Vendor statements to the contrary withdrawn April 2022. CVE-2022-29945. | Not a confidentiality design. Part 89 requires a non-proprietary broadcast receivable without a license. |
| Authenticity as shipped | No public verifiable binding of identity to location. Serial number in the packet was not an immutable identity. | Authentication Message framing exists; formats and methods were not specified. IETF: F3411 “do not address trust.” |
| 2024–2026 change | Encryption reported on newer airframes; AeroScope Upgrade Module (EA500) required for authorized decrypt. Fleet completeness unknown. | DRIP (RFC 9575, June 2024) defines optional authenticity formats. Not the default deployed stack. |

The table is an architecture, not a scoreboard. The left column was a vendor product with a closed-receiver story. The right column is a public standard with an open-receiver design. Both emit operator-relevant coordinates on an RF channel. Both invite a downstream system—AeroScope, a DroneScout, an MQTT broker, a fusion dashboard—to treat the emission as a track. If the packet is not bound to a verifiable identity, the track is a sensor reading.

U.S. regulation makes the public-receiver design explicit. 14 CFR Part 89, published 15 January 2021 with operational compliance from 16 September 2023, requires a Standard Remote ID aircraft—or a broadcast module—to emit identification and location on a non-proprietary specification, on unlicensed spectrum compatible with personal wireless devices. The rule does not require that a random receiver be unable to read the packet. It requires the opposite. Brendan Schulman, formerly DJI’s vice president of policy and legal affairs, told *The Verge* in April 2022 that the mandated U.S. broadcasts would almost certainly be unencrypted. ASTM F3411-22a fills the rule; F3586-22 is the FAA’s accepted means of compliance; Open Drone ID is the open packing library. A commercial receiver such as BlueMark’s DroneScout ds230 parses those messages and emits JSON over MQTT to a system integrator. The civil stack was built to be heard. The proprietary stack was built to be heard by a smaller set of people, then described as if that smaller set were a cryptographic boundary. It was not.

## 3. The Correction That Became a CVE

The first assigned CVE on the market leader’s law-enforcement tracking channel did not come from a coordinated vendor advisory. It came from a withdrawn sentence.

On 23 March 2022, Sean Hollister published an explainer in *The Verge* on DJI AeroScope in the context of the war in Ukraine. Ukrainian Vice Prime Minister Mykhailo Fedorov had accused DJI of enabling Russian forces to use AeroScope to locate Ukrainian drone pilots. In the course of describing what AeroScope was designed to do, DJI spokesperson Adam Lisberg and drone-forensics specialist David Kovar told Hollister that the signals were encrypted. When researcher Kevin Finisterre challenged the claim, *The Verge* checked with DJI again. DJI confirmed encryption a second time. On 28 April 2022, Hollister published the correction. DJI now admitted the signals were not encrypted. Lisberg attributed the error to reliance on R&D contacts in China and said it had taken senior managers to reverse the statement. Finisterre had shown that DroneID packets on at least one Enhanced Wi-Fi airframe were readable in the clear.

That is Fact. It is also the trust failure in miniature. A closed-channel claim was repeated by the vendor, repeated by an independent specialist, checked, repeated again, and then withdrawn. AeroScope’s value proposition was not merely that DJI sold a receiver. It was that the broadcast was a channel for authorized parties. Once the packets are in the air for anyone who can receive the waveform, AeroScope is a convenient decoder, not a trust boundary.

NVD published CVE-2022-29945 the next day, 29 April 2022. The description is short: DJI drone devices sold in 2017 through 2022 broadcast unencrypted information about the drone operator’s physical location via the AeroScope protocol. NIST later classified the weakness as CWE-319, cleartext transmission of sensitive information, and scored it 7.5 High (CVSS 3.1). MITRE’s CNA score was 4.0 Medium. The disagreement is less important than the object. The catalogued harm is disclosure of the operator’s physical location on a channel that does not require authorization to receive.

NVD’s affected-product list includes Air 2, Air 2S, Phantom 4 Pro, FPV, Inspire 2, Mavic 3, Mini 2, Mini SE, RC Pro, and Zenmuse X5S / X7. An evaluator note states that the precise mapping from year-sold to a numerical firmware version was unknown. That gap remains an Unknown in any Passport that tries to inherit “2017–2022” as a version pin. The CVE does not describe a memory-corruption exploit or a CISA KEV condition. Exploit status, as a high-level label, is public writeup: the admission plus the cleartext property.

Inference, moderate confidence: later wartime reporting that describes use of the AeroScope broadcast as a targeting aid is reporting about a sensor that was already public, not evidence that CVE-2022-29945 is a catalogued exploit. Fedorov’s accusation is a political claim; this paper does not elevate it to established operational use. Judgment, high confidence on the CVE, the correction, and the subsequent reconstruction: the market-leader RID channel was never a closed trust boundary in the 2017–2022 fleet.

Watch keeps that fleet visible as an unencrypted operator-location sensor. Kestrel assumes identical OcuSync / DroneID modules share the class until a contrary measurement exists. Lab treats the broadcast as a sensor that Sense can hear. If a downstream process uses that Sense as Act, it has inherited a plaintext coordinate as if it were a verified identity. That inheritance is the harm.

## 4. Reconstruction: Identity as a Sensor

A vendor admission establishes the confidentiality failure. It does not, by itself, establish that a party without AeroScope can recover the fields that matter. That step is the NDSS 2023 paper.

Nico Schiller, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, and Thorsten Holz presented “Drone Security and the Mysterious Case of DJI’s DroneID” at NDSS in San Diego, 27 February–3 March 2023 (DOI 10.14722/ndss.2023.24217). The paper’s first result, and the only result this article takes as in-scope, is the reconstruction of DroneID as a receivable broadcast. The authors reverse-engineered firmware and the wireless physical layer of current DJI products, then built a receiver on commercial off-the-shelf hardware. They showed that the transmitted data is not encrypted and is accessible to anyone who can receive the waveform. The packets disclose the live position of the aircraft, the home point, and the location of the remote pilot. The authors released the receiver as a research artifact.

That is Fact on the paper, the symposium record, and the public repository. It converts a marketing object into a sensor object. The correct model is a plaintext telemetry beacon whose interesting property is the information it carries, not the exclusivity of the decoder. Lab can hear it. Campaign should not file it as a one-off decoder trick.

The same paper contains a second identity finding that belongs here and a larger firmware-and-bus record that does not. On the identity side, the authors showed that the serial number carried in DroneID was not an immutable identifier, and that the operator-location field would accept an unauthenticated location source. Confidentiality and integrity both failed. A detector that trusted the packet as “who is flying, and from where” was trusting a claim. The authors state that DJI fixed the reported bugs; no public CVE-to-version map has been found. The sixteen-item firmware list, the internal bus, and the signing-bypass discussion are sibling problems and are out of scope.

The class of failure is an unencrypted, unauthenticated location broadcast. The physical consequence is that operator, home, and aircraft coordinates are on an RF channel. The trust consequence is that a receiver has no cryptographic reason to believe the coordinates, and no cryptographic reason to keep them from anyone else. This paper does not provide a decoder recipe. Judgment, high confidence: NDSS 2023 is the first peer-reviewed demonstration that post-2017 OcuSync DroneID was not a closed identity channel. Passport the module and the year, not the brand story.

## 5. The Standard That Does Not Address Trust

It is tempting to read the DJI correction as a vendor-specific failure that the civil Remote ID program then repaired. The civil program did not repair it. It standardized the public half of the same property.

ASTM F3411’s scope statement is about identification, not authentication. Remote ID “allows governmental and civil identification of UAS for safety, security, and compliance purposes.” Broadcast Remote ID is radio from the aircraft to receivers in the vicinity. The specification defines message types for Basic ID, Location, Authentication, Self-ID, System, and Operator ID, and Bluetooth and Wi-Fi transports that a handheld device can receive. It also defines an Authentication Message. What it does not do is specify the cryptographic method that would make that message sufficient.

The IETF has now said this in a standards-track RFC, which is the cleanest public primary. RFC 9575 (June 2024) opens with a sentence that should sit on every RID Passport: “The initial regulations (e.g., [FAA-14CFR]) and standards (e.g., [F3411]) for Unmanned Aircraft Systems (UAS) Remote Identification (RID) and tracking do not address trust.” Senders can make any claims the message formats allow. Observers have no standardized means to assess trustworthiness, to verify that the messages were sent by the UA identified therein, or to confirm that the UA identified therein is the one they are visually observing. They have no way to detect whether the messages were sent by a UA or spoofed by some other transmitter in direct wireless range. F3411 “defines Authentication Message framing only. It does not define authentication formats or methods.” Annex A1’s Broadcast Authentication Verifier Service depends on observer connectivity to the internet. DRIP exists because that is not a trust design.

RFC 9153 (February 2022) had already described Broadcast RID as a one-way RF transmission whose Authentication Message specified framing but not a method. Open Drone ID implements the format. It does not mint an identity. A receiver that decodes it and emits a track has performed Sense, not authentication.

Judgment, high confidence: ASTM F3411 / Open Drone ID is an unauthenticated location source—a standard property, not an OEM CVE. Inference, moderate confidence: detection stacks that ingest F3411 as a location source will keep failing in the same way until the broadcast carries a verifiable identity. DRIP is a published repair, not a deployed default. Japan’s signature requirement is a jurisdictional exception. Unknown: whether a future mandate will make a DRIP-class format the default. Watch that as a forward indicator.

A Passport that says “F3411-22a compliant” has stated interoperability, not trust. Until the broadcast carries a verifiable identity and the receiver refuses a track that does not, Control Fabric on the identity path is a slogan.

## 6. Receivers That Inherit the Broadcast

If the civil broadcast is an unauthenticated location source, the first commercial receiver CVE family is not a surprise. It is the inheritance made visible.

On 11 July 2023, Nozomi Networks Labs disclosed three vulnerabilities in BlueMark Innovations’ DroneScout ds230, a broadcast Remote ID appliance aimed at system integrators. The device receives Open Drone ID over Wi-Fi and Bluetooth, associates parsed fields with a source address, and emits JSON-encoded MQTT messages to a broker the integrator operates. It is compatible, in the vendor and researcher description, with ASTM F3411-22a and EN 4709-002. BlueMark shipped firmware 20230605-1350 on 5 June 2023. NVD published the three CVEs the same day as the blog.

CVE-2023-31191 records an information-loss failure through traffic injection. Spoofed Open Drone ID messages could force the ds230 to drop real Remote ID information and instead generate MQTT messages containing crafted RID fields. The integrator’s broker would then have no access to the legitimate tracks. Nozomi scored it 9.3 Critical; NIST later scored it 8.1 High. CVE-2023-29156 records a second information-loss path, also via spoofed Open Drone ID, with higher complexity and a medium score. CISA-ADP’s SSVC annotation on both lists exploitation as “none.” CVE-2023-31190 is a different class: improper authentication on the firmware-update path. The update procedure did not validate the TLS certificate of the HTTPS host from which the firmware archive was fetched. A party who could sit on that path could cause the appliance to install a crafted update and obtain administrative privileges on the underlying Linux system. Affected firmware, per NVD, runs from 20211210-1627 through 20230329-1042. None of the three is in the CISA KEV catalog.

This paper names the classes and stops. Preference for a spoofed Open Drone ID frame over a legitimate track is a spoofable-RID failure on the detector. An update fetch that does not authenticate the download host is an insecure-receiver-update failure on the detector’s Control Fabric. The physical and trust consequence is that a C-UAS integrator who treats MQTT-out RID tracks as aircraft can be shown a false aircraft, and that the appliance that produces those tracks can be rewritten if its update path is reachable. Exploit status is public writeup. It is not a reproduction procedure.

Fact, high confidence: these are the first assigned CVEs on a commercial broadcast RID receiver, and the receiver inherited the unauthenticated property of the Open Drone ID broadcast before adding a second failure on its own update path. Inference, moderate confidence: other F3411 receivers share the RID-inheritance class even without a CVE. A decoder that believes an unauthenticated advertisement will prefer a well-formed lie if the lie is easier to hear. That is the RFC 9575 observer problem installed in an appliance. Judgment: a detection stack that fuses RID tracks into a common operating picture without a second, independent Sense has already decided that the broadcast is truth.

BlueMark’s role is architectural, not punitive. The ds230 is a passive scanner that turns an unauthenticated broadcast into an integrator-facing track. The failure is the trust assignment. Passport the receiver as “unauthenticated broadcast in, track out.” Watch for a second commercial RID-receiver CVE family. Kestrel other Open Drone ID receivers. Lab spoofed-track acceptance: does the detector emit a claim as a track? A Campaign that files 31191 as a one-off firmware defect and closes the ticket has treated a standard property as a vendor incident. The patch is necessary. It is not the boundary.

## 7. Encryption Without a Fleet Map

The closed-channel story did not end in 2022. It changed shape.

In January 2024, Aerial Defence reported that the process of encrypting DJI DroneID had commenced. AeroScope users had been invited, from around November 2023, to update equipment. The update combined a firmware change to the AeroScope SDR module with a hardware Upgrade Module, reference EA500, in a USB-dongle form for both the stationary and portable units. DJI’s patch notes, as quoted in that reporting, said the module was required to maintain compatibility with future DJI devices. Aerial Defence’s inference—and it should remain labeled an inference—was that future and some current airframes would transmit an encrypted DroneID, and that the dongle remaining on the bus was the authorized decrypt. Subsequent trade reporting described encryption appearing on newer models in early 2024 and described uncertainty about whether older Mavic, Phantom, and Mini fleets would receive the same change.

Fact: a vendor-required AeroScope hardware module and a reported encryption change on newer DroneID transmissions are in the 2024 public record. Inference, moderate confidence: the change is as much an access-control move—restoring AeroScope as the authorized decoder—as a privacy repair. Unknown: completeness across the 2017–2022 NVD fleet, the airframe-year map, and whether an encrypted packet is authentic as well as confidential. A ciphertext that only a dongle can open can still carry a spoofable claim.

The 2017–2022 fleet remains listed under CVE-2022-29945. A Passport that writes “DJI encrypted DroneID in 2024” without a per-airframe disposition has laundered a partial control into a fleet-wide close. Encryption of a proprietary beacon also does not alter ASTM F3411. A site that deploys AeroScope with a dongle and a DroneScout on the same pole has stacked a gated proprietary sensor on an open civil sensor and, unless the Passport says otherwise, is still treating both outputs as tracks. Partial encryption is not a closed trust boundary. Campaign should disposition “encrypted” only when year, firmware, dongle requirement, and authenticity are all in the record.

## 8. What the Record Does Not Establish

Analytic honesty on this subject is mostly a discipline of refusal. Several claims travel with the Remote ID record and do not survive the primaries.

Wartime targeting. *The Verge* reported Fedorov’s accusation that AeroScope was used to locate Ukrainian pilots. The technical predicate—that the broadcast was plaintext—is established. The causal chain from that broadcast to a specific fire mission is not a public primary of the same grade, is not a CISA KEV listing, and is not treated here as catalogued exploitation. Grade: B2/C3, left open.

Firmware-to-SKU mapping. NVD’s evaluator note still stands. “Sold 2017–2022” is not a version pin. Unknown.

Patch completeness for the NDSS identity findings. The authors say DJI fixed the reported bugs. No public CVE-to-version map has been found. “Fixed” without a version is not a Passport disposition. Unknown.

A second commercial RID-receiver CVE family. BlueMark remains the assigned case. Shared-class inference is moderate, not a substitute for a second CVE.

Cryptographic authenticity on the civil broadcast. DRIP is a published repair. The U.S. and EU deployed stacks do not make a verifiable identity the default. Not established as present.

KEV status. None of CVE-2022-29945, CVE-2023-31191, CVE-2023-29156, or CVE-2023-31190 appears in the CISA KEV catalog as of this collection. Public writeup is not “actively exploited” in the KEV sense.

Scope. This paper does not establish findings on MAVLink command-and-control, DUML-as-bus, or payload and peripheral electronics. Those are sibling analyses.

“Not established” is not “safe.” It is a hole in the Passport. Watch keeps the hole visible. Campaign assigns a disposition rather than filling it with a headline.

## 9. From Sensor to Assurance Record

The durable object is not a detector. It is a record that refuses to treat a broadcast as an identity.

A Product Security Passport for this problem has a small number of fields. For a DJI airframe: year sold; CVE-2022-29945 listing; DroneID encryption state (plaintext, dongle-gated, unknown); whether the identity field is hardware-bound; whether a civil F3411 transmitter is also present and whether it carries a DRIP-class authenticity format. For an AeroScope: software version, EA500 presence, remaining plaintext-fleet coverage, and whether its management path sits in the same trust domain as the tracks it emits. For a civil RID receiver: standard claimed, firmware, whether the output is labeled as an unauthenticated claim, whether spoofed-track acceptance has been Lab-tested, and whether the update path authenticates the publisher. For a fusion picture: which Sense sources are independent of the broadcast, and which Act functions may fire on a broadcast-only track.

Passport holds that signed longitudinal story. Watch holds the holes Section 8 refused to close, plus the forward indicators: an independent 2024 encryption map, a second receiver CVE family, a versioned advisory for the NDSS identity items, and any future F3411 authenticity mandate. Kestrel hunts the same module and receiver class across renamed SKUs. Lab measures whether the broadcast can be heard and whether the receiver emits a forged claim as a track. It does not publish a decoder recipe and it does not cross from Sense into Act. KAT is that test, not a waveform kit. Campaign closes only what the version map supports. Control Fabric is reserved for the receiver update, the dongle session, and the identity field—not for “we bought AeroScope.”

Sense, Move, and Act must stay unbundled. The identity broadcast is Sense. It becomes Act only when a person or a program treats the coordinate as a targeting or enforcement input. The legitimacy of a public-safety mission does not repair the sensor. A CUAS stack that cues an effector from a RID track without a second source has made the same collapse with higher kinetic leverage. A binary “encrypted / not encrypted” label is the wrong output. Encryption of later DroneID, authenticity of F3411, receiver-update authentication, and fleet remainder are four different controls. A Passport that stores only the first will certify the dongle and miss the integrator’s MQTT picture.

## 10. Conclusion

Remote ID and AeroScope were sold as a closed trust boundary. The sale was the interesting event. The engineering was a broadcast.

CVE-2022-29945 and the April 2022 *Verge* correction established that the market leader’s law-enforcement channel transmitted operator location in the clear, contrary to repeated public statements. Schiller et al. established that the same channel could be recovered with ordinary radio hardware and that a packet carried aircraft, home, and pilot. ASTM F3411 and the IETF’s DRIP RFCs established that the civil successor was never designed as a trust protocol: observers cannot, under the shipped standard, know that a message came from the aircraft it names. BlueMark DroneScout established that a commercial receiver will inherit that property and can be made to prefer a spoofed Open Drone ID track, and that the receiver’s own update path was a second, independent failure. Later DroneID encryption and the AeroScope dongle change who is invited to listen to one proprietary sensor. They do not authenticate the civil broadcast, they do not map the 2017–2022 fleet, and they do not convert a track into an identity.

The assurance response is modest and strict. Treat the broadcast as a plaintext sensor. Passport encryption state, authenticity state, and receiver inheritance by airframe and by appliance. Watch the remainder. Lab claims, not decoder folklore. Keep Sense from collapsing into Act. Detection stacks that ingest unauthenticated F3411 or plaintext DroneID as a location source will keep failing in the same way until the broadcast carries a verifiable identity. That sentence is an Inference about the class, not a prediction about a particular CVE. It is also the only conclusion the decade’s public record currently supports.

Endnotes

1. Sean Hollister, “DJI insisted drone-tracking AeroScope signals were encrypted — now it admits they aren’t,” *The Verge*, April 28, 2022. https://www.theverge.com/2022/4/28/23046916/dji-aeroscope-signals-not-encrypted-drone-tracking

2. National Vulnerability Database, CVE-2022-29945, published April 29, 2022. https://nvd.nist.gov/vuln/detail/cve-2022-29945

3. Sean Hollister, “DJI drones, Ukraine, and Russia — what we know about AeroScope,” *The Verge*, March 23, 2022, with April 28, 2022 correction. https://www.theverge.com/22985101/dji-aeroscope-ukraine-russia-drone-tracking

4. Nico Schiller, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, and Thorsten Holz, “Drone Security and the Mysterious Case of DJI’s DroneID,” Network and Distributed System Security Symposium, February 27–March 3, 2023. https://www.ndss-symposium.org/ndss-paper/drone-security-and-the-mysterious-case-of-djis-droneid/ ; PDF https://www.ndss-symposium.org/wp-content/uploads/2023/02/ndss2023_f217_paper.pdf ; DOI https://dx.doi.org/10.14722/ndss.2023.24217

5. RUB-SysSec, DroneSecurity repository (NDSS 2023 artifact). https://github.com/RUB-SysSec/DroneSecurity

6. Federal Aviation Administration, “Remote Identification of Drones,” last updated March 19, 2025. https://www.faa.gov/uas/getting_started/remote_id

7. Remote Identification of Unmanned Aircraft, 86 Fed. Reg. 4390 (January 15, 2021) (14 CFR Part 89). https://www.govinfo.gov/content/pkg/FR-2021-01-15/pdf/2020-28948.pdf

8. ASTM International, “Standard Specification for Remote ID and Tracking,” ASTM F3411-22a, 2022. https://www.astm.org/f3411-22a.html

9. ASTM International, “Standard Practice for Remote ID Means of Compliance to Federal Aviation Administration Regulation 14 CFR Part 89,” ASTM F3586-22, 2022. https://www.astm.org/f3586-22.html

10. Adam Wiethuechter, Stuart Card, and Robert Moskowitz, “DRIP Entity Tag (DET) Authentication Formats and Protocols for Broadcast Remote Identification (RID),” RFC 9575, June 2024. https://www.rfc-editor.org/rfc/rfc9575.html

11. Stuart Card, Adam Wiethuechter, Robert Moskowitz, and Andrei Gurtov, “Drone Remote Identification Protocol (DRIP) Requirements and Terminology,” RFC 9153, February 2022. https://www.rfc-editor.org/rfc/rfc9153.html

12. Open Drone ID, opendroneid-core-c. https://github.com/opendroneid/opendroneid-core-c

13. Nozomi Networks Labs, “Nozomi Networks Discovers Three Vulnerabilities Affecting BlueMark DroneScout ds230 Remote ID Receiver,” July 11, 2023. https://www.nozominetworks.com/blog/nozomi-networks-discovers-three-vulnerabilities-affecting-bluemark-dronescout-ds230-remote-id-receiver

14. National Vulnerability Database, CVE-2023-31191, published July 11, 2023. https://nvd.nist.gov/vuln/detail/CVE-2023-31191

15. National Vulnerability Database, CVE-2023-29156, published July 11, 2023. https://nvd.nist.gov/vuln/detail/CVE-2023-29156

16. National Vulnerability Database, CVE-2023-31190, published July 11, 2023. https://nvd.nist.gov/vuln/detail/CVE-2023-31190

17. Nozomi Networks Labs, CVE-2023-31190 advisory. https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-31190

18. Nozomi Networks Labs, CVE-2023-31191 advisory. https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2023-31191

19. BlueMark Innovations, DroneScout firmware history. https://download.bluemark.io/dronescout/firmware/history.txt

20. Steven Tisseyre, “The process of encrypting DJI DroneID has commenced,” Aerial Defence, January 23, 2024. https://www.aerial-defence.com/the-process-of-encrypting-dji-droneid-has-commenced/

21. CISA, Known Exploited Vulnerabilities Catalog. https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Selected Bibliography

ASTM International. *Standard Specification for Remote ID and Tracking.* ASTM F3411-22a. 2022. https://www.astm.org/f3411-22a.html

Card, Stuart, Adam Wiethuechter, Robert Moskowitz, and Andrei Gurtov. “DRIP Entity Tag (DET) Authentication Formats and Protocols for Broadcast Remote Identification (RID).” RFC 9575. June 2024. https://www.rfc-editor.org/rfc/rfc9575.html

Federal Aviation Administration. “Remote Identification of Drones.” March 19, 2025. https://www.faa.gov/uas/getting_started/remote_id

Hollister, Sean. “DJI insisted drone-tracking AeroScope signals were encrypted — now it admits they aren’t.” *The Verge*, April 28, 2022. https://www.theverge.com/2022/4/28/23046916/dji-aeroscope-signals-not-encrypted-drone-tracking

National Vulnerability Database. CVE-2022-29945. April 29, 2022. https://nvd.nist.gov/vuln/detail/cve-2022-29945

National Vulnerability Database. CVE-2023-31190; CVE-2023-31191; CVE-2023-29156. July 11, 2023. https://nvd.nist.gov/vuln/detail/CVE-2023-31190

Nozomi Networks Labs. “Nozomi Networks Discovers Three Vulnerabilities Affecting BlueMark DroneScout ds230 Remote ID Receiver.” July 11, 2023. https://www.nozominetworks.com/blog/nozomi-networks-discovers-three-vulnerabilities-affecting-bluemark-dronescout-ds230-remote-id-receiver

Schiller, Nico, Merlin Chlosta, Moritz Schloegel, Nils Bars, Thorsten Eisenhofer, Tobias Scharnowski, Felix Domke, Lea Schönherr, and Thorsten Holz. “Drone Security and the Mysterious Case of DJI’s DroneID.” NDSS 2023. https://dx.doi.org/10.14722/ndss.2023.24217

Tisseyre, Steven. “The process of encrypting DJI DroneID has commenced.” Aerial Defence, January 23, 2024. https://www.aerial-defence.com/the-process-of-encrypting-dji-droneid-has-commenced/

Wiethuechter, Adam, Stuart Card, and Robert Moskowitz. “DRIP Entity Tag (DET) Authentication Formats and Protocols for Broadcast Remote Identification (RID).” RFC 9575. June 2024. https://www.rfc-editor.org/rfc/rfc9575.html

Source note. This paper distinguishes the proprietary DroneID / AeroScope channel from the civil ASTM F3411 / Open Drone ID / Part 89 broadcast, and treats both as unauthenticated location sources rather than as a single vendor incident. It uses Schiller et al. only for the DroneID reconstruction and the identity-field findings; the paper’s firmware-bus, signing, and crash results are excluded as sibling-scope. Wartime AeroScope-use reporting is carried as B2/C3 context and is not treated as catalogued exploitation or as a CISA KEV condition. ASTM RID spoofability is a standard property, not an OEM CVE. The 2024 DroneID encryption / AeroScope dongle change is taken from contemporary CUAS trade reporting and is not treated as a complete fleet close. Command-and-control (including MAVLink), DUML-as-bus, and payload or peripheral topics were excluded by design. The analysis is current as of August 19, 2026 and should be revalidated against subsequent NVD enrichment, a vendor version map for 2024 encryption, any second commercial RID-receiver CVE family, and any ASTM or CAA mandate that makes a DRIP-class authenticity format the default content of the broadcast.